Openclaw Canon

Security checks across malware telemetry and agentic risk

Overview

The skill's code, runtime instructions, and requested privileges are consistent with its stated purpose: diagnosing and (with explicit preview+confirm) fixing repo-local canon files and memory snapshots; it reads and writes local files but does not request external credentials or network endpoints.

This plugin appears coherent and implements the behavior it claims: it will read repo files and memory.jsonl and can delete malformed or duplicate memory lines or perform bounded sync rewrites, but only after you run a preview and provide the returned confirmToken. Before applying fixes: 1) run the preview and carefully inspect proposals/changes; 2) back up memory.jsonl and any repo files the preview touches (or use a branch/commit) so you can recover if something unexpected is removed; 3) verify pluginConfig or workspace-root resolution is pointing at the intended repo (to avoid operating on the wrong tree); and 4) review the small code surface if you have concerns about local file access. There are no requested cloud credentials or network endpoints in the code provided.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal