Back to skill

Security audit

Drama Script

Security checks across malware telemetry and agentic risk

Overview

This is a visible drama-writing workflow that creates project files in the workspace, with no evidence of hidden credential use, exfiltration, or destructive behavior.

Install this only if you want a Chinese-oriented drama-writing workflow that will create and update files in your OpenClaw workspace. Expect generated project folders, temporary draft files, possible subagent use for longer projects, and staged user review before moving through the writing pipeline.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill content is entirely written as a Chinese-only operating manual and provides no mechanism for honoring the user's language preference. In an agent setting, hard-coding output language can override user intent, reduce usability, and cause downstream errors when other tools, reviewers, or workflows expect another language.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to append confirmed content into a draft file and later delete it, but does not require clear user-facing disclosure or consent before modifying workspace files. This can cause unexpected persistence of user content, accidental overwrites, or silent deletion of intermediate material, especially when users think they are only having a chat-based ideation session.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This section directs the agent to create a project folder structure, generate multiple files, and delete the draft after saving, again without mandating a visible warning or opt-in from the user. In an agent environment with filesystem access, silent project scaffolding can alter the workspace in ways the user did not expect and may destroy data if names collide or cleanup is performed automatically.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.