Back to skill

Security audit

skill-builder

Security checks across malware telemetry and agentic risk

Overview

This skill is a paid Chinese-language helper for creating OpenClaw skills, with no hidden destructive behavior or unrelated data access found.

Install only if you specifically want a paid Chinese-language workflow for creating OpenClaw skills. Review the off-platform payment/contact details, and make sure you want it to create files in your OpenClaw skills workspace before following its commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger description is extremely broad, covering nearly any request to create a helper, capability, or skill. In an agent environment, this can cause the skill to activate outside its intended scope, potentially taking over unrelated user tasks and steering execution toward skill creation workflows, packaging steps, or external payment instructions.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The description states the skill as a Chinese-language assistant, which can bias or force language selection without checking the user's preference. This is less severe than code execution issues, but it can degrade usability, cause incorrect activation in multilingual settings, and create confusing or policy-incompatible behavior when the user expects another language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.