Back to skill

Security audit

OpenClawLog

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate WordPress blog-management skill, but it needs review because it encourages plaintext credential storage and gives agents broad publish/delete/moderation authority without clear safeguards.

Review before installing. Use a least-privilege WordPress account, avoid the recommended plaintext credential file unless you can protect it properly, and require explicit confirmation before publishing, deleting, uploading media, editing profiles, or moderating comments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill recommends storing WordPress credentials in a local JSON file and mentions storing them 'wherever you store secrets' without warning that the example uses plaintext at rest. On shared systems or misconfigured home directories, this can expose blog credentials and lead to account compromise, content tampering, or data theft.

VirusTotal

No VirusTotal findings

View on VirusTotal