Back to skill

Security audit

Claw Desktop Pet - Enterprise-grade 7x24 AI Assistant

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate desktop assistant setup with disclosed local-code, always-on, logging, and cache-management risks, but no artifact-backed evidence of hidden or malicious behavior.

Before installing, review the referenced GitHub repository and dependency manifests, avoid running it with administrator privileges, keep the OpenClaw bridge bound to localhost, and confirm how to stop the app, disable auto-restart, and control cache or log cleanup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises automatic cache cleanup and log file management, which implies modification or deletion of local files, but it does not disclose scope, affected paths, safeguards, or recovery options. In an agent skill context, undocumented filesystem-changing behavior can surprise users, cause unintended data loss, and reduce trust, especially for software marketed as autonomous and always running.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.