Back to skill

Security audit

Agentvibes Openclaw Skill

Security checks across malware telemetry and agentic risk

Overview

This TTS skill is mostly coherent, but it asks for exec-capable behavior while under-scoping updates, cleanup, downloads, broad triggers, and retained audio.

Review this skill before installing. It appears to be a TTS assistant skill rather than malware, but only use it if you are comfortable with an agent running local commands for audio, downloading voice files, updating the tool, deleting cached audio, and retaining recent spoken outputs. Prefer explicit /agent-vibes commands and avoid enabling broad automatic triggers.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation gives conflicting statements about API key requirements: one section says no extra API key is needed, while a later limitation says the skill requires an API key and cannot be used without one. This can mislead users into enabling or invoking the skill under false assumptions, causing unsafe setup behavior, failed execution paths, or unreviewed credential handling when the agent tries to compensate.

Vague Triggers

High
Confidence
92% confidence
Finding
The listed trigger keywords are extremely broad terms such as 'switch', 'code', 'skill', and 'ai-assistant', which are likely to appear in ordinary conversation. In agent environments, this creates a real risk of accidental skill activation or routing, potentially causing unexpected command execution or state changes without deliberate user intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill advertises update, cleanup, and external voice-download functionality but does not warn users that these actions may fetch remote content, modify local files, or delete cached data. In an exec-capable agent context, missing warnings reduce informed consent and can lead to unintended network access, supply-chain exposure, or destructive cleanup behavior.

Ssd 3

Medium
Confidence
97% confidence
Finding
The skill explicitly promises 'Full reasoning' in high-verbosity mode, encouraging disclosure of internal chain-of-thought or hidden reasoning content. This is dangerous because such output can expose sensitive intermediate analysis, policy-related internals, or information the model should summarize instead of revealing verbatim.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.