Openclaw Shield 1.0.3

Security checks across malware telemetry and agentic risk

Overview

This appears to be a security-review skill with broad activation wording, but the supplied evidence does not show hidden, destructive, persistent, or data-exfiltrating behavior.

Install only if you want this skill to be available for security and code-audit tasks. The publisher should ideally narrow its activation wording so ordinary security-related discussion does not invoke it unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance lists broad phrases like "security scanning," "threat detection," and "code auditing" without defining boundaries, exclusions, or concrete trigger phrases. In a skill-routing context, this can cause unintended invocation for many generic security or auditing requests.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal