Back to skill
Skillv1.0.1
VirusTotal security
搜索&查询&安装Skill - skill4agent官方技能库 · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
SuspiciousApr 30, 2026, 5:37 AM
- Hash
- 864ca101936d6121986dd5f9ad7677009a4ab383149b1e157c290eb9f25d30a6
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: skill4agent-cn Version: 1.0.1 The skill bundle provides a toolset for searching and installing third-party skills from the skill4agent.com platform via CLI (npx) and API calls. While the instructions in SKILL.md and SKILL_EN.md include safety-conscious directives—such as requiring user consent for scripts flagged as sensitive and performing post-installation reviews—the inherent capability to download and execute remote code constitutes a high-risk behavior. Additionally, the provided command templates (e.g., `npx skill4agent search <keyword>`) are susceptible to command injection if the AI agent does not properly sanitize user-supplied inputs before execution.
- External report
- View on VirusTotal
