Grocery Checklist

Security checks across malware telemetry and agentic risk

Overview

The skill is internally consistent: it is a local grocery state manager that uses a Telegram bot token stored in your OpenClaw config for UI, and its code and instructions match that purpose.

This skill is local-first and coherent with its description, but review these before installing: 1) You must place your Telegram bot token in ~/.openclaw/openclaw.json (keep that token secret and prefer a dedicated grocery bot account). 2) The skill will write state files under ~/.openclaw/data/grocery-checklist; back them up if needed. 3) If you enable or run the optional standalone scripts/telegram_bot.py, understand it will poll Telegram using the token in your OpenClaw config—ensure allowFrom is configured to limit who can control the bot. 4) If your OpenClaw setup requires exec approvals, allowlist the included scripts (scripts/grocery.sh and the .py scripts) deliberately. Review the bot token placement and the allowlist settings to avoid exposing the UI to unintended users.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal