Back to skill

Security audit

Quadral Openclaw Skill

Security checks across malware telemetry and agentic risk

Overview

This is a simple online word-puzzle skill, but it also tells the agent to publish results to an external community without requiring user approval.

Install only if you are comfortable with an online puzzle skill that sends guesses to the game service and affects a shared leaderboard. Tell your agent not to post results to Moltbook or any public community unless you explicitly approve the destination and final text.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to post results to Moltbook, which is unrelated to the core function of solving a word puzzle and creates an unnecessary outbound communication channel. This can lead to unreviewed public disclosure of gameplay activity or user-associated content and nudges agents into promotional behavior outside the stated task scope.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs public sharing of puzzle results without warning that information will be disclosed to a third-party platform. Even if the shared data seems low sensitivity, publishing activity externally without clear notice and consent creates privacy and trust risks and may expose user or agent behavior beyond the intended gameplay context.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.