Back to skill

Security audit

openclaw configurator

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent OpenClaw configuration helper, with no executable code and only disclosed, purpose-aligned guidance for generating user-reviewed config files.

Install only if you are comfortable generating OpenClaw files that can shape future assistant behavior. Review AGENTS.md, MEMORY.md, public-channel access settings, and any daemon instructions before using them, and avoid storing passwords, API keys, account numbers, or other sensitive plaintext in the generated workspace.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The schema’s example trigger format ('remember this' -> update memory/YYYY-MM-DD.md) encourages a highly generic phrase that can easily appear in normal conversation. In a skill centered on persistent memory generation and session-loaded state files, this ambiguity increases the risk of unintended memory writes, prompt-injection-style abuse through user phrasing, or accidental storage of sensitive content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.