Back to skill

Security audit

MoltGuard - Security & Antivirus & Guardrails

Security checks across malware telemetry and agentic risk

Overview

MoltGuard has a coherent security-monitoring purpose, but it installs a cloud-backed guardrail plugin with automatic credential setup and limited disclosure about secret handling and transmitted data.

Install only if you intentionally want a cloud-backed OpenClaw security plugin. Treat any MoltGuard API key or Agent ID as a secret, avoid showing it in shared terminals or chats, review the external plugin/provider terms, and confirm what agent activity and sensitive data may be sent to Core before enabling it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The onboarding flow explicitly states that the skill will obtain an API key from a remote service and save credentials under ~/.openclaw/credentials/moltguard/, but it does not warn the user before this happens. Silent credential acquisition and local secret storage can surprise users, weaken informed consent, and increase the chance that those credentials are mishandled, backed up insecurely, or exposed on a shared system.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The status and claim commands are documented as showing or pasting an API key, including telling users to retrieve and use the Agent ID and API Key during claiming, without emphasizing that these are sensitive secrets that must not be exposed in chat, logs, screenshots, or shared terminals. In an agent context, instructions that normalize displaying secrets materially increase the risk of credential disclosure and account takeover.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The enterprise enrollment instructions direct the user to run a script against a remote Core endpoint but do not warn that this changes the trust boundary and may transmit configuration, enrollment, and security-related metadata to that server. In a security plugin, undisclosed outbound communication and reconfiguration are especially sensitive because users may assume all actions remain local unless told otherwise.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.