Back to skill

Security audit

Agent Advisor

Security checks across malware telemetry and agentic risk

Overview

This is a local model-advice tool whose history mode reads recent OpenClaw conversations, but the behavior is disclosed, bounded, and not paired with network sending or file changes.

Install only if you are comfortable with the auto and full-without-task modes reading recent local OpenClaw conversation history. Use recommend with an explicit task description if prior sessions may contain secrets, credentials, proprietary topics, or personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The auto-analysis feature reads historical session files from the local OpenClaw sessions directory and analyzes prior user messages without any explicit notice, consent, or per-run confirmation. This creates a privacy risk because sensitive prompts or personal data from past conversations may be processed unexpectedly, and users may not realize that invoking model recommendation can inspect historical content.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs reading the most recent 5 sessions' user messages to infer task types, which creates a privacy risk by collecting and processing prior conversation content without clear consent or data-minimization controls. Even if used only for recommendation, history analysis can expose sensitive prompts, credentials, proprietary code topics, or personal information across contexts.

Ssd 3

Medium
Confidence
95% confidence
Finding
The automatic history analysis ingests raw user message text and then surfaces derived plain-language summaries such as high-frequency keywords, which can reveal the nature of prior sensitive conversations without minimization. Even though it does not print full messages, the extraction and presentation of content-derived signals from multiple sessions can leak confidential topics, credentials-related themes, health/legal issues, or other private context to anyone with access to run the skill.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.