Back to skill
Skillv1.0.0

VirusTotal security

local-portfolio-auditor · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

BenignApr 30, 2026, 4:26 AM
Hash
bde6c3242956824d67f529729fc1984548bacd91e58683c58ed23644bbe1eab0
Source
palm
Verdict
benign
Code Insight
Type: OpenClaw Skill Name: local-portfolio-auditor Version: 1.0.0 The OpenClaw skill 'local-portfolio-auditor' is benign. It adheres to its stated purpose of auditing a local financial portfolio using public, read-only APIs (CoinGecko, Etherscan, Alpha Vantage placeholder). The `main.py` script securely handles API keys via environment variables and only reads the user-provided `portfolio.json` file. There is no evidence of data exfiltration, arbitrary code execution, persistence mechanisms, or prompt injection attempts in any of the files, including `SKILL.md` and `README.md`.
External report
View on VirusTotal