Workhorse Duo

PassAudited by VirusTotal on Apr 3, 2026.

Findings (1)

The skill bundle implements a multi-agent orchestration workflow but includes a PowerShell bootstrap script (in published-bootstrap-helper.md) that modifies the local OpenClaw configuration. Specifically, it enables broad cross-agent communication permissions (agentToAgent.allow = ['*']) and performs a service restart (openclaw gateway restart). While these actions are documented as setup requirements and accompanied by rollback instructions in risk-and-rollback.md, the automated modification of security-sensitive configurations and service management constitutes a high-risk capability.