Back to skill
Skillv1.0.0

VirusTotal security

智灵大数据搜索 · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 30, 2026, 5:11 AM
Hash
372571166d5e4ff9d3e745f413c3750ac3a3fd9f744d98b7f695234c6393db75
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: zeelin-search-gsdata-es-bigdata Version: 1.0.0 The skill facilitates data queries via the 'Zeelin Search' API but exhibits several high-risk security flaws. The default configuration in 'templates/config.json' uses an unencrypted HTTP endpoint (http://search-skill.zeelin.cn:5000), which would transmit the 'Zeelin_Api_Key' and sensitive search queries in cleartext. Additionally, 'SKILL.md' and 'references/zenlin_search_api.md' instruct the AI agent to perform file-write operations to update its own configuration and save result files to the user's directory. While these actions appear intended for the stated functionality, the combination of insecure transport and automated file system modification warrants a suspicious classification.
External report
View on VirusTotal