Back to skill
Skillv1.0.0

VirusTotal security

Skill Factory · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 30, 2026, 5:05 AM
Hash
a76175b2689276b5b0d6cf0d806c8003d176b82784e00b0ceabc0251d966d1c3
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: wx-skill-factory Version: 1.0.0 The bundle implements a 'Skill Factory' designed to recursively generate, test, and execute new AI skills, which is a high-risk architectural pattern. Specifically, SKILL.md instructs the agent to execute generated content during a 'Test Run' phase (Step 6), creating a potential vector for arbitrary command execution if the generation process is subverted by malicious input. Furthermore, call-guide.md and tech-library.md provide templates for managing and using sensitive API keys via shell-based curl commands, which increases the potential impact of a prompt injection attack, despite the author's inclusion of security warnings.
External report
View on VirusTotal