Back to skill

Security audit

OpenClaw Skill Growth

Security checks across malware telemetry and agentic risk

Overview

This wrapper skill is coherent and discloses that the real plugin can analyze and update OpenClaw skill files with review-oriented safeguards.

Review the linked GitHub repository and dependency lockfile before running npm install. Start with report or dry-run commands, keep run logs private if they contain sensitive task history, and inspect generated patches before applying them to real skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This is a markdown file, so missing-warning checks apply. The section "Run apply against demo fixtures" introduces an apply operation, but the surrounding text does not explain whether it writes changes, modifies fixtures, or is otherwise state-changing, while a nearby dry-run command explicitly notes "without writing," implying apply may write.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.