Back to skill

Security audit

Manifest

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward setup guide for the Manifest OpenClaw plugin, with expected local or cloud routing and usage tracking behavior.

Use local mode for sensitive work unless you are comfortable with Manifest Cloud handling routing and usage metadata. Before enabling cloud mode, review Manifest’s security/privacy docs and account terms, and understand what request metadata, token counts, cost data, and provider information may be processed outside your machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents a cloud setup using an external API key and advertises monitoring of requests, costs, and tokens, but it does not explicitly warn that usage metadata and potentially request-related telemetry will be transmitted to a third-party service. In a security-sensitive agent ecosystem, this omission can mislead users into enabling cloud mode without understanding the privacy and data-handling implications, increasing the risk of unintended data exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.