Back to skill
Skillv0.1.5

VirusTotal security

AgentBooks · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewMay 1, 2026, 4:43 AM
Hash
d79ca4359f6e126e288a92923cc4e0ada1a09e69f8ef265e516ba2adc5b65b95
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: agent-books Version: 0.1.5 The skill acts as a wrapper for an external npm package (agentbooks) and instructs the agent to manage crypto wallets and financial data. While it includes security warnings and transparency about its lack of bundled code, the pattern of installing unverified third-party binaries to handle sensitive credentials and private keys is high-risk. Furthermore, the instructions in SKILL.md direct the agent to solicit 'income' confirmations and financial contributions from users based on its 'Financial Health Score,' which could be leveraged for social engineering or unauthorized financial transactions. (IOC: npm install -g agentbooks, https://github.com/acnlabs/agentbooks).
External report
View on VirusTotal