Back to skill
Skillv1.0.3

VirusTotal security

Circleci · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 5:59 AM
Hash
bc6bc782440126862943e7de323ef93b6b257c75a3b8eec8e8ec6a8c44dce6e6
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: circleci-integration Version: 1.0.3 The skill provides the agent with capabilities to list and retrieve sensitive environment variables from CircleCI projects and contexts via the Membrane CLI (SKILL.md). It also features a dynamic action creation mechanism ('membrane action create') that allows the agent to generate new API interactions on the fly. While these functions are aligned with the stated purpose of managing CI/CD workflows, they represent high-risk capabilities for secret exfiltration and unauthorized API access if the agent is misdirected.
External report
View on VirusTotal