Back to skill
Skillv3.7.5
VirusTotal security
CatchClaw · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
BenignApr 30, 2026, 5:42 AM
- Hash
- aa12c270c31025d570925c0d11fd48214f10cb8ee6f9b8460ae9b8fcb3134dc7
- Source
- palm
- Verdict
- benign
- Code Insight
- Type: OpenClaw Skill Name: catchclaw Version: 3.7.5 The 'catchclaw' skill is a comprehensive package manager for OpenClaw agents and teams, facilitating the search, installation, and export of agent archives. The bundled CLI (agentar_cli.mjs) demonstrates high-quality security practices, including thorough ZIP validation (protecting against path traversal, symlinks, and decompression bombs), sensitive file filtering (e.g., .env, .credentials) during exports, and restricted binary lookups to mitigate PATH hijacking. The SKILL.md instructions implement 'hard gates' that force the AI agent to obtain explicit user confirmation before performing high-risk actions like overwriting workspaces or installing multi-agent teams.
- External report
- View on VirusTotal
