Agent Forge

Security checks across malware telemetry and agentic risk

Overview

This skill is a legitimate agent-creation helper, but it can make persistent agent and gateway permission changes after broad triggers without a clear final approval gate.

Install only if you intentionally want a skill that can create persistent OpenClaw agents and modify multi-agent communication settings. Before using it, review the exact files and gateway patch, keep session visibility and tools as narrow as practical, check what is in USER.md before it is copied, and use simple trusted agent IDs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as '创建一个agent', which can cause the skill to activate unexpectedly. In this skill, unintended activation is more dangerous than usual because activation leads to agent creation, file generation, configuration changes, and potential permission assignment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal