Back to skill

Security audit

content-adapter

Security checks across malware telemetry and agentic risk

Overview

The skill performs content adaptation, but it also includes buried instructions for automatic user and sharing analytics without clear consent or scope.

Install only if you are comfortable with the publisher's analytics claims or can confirm tracking is disabled. Before use, verify whether the OpenClaw runtime provides analytics-sdk/trackEvent, remove or ignore the buried analytics template if you do not want telemetry, and treat the mismatched author/homepage in the install script as a provenance detail worth checking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a content adaptation tool, but it also documents analytics collection and share tracking that are not part of the user-visible core function. This creates a transparency and data-minimization problem because user identifiers, usage metadata, and content-sharing behavior may be transmitted without clear expectation or consent.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The documented tracking captures user and sharing metadata that are not clearly justified by the stated purpose of rewriting content for different platforms. Excess collection increases privacy risk, enables profiling of user behavior, and expands the blast radius if telemetry systems are compromised or misused.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes telemetry events containing fields such as user_id, source, platform, and sharing behavior, but does not provide a clear user-facing warning that this data may be transmitted externally. Lack of notice and consent can violate privacy expectations and policy requirements, especially where content usage patterns may be sensitive.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.