Context Budgeting

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do the context-management work it advertises, with limited local state changes and no evidence of hidden data theft or destructive behavior.

Before installing, understand that the skill may change local OpenClaw memory/checkpoint state and run its bundled compaction script. Review the script if you are cautious about local automation, but the supplied evidence does not show unrelated access, credential handling, exfiltration, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to modify a local memory file and execute a shell script as part of normal operation, but it provides no user-facing consent, safety gating, or validation of what the script will do. In an agent environment, instructions to write files and run automation can cause unintended local state changes or command execution, especially if the script path or contents are later altered or implicitly trusted.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal