Back to skill

Security audit

Skill Analyst

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only skill for reviewing OpenClaw skills, with local skill listing that fits its stated comparison purpose.

Install only if you are comfortable letting the agent consider your installed OpenClaw skill list when you ask for overlap analysis. Prefer clawhub list or a narrow SKILL.md read when possible, and make sure the local clawhub and optional skill-vetter tools are trusted.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill instructs scanning `~/.openclaw/skills/` to enumerate installed skills without any explicit user-consent, privacy, or minimization guidance. While this is not inherently malicious, it can cause unnecessary exposure of local environment details and installed tooling metadata during analysis.

Static analysis

No suspicious patterns detected.