Back to skill

Security audit

Openclaw Master Skills Clawhub Pkg

Security checks across malware telemetry and agentic risk

Overview

This package is a markdown-only catalog of OpenClaw skills with disclosed install pointers and no executable behavior in the inspected artifact.

Review this as a catalog rather than a bundled collection of all listed skills. If you follow the manual clone/copy instructions or install any listed skill, vet that specific skill separately, especially entries involving credentials, browser automation, posting, memory, or background updates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Low
Confidence
78% confidence
Finding
The manifest description presents this package as a curated collection of skills, which suggests an index or catalog role. The README goes beyond simple cataloging by instructing users to clone the repository and copy files into the local OpenClaw skills directory, introducing an installation/management behavior not reflected in the manifest description.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says this skill helps when users ask questions like "how do I do X," which is an extremely common phrase not limited to skill discovery. Without clearer constraints or exclusion conditions, this could cause the skill to activate for many general help requests rather than only when the user wants to discover/install skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The listed trigger includes answering questions like "有什么技能可以X" (what skill can do X), where X can be arbitrarily broad. As written, it lacks scope boundaries or negative examples, increasing the chance of unintended activation for general capability questions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.