Back to skill

Security audit

Gitcrawl

Security checks across malware telemetry and agentic risk

Overview

This skill is a GitHub triage helper with some sloppy metadata, but its behavior is visible, scoped to OpenClaw issue/PR lookup and verification, and not deceptive or automatically destructive.

Before installing, note that this skill is meant for OpenClaw GitHub triage and may guide decisions that affect issues or PRs. Use it for research and verification, and require explicit human confirmation before any comment, label, close, reopen, merge, or review action. The publisher should fix the placeholder description and trigger wording for clarity.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The frontmatter description at L003 states only "metadata:", which does not describe the actual skill behavior. The body from L090 onward clearly instructs the agent to inspect local archives, run gitcrawl and gh commands, perform live GitHub lookups, and support decision-making around commenting, labeling, closing, reopening, merging, and PR review activity.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The changelog entry says the frontmatter description was corrected into a real trigger, yet L003 still contains the non-descriptive placeholder "metadata:". This is an active contradiction between the documentation of the change and the current manifest content.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger section says the skill activates whenever a user request matches "the description above," but the earlier purpose/description content is effectively just "metadata:" and does not define a concrete scope. This makes it unclear when the skill should or should not activate, increasing the risk of unintended invocation.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The file contains natural-language instructions in Indonesian ("Skill milik user", "Mengikuti ... wajib") and presents them as mandatory, with no indication that the user can choose another language or locale. This can violate language/locale policy when no opt-in or justification for the constraint is provided.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.