Back to skill

Security audit

Dolores 运维工具

Security checks across malware telemetry and agentic risk

Overview

This maintenance skill is mostly purpose-aligned, but it asks for powerful local operations and recurring memory retention without enough user control or privacy boundaries.

Install only if you want an assistant maintenance skill that can run local OpenClaw commands, inspect logs and workspace files, review conversation history, write memory files, and help create scheduled tasks. Before enabling it, decide whether memory sync should require explicit approval, periodically review stored memory files, and confirm any cleanup or cron changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad everyday expressions such as '维护你自己' and '清理工作目录', which can cause this high-privilege skill to activate in contexts where the user did not intend operational actions. Because the skill has exec, write, and edit capabilities, accidental invocation could lead to state changes, cleanup actions, or cron management without sufficiently explicit user consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly reviews conversation history and writes persistent memory files, but it does not present a clear user-facing notice that conversational data may be extracted, summarized, and retained. This creates a privacy and consent risk, especially because the skill is user-invocable and framed as routine maintenance of the assistant itself.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill performs integrity-affecting operations including log deletion and cron creation, yet lacks a unified warning that these actions modify the host environment and may persist across sessions. In context, this is more dangerous because the skill is an ops tool with system-level behavior and permitted execution primitives, so even intended maintenance actions can have durable side effects if users are not clearly warned.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.