Security audit
Kiro Cli Openclaw Bridge
Security checks across malware telemetry and agentic risk
Overview
The artifact appears to be a legitimate ClawHub maintainer skill bundle, but it deserves review because one helper defaults to unrestricted local execution and can send diffs to external reviewer tools.
Install only in a trusted ClawHub maintainer workspace. Use the moderation and publishing workflows with explicit targets and review the exact commands first. For autoreview, prefer the safer no-yolo mode unless unrestricted local access is truly needed, and be aware that fallback reviewer CLIs may receive repository diffs.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
