Claw Time Machine

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed OpenClaw backup, restore, and migration tool, with sensitive access that matches its stated purpose.

Install only if you want a tool that can copy and restore sensitive OpenClaw state, including credentials and identity files. Review the backup contents, keep archives private, and use restore, migrate, and --force only when you clearly intend to overwrite OpenClaw state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description contains broad trigger phrases like backup, restore, migration, and generic multilingual synonyms that can cause the skill to activate on loosely related user requests. Because this skill performs destructive and highly sensitive operations involving credentials, identity, and remote migration, over-triggering increases the chance of unintended execution and unsafe disclosure or modification of state.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal