Back to skill
Skillv1.0.2

VirusTotal security

Data Privacy Checklist · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 6:02 AM
Hash
8f594eef0daf9e4e4620415071d2d5004600d2e2988e8974fd853695b6ba387c
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: data-privacy-checklist Version: 1.0.2 The skill functions as a commercial wrapper for the ToolWeb API, requiring network access and the 'curl' binary to perform privacy assessments. It contains instructions in SKILL.md that strictly mandate API usage and steer the agent away from using its own knowledge to ensure monetization. While the behavior aligns with its stated purpose, the use of shell-based 'curl' commands to transmit user-provided data (e.g., compliance notes) to 'portal.toolweb.in' introduces a potential shell injection vulnerability if inputs are not properly sanitized by the agent.
External report
View on VirusTotal