CodeBuddy Code for OpenClaw

Security checks across malware telemetry and agentic risk

Overview

This is a CodeBuddy CLI setup and usage guide with clearly disclosed but risky permission-bypass options that users should avoid outside disposable sandboxes.

Install only if you intend to use Tencent CodeBuddy. Verify the npm package before installing globally, use normal interactive permissions for real projects, avoid `-y`, `--dangerously-skip-permissions`, and bypass modes outside disposable sandboxes, and review any generated memory or command files before relying on future sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal