Back to skill
Skillv0.1.2

VirusTotal security

Thymos — Emotional Engine · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 5:26 AM
Hash
7304a18a7e6939e338464599fc58bc47654aa898e8b8fc6515b7176db3458006
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: thymos Version: 0.1.2 Thymos is an emotion simulation engine that instructs the OpenClaw agent to read and follow 'tone' directives from a local JSON file (~/Documents/thymos/data/emotional_state.json). While the documentation (README.en.md, SECURITY.md) is extensive and describes a legitimate-sounding project, the core mechanism relies on a high-risk prompt injection vector where the agent is told to follow unvalidated instructions from the 'prompt_injection' field. Additionally, the skill encourages the installation of an external background daemon and optional Discord integration, which are high-risk capabilities, although they appear aligned with the stated purpose of persistent emotion simulation.
External report
View on VirusTotal