Skylv Skill Creator

Security checks across malware telemetry and agentic risk

Overview

This is a text-only skill for generating OpenClaw skill templates, with no executable code or hidden access requests found.

Before installing, treat it as a template-writing helper. Review any generated skill before publishing or installing it, especially trigger words, permission lists such as file or calendar access, and any generated publish commands. Do not add credentials or broad permissions to generated skills unless they are clearly needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill advertises broad creation and template-related triggers such as 'create skill', 'build skill', and 'new skill' without clear activation boundaries. In an agent environment, ambiguous triggers can cause unintended invocation during normal conversation, leading the agent to scaffold or propose actions the user did not explicitly request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example guidance explicitly recommends automatic activation based on generic task-related keywords, which normal user dialogue may contain incidentally. This increases the risk of spurious tool/skill activation, context hijacking, or the agent shifting into file/calendar-oriented behavior without sufficiently specific user consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal