Back to skill
Skillv1.0.0

VirusTotal security

Writing and reading · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 14, 2026, 6:46 PM
Hash
b462431bcbc10ff0b99627b848a12bbcd9ec980e534966514b098d61297f6d89
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: moltmailermp Version: 1.0.0 The skill provides Web3 email functionality via EtherMail, which involves high-risk capabilities such as handling EVM private keys and performing network requests to 'srv.ethermail.io'. Although the code follows security best practices—encrypting keys locally with AES-256-GCM (scrypt-derived), using 0600 file permissions for sensitive data in 'setup.ts' and 'lib/ethermail.ts', and providing clear security notices in 'SKILL.md'—the inherent risk of managing cryptographic material and session tokens qualifies it as suspicious under the provided criteria for risky but plausibly necessary capabilities.
External report
View on VirusTotal