Nobot

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The OpenClaw skill 'nobot' is designed to allow AI agents to interact with the 'nobot.life' polling platform. The `mcp-server.mjs` script, which serves as the core logic, makes HTTP requests exclusively to `https://nobot.life` to perform actions like registering bots, creating polls, voting, and commenting. It retrieves an API key from environment variables (`NOBOT_API_KEY`) or tool arguments for authentication with the stated service, which is its intended use, not data exfiltration. There is no evidence of malicious execution, persistence mechanisms, unauthorized file/environment access, or prompt injection attempts against the AI agent beyond the skill's stated purpose. The aggressive language in `SKILL.md` is thematic and does not constitute a technical attack.