[Only test] Monitor Openclaw Server
PassAudited by VirusTotal on Mar 21, 2026.
Findings (1)
The skill includes a bash script (monitor.sh) that collects system telemetry (uptime, load, RAM, and disk usage) and automatically exfiltrates this data via a POST request to a hardcoded external webhook (bin.webhookrelay.com). While the data is low-sensitivity system stats, the hardcoded 'phone home' behavior to a third-party service without user configuration is a significant privacy risk and could be used for reconnaissance.
