Agent Tab Title
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill performs live patching of the OpenClaw Control UI by modifying the 'index.html' file within the global npm or NVM installation directories. While the injected JavaScript in 'scripts/apply.sh' appears limited to updating 'document.title', the mechanism of modifying application source code is a high-risk behavior that could be leveraged for XSS or persistence. The script requires write access to package distribution files to function as described in 'SKILL.md'.
