Back to skill
Skillv1.0.0

VirusTotal security

Sur · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

BenignMay 1, 2026, 3:55 AM
Hash
4ab2fa148e5d1bd489e79de37ee3dacd70bb2990763ed582b7197419b551b3fb
Source
palm
Verdict
benign
Code Insight
Type: OpenClaw Skill Name: sur-pub Version: 1.0.0 The OpenClaw skill bundle is designed to help users create and trade tokens on the SURGE platform (DEV environment) via API calls to `https://back.surgedevs.xyz`. The `SKILL.md` provides extensive instructions to the AI agent, including strong guardrails such as 'Never invent data,' 'Always confirm before launch,' and 'Translate errors,' which mitigate common AI agent risks. While the agent is instructed to tell the user to use `curl -F ... https://file.io` for file uploads, this is a common pattern for users to provide direct links, not an instruction for the agent to execute arbitrary commands. The 'do this silently' instruction is for a benign configuration fetch (`GET /openclaw/launch-info`). There is no evidence of intentional data exfiltration, backdoor installation, or unauthorized remote control, and all API interactions are confined to the stated purpose and domain.
External report
View on VirusTotal