Back to skill
Skillv3.1.0

VirusTotal security

Otc Confirmation · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

BenignApr 30, 2026, 5:17 AM
Hash
a7ec7a700cadb285bf27418ab664c95134844ad7514a855a0ceeee2e232ee5ab
Source
palm
Verdict
benign
Code Insight
Type: OpenClaw Skill Name: otc-confirmation Version: 3.1.0 The 'otc-confirmation' skill bundle is a well-designed security tool providing a human-in-the-loop confirmation mechanism for AI agents. It implements a 'zero-knowledge' architecture where the agent generates and verifies codes via secure local state files (mode 600) without ever seeing the code in its own context or logs. The scripts (generate_code.sh, send_otc_email.sh, verify_code.sh) use cryptographically secure entropy and follow defensive programming practices. Furthermore, the bundle includes an extensive 'Security Architecture Pack' with Python reference implementations for audit logging and permission guarding, specifically designed to protect against prompt injection and unauthorized command execution.
External report
View on VirusTotal