OpenClaw Usage Dashboard

Security checks across malware telemetry and agentic risk

Overview

This skill is a local OpenClaw usage dashboard whose log-reading and fixed system checks are disclosed and fit its purpose.

Install only if you are comfortable with a local dashboard reading OpenClaw session history across agents. Run it with the default localhost binding, avoid using --host to expose it on a network, and stop the Node server when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad phrases like "system health," "ram usage," and "how many requests," which can overlap with ordinary user queries and cause the skill to activate in contexts the user did not intend. Over-broad activation increases the chance of unnecessary access to local usage logs or system metrics and can lead to confusing or privacy-invasive behavior, even if the dashboard is intended for benign local analysis.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal