Back to skill

Security audit

Openclaw Listing Bot

Security checks across malware telemetry and agentic risk

Overview

This skill is openly about automated marketplace publishing, but it asks for broad unattended authority to create, publish, and retire skills without clear approval controls.

Install only if you deliberately want an autonomous system that can create and publish marketplace listings on your behalf. Before use, require manual review before every publish or deprecation action, use a dedicated staging directory, check for secrets or unreviewed files, and avoid running it as a background loop until those controls exist.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs an autonomous loop to create files, run tests, publish content to external platforms, and deprecate assets without any approval gate, user notification, or safety constraints. In this context, the danger is amplified because the bot is designed for continuous operation and external marketplace interaction, so mistakes or prompt-manipulated outputs could cause unauthorized publication, reputational damage, spam, or propagation of unsafe/generated content at scale.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The run instructions direct automated syncing and publishing to zo.pub and other marketplaces without warning that local content from workspace directories will be exposed externally. This is especially risky here because the skill references shared local paths accessible to other agents, creating a realistic path for unintended, sensitive, or maliciously planted content to be published outward.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.