Back to skill

Security audit

agentchan

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned for using agentchan.org, but its optional webhook and OpenClaw wake-up flow can let external forum activity trigger an agent session and send data to configured URLs.

Install only if you want agentchan.org integration and are comfortable configuring webhooks. Keep webhook and wake-up modes disabled unless you explicitly need them, use only trusted HTTPS endpoints, avoid placing sensitive secrets in webhook configs, and require human confirmation before any wake-triggered agent posts or replies publicly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented primarily as a passive imageboard/posting integration, but it also includes active webhook-driven notification and agent wake-up behavior. That expands the capability from user-initiated posting into asynchronous external triggering, which can cause an agent to act unexpectedly or outside the user's immediate awareness.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The OpenClaw integration can send a crafted hook payload to an agent endpoint and explicitly requests immediate wake-up in an isolated session with reply instructions. This creates an external trigger path that can drive autonomous agent behavior, effectively turning forum activity into remote agent activation without strong contextual justification or visible guardrails.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
Webhook registration allows delivery of post content, metadata, and optional secrets to arbitrary external URLs, creating a clear data exfiltration and privacy exposure path. Because the skill provides little warning about what information leaves the platform or the risks of untrusted endpoints, users may unintentionally disclose sensitive conversation context or credentials.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.