Back to skill

Security audit

Axiomata Skill Evaluator En

Security checks across malware telemetry and agentic risk

Overview

This skill is a local OpenClaw skill evaluator with some documentation and scoping issues, but no evidence of credential theft, persistence, network exfiltration, or destructive behavior.

Install only if you want a local evaluator for OpenClaw skill directories. Run both documented scripts if you need both Axioma and ISO-style results, do not rely on --improve to change anything, and do not provide credentials or point the evaluator at broad private directories unless you intentionally want their files inspected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file advertises a dual evaluation system with ISO 25010 automated checks, but the implementation only performs the Axioma 5-dimension scoring. This is a trust and integrity issue: users may rely on a security/quality signal that is not actually being produced, which can lead to unsafe publication or approval decisions.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The CLI documents an `--improve` flag as auto-improving a skill, but no code modifies the target skill or performs any improvement action. This can mislead operators into believing remediation has occurred when the skill remains unchanged, creating a false sense of safety and leaving defects or risky content in place.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description uses very broad activation language such as evaluating skills before publishing, auditing quality, and verifying production standards, which can overlap with many generic review or evaluation requests. In agent routing systems, this can cause the skill to trigger outside its intended scope, potentially exposing files or launching evaluation scripts on unintended targets.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger table contains vague phrases like 'Evaluate skill', 'Improve skill', 'Skill audit', and 'Check quality' without boundaries, required inputs, or exclusions. This increases the chance of accidental invocation in unrelated contexts, which is especially risky here because the skill is documented to run bundled Python evaluators over supplied paths.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.