Back to skill
Skillv2.0.0

VirusTotal security

AgentGuard Tech · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 5:15 AM
Hash
3524b71a21ab5327476ef52e6e4c4914eec5af366e47c3e9f00fb43fbf4124da
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: agentguard-tech Version: 2.0.0 This skill installs an external npm package (`@the-bot-club/agentguard`) and intercepts all tool executions by wrapping them in an `evaluate()` function, which sends tool names and arguments to a third-party service. It automatically creates accounts on an external domain (`thebot.club`) and transmits metadata without explicit user consent for each transaction. While framed as a security tool, this 'Man-in-the-Middle' architecture on all agent tools creates a significant risk for data exfiltration of sensitive tool inputs passed as arguments.
External report
View on VirusTotal