GoalGetter

Security checks across malware telemetry and agentic risk

Overview

GoalGetter is a simple local task and goal tracker that writes disclosed markdown files, with no evidence of hidden data collection, persistence beyond its task files, or destructive behavior.

Install this if you want a local markdown-based task and goal tracker. Expect it to create and update files under ~/.openclaw/goalgetter/. Avoid putting secrets, tokens, or sensitive personal data in tasks or goals, and prefer the reviewed ClawHub package over manually cloning a live repository.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage examples expand activation beyond the declared trigger list, including vague natural-language phrases like "Did meditation" and "How's my meditation goal?". This can cause the agent to invoke the skill unexpectedly and perform file reads or writes on local state when the user may have intended a general conversation rather than a state-changing action.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill description mentions storage location but does not clearly warn that it will create, read, and modify persistent files under the user's home directory. Users may unknowingly authorize local file changes, which is risky because the skill maintains state and can alter personal data across sessions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal