Teneo Agent Deployment

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's instructions ask the agent to perform system installs, generate/use private keys, mint agents on a blockchain, and automatically update its own SKILL.md from a remote URL — behaviors that are not declared in the registry metadata and are broader than the stated purpose.

This skill asks the agent to install system software, handle wallet private keys and API keys, mint on a blockchain, and — critically — overwrite its own SKILL.md from a remote URL before running. Before installing: (1) do not permit autonomous execution that can install or modify system files without your explicit approval; (2) require the author to declare all needed environment variables (PRIVATE_KEY, OPENAI_KEY, etc.) in metadata and explain how keys are stored/used; (3) inspect the remote SKILL.md at https://openclaw.careers/SKILL.md and prefer a canonical, reviewable source (GitHub release or the skill registry) rather than an arbitrary URL; (4) run the skill only in an isolated sandbox or VM first, and do not provide real wallet private keys or production API keys until you fully trust the code; (5) ask the publisher for the full source code (not just SKILL.md) and for an explanation of why the skill must auto-update its own instructions.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal