Back to skill

Security audit

tsarr

Security checks across malware telemetry and agentic risk

Overview

This skill transparently helps manage a home media stack and its higher-risk actions are disclosed and tied to user-directed media administration.

Install this only if you want OpenClaw to operate your media services through TsArr. Review commands before approving actions that delete items, use --delete-files, change watched state, control Jellyfin sessions, or approve/decline requests, and keep the configured API keys and qBittorrent credentials protected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The workflow documentation includes commands that permanently delete media files (`--delete-files`) but only says to use extra destructive flags when the user clearly asks for them. It does not explicitly warn that these actions are irreversible and can remove underlying downloaded or managed files, which increases the chance of accidental destructive use by an agent or operator following the guide.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.