Back to skill

Security audit

AgentOps — Agent运维管理

Security checks across malware telemetry and agentic risk

Overview

This is a local OpenClaw operations skill whose scripts match its stated diagnostic and monitoring purpose, with some normal but sensitive local-output risk.

Install only if you want a local OpenClaw diagnostics tool to inspect logs, config, workspace metadata, process state, and system metrics. Run it as a normal user, invoke it for clearly OpenClaw-related tasks, and review/redact command output before sharing because logs and reports may include paths, host details, process commands, or secrets already present in local logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill advertises and instructs use of scripts that read files, write outputs, and invoke shell-capable operations, but it does not declare any permissions or execution boundaries. This creates a trust gap where an orchestrator or reviewer cannot accurately assess the skill's runtime access, increasing the risk of over-privileged execution, unintended file access, or unsafe command execution.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad operational phrases like 日志分析, 性能监控, 告警, Agent管理, and 系统监控, which can match many ordinary user requests and cause unintended invocation. Unnecessary activation is especially risky here because the skill exposes scripts with file and shell capabilities, so a loose trigger surface can expand access beyond what the user explicitly intended.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.