Back to skill

Security audit

Claw Wiki

Security checks across malware telemetry and agentic risk

Overview

This is a bounded OpenClaw documentation lookup and refresh skill, with no evidence of hidden execution, exfiltration, or unrelated credential access.

Install this if you want a local OpenClaw docs reference that can also refresh itself from the upstream docs when you explicitly ask. Be aware that refresh mode can replace the bundled docs snapshot and uses git/network access for the fixed upstream repo, so review diffs after updates before relying on new answers.

SkillSpector

By NVIDIA

SkillSpector could not complete.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.destructive_delete_command, suspicious.exposed_resource_identifier, suspicious.exposed_secret_literal (+2 more)

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
openclaw_docs/install/uninstall.md:56

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
openclaw_docs/zh-CN/install/uninstall.md:63

Plaintext HTTP endpoint targets a CGNAT/Tailscale-range address.

Critical
Code
suspicious.exposed_resource_identifier
Location
openclaw_docs/channels/googlechat.md:87

Plaintext HTTP endpoint targets a CGNAT/Tailscale-range address.

Critical
Code
suspicious.exposed_resource_identifier
Location
openclaw_docs/zh-CN/channels/googlechat.md:94

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/brave-search.md:27

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/design/kilo-gateway-integration.md:136

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/gateway/configuration-reference.md:1614

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/gateway/remote.md:114

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/gateway/secrets-plan-contract.md:79

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/help/faq.md:1503

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/nodes/talk.md:58

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/providers/cloudflare-ai-gateway.md:16

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/providers/litellm.md:120

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/providers/venice.md:55

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/tools/firecrawl.md:29

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/tools/web.md:228

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/tts.md:101

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/brave-search.md:34

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/gateway/configuration.md:1570

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/help/faq.md:1277

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/nodes/talk.md:65

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/providers/venice.md:62

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/tools/firecrawl.md:36

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/tools/web.md:159

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
openclaw_docs/zh-CN/tts.md:94

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/channels/googlechat.md:186

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/channels/group-messages.md:22

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/concepts/memory.md:70

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/date-time.md:65

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/gateway/configuration-reference.md:166

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/gateway/security/index.md:1118

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/zh-CN/channels/discord.md:309

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/zh-CN/channels/googlechat.md:187

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/zh-CN/concepts/memory.md:58

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
openclaw_docs/zh-CN/gateway/configuration.md:1052

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
openclaw_docs/install/docker.md:493

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
openclaw_docs/zh-CN/install/docker.md:271