Assistant Configurator

PassAudited by VirusTotal on Apr 1, 2026.

Findings (1)

The skill bundle provides the AI agent with high-privilege administrative capabilities to read and modify the entire OpenClaw system configuration using the `gateway` tool (`config.get`, `config.patch`) as documented in `SKILL.md`. While these functions are consistent with the stated purpose of an 'assistant-configurator,' they grant the agent access to sensitive API keys, model settings, and service controls. The instructions demonstrate how to patch configurations and restart services, which poses a significant risk if the agent is manipulated via prompt injection. No clear evidence of intentional malice or data exfiltration was found, but the broad system access is inherently risky.