Back to skill

Security audit

Claw Seatbelt

Security checks across malware telemetry and agentic risk

Overview

This skill is a visible local rollback helper, but it can overwrite the OpenClaw config and force-restart Gateway more broadly than its “10-second” and backup-script-only wording implies.

Install only if you are comfortable with a script replacing ~/.openclaw/openclaw.json from the newest backup and force-restarting OpenClaw Gateway. Run it manually in a confirmed config-change window, inspect the selected backup first, and avoid scheduling it as a background watchdog unless the trigger timing, confirmation, and rollback scope are tightened.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation describes automatic restoration of configuration files and Gateway restarts without a prominent warning about these side effects. In a configuration-management skill, undisclosed automatic rollback and service restart behavior can cause unexpected downtime, overwrite intentional changes, or interfere with incident response and debugging if triggered at the wrong time.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.