Back to skill

Security audit

Openclaw Auto Skill Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only planning helper that is scoped to drafting workflow plans and does not add hidden execution or persistence.

Before installing, note the metadata slug mismatch because it may make the package name look different from the skill name. From a security perspective, the skill is narrowly scoped to planning and repeatedly requires approval for sensitive or destructive actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.