Back to skill
Skillv1.0.0
VirusTotal security
Podcast Generator · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
ReviewMar 24, 2026, 3:36 AM
- Hash
- c327127f6ff4500efc5e6b5e43410376f676d73ee0b7fcaf3e0a6635470c2253
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: podcast-gen Version: 1.0.0 The skill is a podcast generator that automates news retrieval via search engines and audio synthesis using the xfyun-tts skill. It is classified as suspicious because it instructs the AI agent to construct and execute shell commands, including searching the local filesystem (~/.openclaw) and running a Python script with dynamically generated arguments. While the use of quoted heredocs in SKILL.md suggests some awareness of shell safety, the pattern of executing shell commands based on AI-selected parameters (like the voice ID) represents a high-risk capability that could be exploited via prompt injection.
- External report
- View on VirusTotal
