Back to skill
Skillv1.0.0

VirusTotal security

Social Media Cover Generator · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewMay 1, 2026, 2:36 AM
Hash
83db8fb0e8eeac3c3626caec3bc153806f4048624cc8dcaf1a11826ecde4e75b
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: social-media-cover-generator Version: 1.0.0 The skill provides a utility to convert HTML to PNG using Puppeteer, which inherently requires high-risk capabilities like local file system access and browser execution. The conversion script (scripts/html2png.js) launches Puppeteer with the '--no-sandbox' flag, a known security weakness, and lacks strict validation on input paths, which could potentially be exploited to read sensitive local files if the agent is manipulated. While the behavior aligns with the stated purpose in SKILL.md and no clear evidence of intentional malice or data exfiltration was found, these architectural vulnerabilities warrant a suspicious classification.
External report
View on VirusTotal