Back to skill

Security audit

Competitive Agent Loop

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed multi-agent coding workflow, but it can automatically create persistent tasks and message fixed agent sessions without an explicit user confirmation step.

Install this only if you intentionally want automatic multi-agent coding orchestration in an OpenClaw environment configured with the named agents, QQ sessions, workboard tools, and local model endpoints. Consider adding a confirmation step before dispatching agents or creating persistent workboard tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
Declaring that the skill auto-loads without manual trigger can force orchestration behavior onto tasks without explicit user opt-in or contextual suitability checks. In this skill, auto-application is more dangerous because it can initiate multi-agent dispatch, persistent task creation, and external session messaging, increasing the chance of unintended actions, data exposure, or resource consumption.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.