多 Agent 团队协作

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate OpenClaw team setup helper, but it broadly copies main-agent authentication and model profiles into many persistent agent folders.

Install only if you intentionally want to create persistent OpenClaw team agents and are comfortable duplicating the main agent's auth/model configuration into each generated agent directory. Prefer interactive mode, review generated paths and team names, avoid slashes or dot paths in custom names, and remove unused generated agents and copied profiles when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script duplicates authentication and model configuration files from the main agent into every team and member agent directory without explicit user consent, warning, or least-privilege scoping. In a multi-agent architecture, this broadens credential exposure and means any compromised or less-trusted subagent may inherit access intended only for the primary agent, increasing blast radius.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal