Openclaw Bridge

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local agent bridge, but it gives Claude broad authenticated ability to message and trigger OpenClaw without tight data-sharing boundaries.

Install only if you trust the local OpenClaw gateway, its configured agents, and the account or token used by the OpenClaw CLI. Use explicit OpenClaw commands, avoid sending secrets or whole files, and review any handoff content before forwarding it to another agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase "ask the local agent" is broad enough to match ordinary user language that may not specifically intend to invoke this skill. That creates an unintended invocation risk, which can cause messages or context to be sent to another agent without sufficiently explicit user intent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly supports sending arbitrary messages and session handoff context to another local agent, including examples that read file contents and transmit them onward. Without a clear warning, consent boundary, or data-classification guidance, users may unknowingly disclose sensitive project data, secrets, or internal notes to a separate system boundary.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal