Elasticsearch Openclaw
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle provides documentation and code examples for read-only Elasticsearch 9.x operations, focusing on search and analytics. It explicitly states its read-only nature and consistently adheres to it across all files. While it requires external API keys (ELASTICSEARCH_API_KEY, JINA_API_KEY), this is necessary for its stated purpose, and the skill provides clear instructions for secure handling (least-privilege API keys, environment variables, .gitignore). There is no evidence of data exfiltration, malicious execution, persistence, obfuscation, or prompt injection attempts designed to harm the agent or user. All external network calls are to the Elasticsearch cluster and Jina AI, which are integral to the skill's functionality.
