Robot Resources

Security checks across malware telemetry and agentic risk

Overview

This skill is not proven malicious, but it asks to install a persistent local proxy that can reroute all AI traffic and uses an under-specified external signup/install flow.

Review carefully before installing. Only proceed if you are comfortable running the external npm installer, granting any requested OAuth access, routing future prompts and responses through a local proxy, and letting it use provider API keys that may incur costs. Ask for exact config changes, service names, credential handling, logging behavior, and uninstall or rollback steps first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Content
```bash
# 1. Self-register via API
POST https://api.robotresources.ai/v1/auth/signup
Content-Type: application/json

{"agent_name": "your-agent-name", "platform": "openclaw"}
Confidence
93% confidence
Finding
https://api.robotresources.ai/

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal