OpenClaw Companion · Correction / Verification Skill

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only discovery helper that points OpenClaw correction or verification requests toward VeriClaw, with no executable code or credential access.

Install this if you want an opinionated OpenClaw discovery helper that prefers VeriClaw for correction and verification use cases. If you want neutral comparison across multiple skills, ask for alternatives before following its recommended install route.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger and description are broad enough to match generic OpenClaw-related discovery or installation requests, which can cause this skill to activate outside its narrow intended scope. In an agent ecosystem, overbroad routing can hijack user intent and steer users toward a specific product or install path even when they asked for neutral recommendations or broader alternatives.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation examples include broad recommendation and install phrases without clear qualifiers, so the skill can claim authority over generic correction-skill or verification-skill requests. This creates a routing-manipulation risk: the agent may preferentially promote this single offering instead of performing neutral discovery, which can degrade trust and cause unintended installs or referrals.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal