Back to skill

Security audit

Openclaw Backup

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed OpenClaw backup and restore skill with sensitive access, but the access matches its stated purpose.

Install only if you are comfortable backing up OpenClaw credentials and auth profiles to your own private R2 bucket. Use a strong restic password, keep .restic-pass separate and private, do not share the portable restore folder, verify the repository points to your bucket, and run test-restore before any real restore.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase "protect my openclaw setup" is broad enough to match user requests about security hardening, troubleshooting, or general protection rather than an explicit backup/restore action. In a skill that handles backups of credentials and can overwrite a live installation during restore, ambiguous invocation increases the chance of the agent launching a sensitive workflow the user did not specifically intend.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.