Back to skill

Security audit

Openclaw Evolution

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only onboarding guide, but it encourages broad agent autonomy like public posting, persistent memory, and scheduled monitoring without enough safety boundaries for new users.

Install only if you are comfortable treating this as advanced onboarding guidance rather than a safe default. Keep public posts, emails, social accounts, browser automation, account changes, and broad file access approval-gated; restrict channel access with allowlists; avoid storing secrets or sensitive third-party information in memory files; and enable cron or gateway auto-start only after testing narrowly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file explicitly encourages granting an agent authority to "write and publish freely" and to post socially "with judgment" as part of a newcomer-oriented growth path. That is dangerous because it normalizes autonomous external actions without requiring approval gates, scope limits, or discussion of privacy, legal, reputational, and safety consequences, which could lead to unintended public disclosures or harmful posts.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
For a skill described as an interactive guide for new OpenClaw users, recommending autonomous public posting and self-directed projects is an unjustified escalation of capability. In onboarding context this is more dangerous because inexperienced users may adopt the guidance without understanding safeguards, causing the agent to act beyond the user's intent or publish unsafe content under the user's identity.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises several broad onboarding-style trigger phrases such as 'getting started', 'onboarding', and 'how do I set up', which are likely to match many unrelated conversations. This can cause unintended invocation of the skill, steering users into setup guidance when they did not request it and increasing the chance of confusing or unsafe context switches during agent operation.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The setup guidance recommends connecting channels and later enabling memory, cron jobs, and skills without warning users about privacy, data retention, and automation risks. In this context, new users may enable persistent memory or automated actions before understanding what data is stored, what external systems are connected, or what autonomous behaviors may occur.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guidance promotes broad autonomous authorization for blogging, memory access, social posting, and starting projects, but does not pair this with clear warnings about privacy leakage, accidental disclosure of sensitive data, impersonation, reputational damage, or irreversible public actions. Because the skill targets users setting up an agent relationship, the lack of safety framing can mislead users into granting risky permissions too early and too broadly.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The guide encourages configuring the agent to read schedules, check unread email, and send reminders/announcements, but it does not explicitly warn users about the sensitivity of calendar, email, and notification-channel data or recommend least-privilege scoping. In an onboarding skill, this omission can lead new users to grant broad access and enable proactive monitoring without understanding privacy, retention, or misdelivery risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/multi-agent.md:162