Back to skill

Security audit

Agentoctopus Openclaw

Security checks across malware telemetry and agentic risk

Overview

This router is not overtly malicious, but it can automatically run unknown community skills without clear confirmation controls, so users should review it before installing.

Install only if you want AgentOctopus to choose and run community skills for you automatically. Avoid sending secrets, private personal data, API keys, or confidential work content unless you understand which downstream skill or service may receive it, and prefer restricting or reviewing the enabled skill set before using automatic routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly states that it will automatically select and execute downstream community skills from a large pool, and even retry alternate candidates, without documenting any consent, allowlisting, or side-effect safeguards. In a routing/orchestrator context, this materially increases the chance that a benign-looking user query triggers a downstream tool with network access, file access, account actions, or other unintended side effects, making the omission security-relevant rather than merely informational.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.