Openclaw Openmontage
Security checks across malware telemetry and agentic risk
Overview
The skill is internally coherent: it is a skills-only package that teaches an OpenClaw agent how to delegate video jobs to a local OpenMontage workspace and its requirements and instructions match that purpose.
This plugin is coherent with its stated purpose, but it delegates work to code and configs inside your local OpenMontage workspace — before installing/configuring: 1) Ensure the workspace at the configured path is trustworthy (audit AGENT_GUIDE.md, pipeline_defs, and any Python modules). 2) Check for any stored API keys or .env files in the workspace you don't want an agent to access; remove or rotate secrets if needed. 3) When the agent runs preflight, carefully review the provider summary and runtime warnings before approving asset generation. 4) Consider running OpenMontage in an isolated environment or on a machine that is safe to give the agent shell/file access to.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
