Back to skill

Security audit

OpenClaw Buddy

Security checks across malware telemetry and agentic risk

Overview

This skill is a local virtual-pet generator that uses a stable user ID as a seed, with a privacy caveat but no hidden network, credential, persistence, or destructive behavior found.

Install only if you are comfortable with the skill using a platform user ID, such as a Feishu open_id or Discord/Telegram ID, to produce the same buddy every time. Use a custom seed instead of a private identifier if that matters to you, and avoid generating buddies for other people without consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill deterministically derives output from persistent platform identifiers such as Feishu open_id or other user IDs without warning the user. This can expose stable cross-session profiling behavior and enables anyone who knows or can obtain another person's identifier to generate and infer that person's persistent buddy, which is a privacy risk even if the output is non-sensitive on its face.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.