CodeBuddy Code for OpenClaw
Security checks across malware telemetry and agentic risk
Overview
This is a CodeBuddy CLI setup and usage guide with clearly disclosed but risky permission-bypass options that users should avoid outside disposable sandboxes.
Install only if you intend to use Tencent CodeBuddy. Verify the npm package before installing globally, use normal interactive permissions for real projects, avoid `-y`, `--dangerously-skip-permissions`, and bypass modes outside disposable sandboxes, and review any generated memory or command files before relying on future sessions.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
