openclaw-skill-ideation

Security checks across malware telemetry and agentic risk

Overview

This planning skill appears purpose-aligned, but it may inspect your project and create planning documents in a disclosed folder.

Install this only in workspaces where you are comfortable with the agent reading relevant project files and writing planning docs under ./docs/ideation/. Review generated contracts, specs, and validation commands before approving or running them, especially in repositories containing secrets or sensitive business code.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to match many ordinary planning, brainstorming, or feature-spec requests, which increases the chance of unintended auto-invocation. When combined with later instructions to explore the codebase and write files, this can cause the agent to perform side effects or access more project context than the user explicitly requested.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill mandates creating multiple files under ./docs/ideation/{project-name}/ but does not require prior user notice or consent at the time of execution. This creates an unauthorized side effect risk: an agent could modify the working tree, generate unwanted artifacts, or interfere with user workflows simply from a planning-style request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal