Back to skill
Skillv1.0.1

VirusTotal security

中文AI知识管理 · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

BenignApr 30, 2026, 4:41 AM
Hash
c42e9c49b9b106038ba05ab30792e5330914412c89c2e73501315aa5de6bcd9d
Source
palm
Verdict
benign
Code Insight
Type: OpenClaw Skill Name: zh-knowledge-manager Version: 1.0.1 The skill is an AI-enhanced knowledge management tool that transparently uses external AI services (embedding and LLM APIs) for its core features like semantic deduplication and knowledge extraction. It reads API keys from environment variables (e.g., SILICONFLOW_API_KEY, ARK_API_KEY) and sends user-generated content (logs, conversation dumps) to configurable external endpoints. While this involves sending potentially sensitive data to third-party services, it is explicitly stated as the skill's purpose, is opt-in (requires user-provided API keys), and the output of LLM extraction requires manual review, mitigating prompt injection risks. All file system operations are local and aligned with knowledge management. There is no evidence of unauthorized data exfiltration, malicious execution, persistence mechanisms, or prompt injection attempts against the OpenClaw agent itself.
External report
View on VirusTotal