OpenClaw Workflow Planner

Security checks across malware telemetry and agentic risk

Overview

The skill's code, instructions, and requirements are consistent with a local workflow planner that persists a single WORKFLOW_PLAN.md file and provides planning actions; nothing in the package asks for unrelated credentials or network access.

This package appears to do what it claims: manage ideas, plans, tasks, and a single WORKFLOW_PLAN.md source-of-truth. Before installing: 1) Confirm pluginConfig.plannerFilePath is set to a safe project path (leave default WORKFLOW_PLAN.md or another project file) and not to system or sensitive files. 2) Ensure the agent process does not run with excessive privileges (avoid root) so file writes cannot overwrite system data. 3) Review bundled SKILL.md files (research and implementer) if you want to confirm no additional behaviors you don't expect. 4) If you plan to allow autonomous agent invocation, be aware the skill can read and update the configured planner file without further prompts — restrict pluginConfig and agent permissions accordingly.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal