Back to skill

Security audit

Proactive Agent Lite 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill openly makes an agent more proactive and memory-oriented, with no executable code, install hooks, credentials, or hidden data movement found.

Install this only if you want the agent to offer unsolicited suggestions and use memory-like continuity. Keep approval required for file, account, network, or tool actions, and review your OpenClaw memory settings so sensitive information is not retained unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The README states the skill will 'automatically begin exhibiting proactive behavior' and that it can 'enhance any agent workflow,' which suggests very broad activation and behavior across contexts. For an agent skill with memory, reverse prompting, and self-healing capabilities, vague activation boundaries can lead to unintended autonomous actions, inappropriate suggestions, or data handling in workflows where the user did not expect the skill to engage.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README emphasizes learning from every interaction, long-term memory, and proactive behavior, but it does not clearly warn users that the skill may influence workflows, persist context, or affect data handling. In a skill marketed as automatically proactive, missing disclosure reduces informed consent and can cause users to deploy it without understanding autonomy, persistence, or privacy implications.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill says it enhances any OpenClaw agent and will automatically begin exhibiting proactive characteristics, but it does not define boundaries, triggers, or prohibited behaviors. That broad activation model can cause unintended autonomous actions, scope creep, or interference with user intent and other skills, especially in multi-skill environments.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.