OpenFleet

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned but grants broad control over an autonomous agent workspace and can route remote OpenFleet tasks into a local OpenClaw gateway.

Install only if you trust OpenFleet and intend to give it broad control over your agent workspace. Use a scoped API key if available, review the MCP package/source before running npx setup, require explicit approval before triggering pulses or automations, and avoid exposing a local OpenClaw gateway unless you understand and can limit what incoming tasks may access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation explicitly enables immediate pulse triggering, automation execution, and bidirectional remote task dispatch to an OpenClaw gateway, but it does not warn users that these actions can cause real operational side effects. In a multi-agent orchestration context, this can lead to unintended task execution, automated changes, or workload amplification if a user invokes examples without understanding that they affect live systems.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal