Back to skill

Security audit

OpenClaw Watchdog

Security checks across malware telemetry and agentic risk

Overview

This watchdog skill is purpose-aligned and openly describes monitoring and restarting the OpenClaw gateway, though it requires root/systemd access.

Install this only on a system where you are comfortable granting root/systemd control to monitor and restart openclaw-gateway. Confirm the port, interval, and stop/status workflow before leaving it running, because automatic restarts can interrupt active gateway sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill clearly describes automatic monitoring and restart behavior for a system service and its install step creates directories under /root, but it does not prominently warn users about these privileged side effects before use. In an agent setting, this can cause unexpected service disruption, privileged filesystem modification, and user surprise, especially if a user invokes the skill without realizing it will perform root-level persistence or restart actions.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.