Back to skill

Security audit

content-rewriter

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed content rewriting and duplicate-checking helper with optional external LLM use and limited local history storage.

Before installing, be aware that local detect mode keeps recent content fingerprints for duplicate checks, and LLM rewrite mode may send submitted content through OpenClaw gateway to 9Router. Keep sensitive unpublished material in local mode unless external processing is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description contains very broad trigger phrases such as content rewriting, cross-platform differentiation, and pre-publish dedup checks, which can cause the skill to be invoked for a wide range of normal content workflows without clear user intent. Over-broad routing increases the chance that sensitive or unpublished user content is unnecessarily processed by this skill and, in rewrite mode, potentially forwarded onward to external components.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly states that LLM mode sends content through an external gateway to 9Router, but the description does not prominently warn users that their content may leave the local environment. This is dangerous because users may submit confidential drafts, business content, or personal data under the assumption of local processing, leading to unanticipated data exposure to third-party services.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.