Back to skill

Security audit

Team Lead

Security checks across malware telemetry and agentic risk

Overview

This is a coherent multi-agent coordination skill, with disclosed agent dispatch and history tracking, but users should be aware that task details may be shared across agents and retained in memory/history.

Install only if you are comfortable with complex requests being split across multiple agents and with task history or performance metadata being tracked during use. Avoid sending secrets, credentials, or highly sensitive business data unless your OpenClaw environment gives you clear controls over sub-agent sharing, memory, cache, and history deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
The report makes absolute safety claims such as '无安全漏洞' and '权限最小化' despite the documented ability to dynamically create agents and publish the skill. Absolute assurances in security documentation are misleading because they can suppress appropriate review and cause operators to trust capabilities that increase execution and supply-chain risk.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README promotes automatic task decomposition, multi-agent dispatch, data search, performance tracking, and collaboration history, but does not disclose what data may be shared across agents, retained, cached, or logged. In an orchestration skill, this omission is security-relevant because users may submit sensitive business, code, or personal data that then propagates to multiple components without informed consent or clear boundaries.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly says the capability matrix is kept in memory or configuration files, yet it provides no privacy notice or consent model for persistence of task-related metadata. In a multi-agent orchestrator, stored capabilities, session keys, and related context can accumulate into sensitive operational data that may later be exposed, reused outside user expectations, or accessed by other components.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill states that execution history, quality scores, agents used, and lessons learned are recorded after each collaboration without warning users about retention. For an orchestration skill, this creates a real privacy and data-handling risk because task histories can reveal confidential business requests, internal workflows, or personal data across repeated runs.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.