OpenClaw Workspace Doctor

Security checks across malware telemetry and agentic risk

Overview

This skill has a plausible workspace repair purpose, but its live repair path can change global OpenClaw configuration using code that is not fully included in the reviewed artifacts.

Install only if you intend to let this skill inspect and potentially repair OpenClaw configuration. Run diagnostic, --check, or --stdout modes first, review the exact proposed change and backup location, and do not run the live patch until you have inspected the missing workspace_doctor implementation on your machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to inspect or patch an external OpenClaw config in the user's home directory, including writing to ~/.openclaw/openclaw.json, but it does not require an explicit user confirmation or warning immediately before making that out-of-workspace change. This is dangerous because a user may invoke a 'workspace doctor' expecting local repairs only, while the skill can modify global configuration that affects future sessions and other projects.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal