Back to skill
Skillv0.3.3

VirusTotal security

Firesale Stress Test · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 23, 2026, 2:51 PM
Hash
8efe03d652518a23ef743bd93665ba777a614816dc72de9e0c0a62d225578e15
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: firesale-stress-test Version: 0.3.3 The skill bundle is a complex financial stress-testing framework designed to simulate bank 'fire sales' using the ZVT library and EBA 2018 data. It is classified as suspicious due to an explicit instruction in `seed.yaml` (constraint `finance-C-007`) directing the AI agent to use `eval()` for parsing compound expressions within CSV data, which introduces a significant Remote Code Execution (RCE) vulnerability if the input data is untrusted. While the bundle's logic is highly structured and aligned with its stated purpose of regulatory compliance and financial modeling, the requirement for unsafe string evaluation on external data poses a high security risk.
External report
View on VirusTotal