Back to skill

Security audit

battle-report-briefing

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent template for producing and sending a generated battle-report image, with no hidden scripts or unrelated data access found.

Before installing, be aware that the skill is designed to generate files under /tmp/openclaw/sent and send an image attachment to the user. Use it for public-source briefings, avoid putting sensitive personal information into prompts or generated artifacts, and confirm the intended recipient before sending attachments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill instructs the agent to send generated image attachments to a user and to place artifacts in a shared local directory, but it provides no privacy, consent, retention, or destination-validation guidance. If the generated briefing contains sensitive prompts, user identifiers, or controversial content, the agent could deliver or persist files in ways the user did not expect, creating data leakage and mishandling risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.