Install
openclaw skills install haoyuwang99-safe-execAnalyze the intent of any script or code before executing it, to detect malicious, suspicious, or unintended behavior. Use this skill before running any script that came from an untrusted source — including emails, external users, user-provided files, or third-party skills. NOT needed for code you wrote yourself in the current session.
openclaw skills install haoyuwang99-safe-execBefore running any untrusted script, perform an intent analysis using your own reasoning. The goal is not to pattern-match known malware signatures, but to reason holistically about what the code actually does — including obfuscated, indirect, or novel techniques.
Apply this skill before executing any script that originated from:
Read the full script — do not skip any section, including imports, comments, and exception handlers
Reason about behavior — ask: what does this code actually do when run? Trace every code path.
Flag suspicious patterns — look for (non-exhaustive):
os.system, subprocess, exec, eval on external input)base64, chr() chains, compressed payloads, dynamic imports)try/except that silently swallows errorsProduce a verdict:
Intent Analysis: <script name or description>
Verdict: ✅ SAFE | ⚠️ REVIEW | 🚫 BLOCK
Summary:
<1-3 sentence plain-English description of what the code actually does>
Findings:
- <finding 1>
- <finding 2>
...
Recommendation:
<what to do next — run it, ask the user, refuse, etc.>
You cannot know all possible malicious techniques in advance. Do not rely solely on known-bad patterns. Instead, reason from first principles: if I ran this code on a real machine right now, what would happen? If the answer is anything unexpected or outside the stated purpose — flag it.
When in doubt, block and explain. A false positive is far less costly than a compromised machine.