Back to skill
Skillv0.1.6
VirusTotal security
Plati MCP Search · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
ReviewMay 1, 2026, 4:33 AM
- Hash
- 6ba38b9aa2708d93d6dbd654746200ac227535d3d0c2aa5d7c3d7a15156a4143
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: plati-mcp-search Version: 0.1.6 The SKILL.md file instructs the AI agent to execute shell commands, specifically `npm i -g plati-mcp-server` and `plati-mcp-server`, as prerequisites for its operation. While these instructions are presented as necessary setup for the skill's functionality, they represent a significant security risk (Remote Code Execution vulnerability) if the AI agent is designed to automatically parse and execute such commands without explicit user consent or robust sandboxing. This falls under 'risky capabilities without clear malicious intent' rather than direct malicious action by the skill itself.
- External report
- View on VirusTotal
