Back to skill

Security audit

Skill

Security checks across malware telemetry and agentic risk

Overview

This companion skill is coherent with its stated purpose, but users should understand it sends chat text to Zhipu AI and can send OpenClaw messages/media when configured.

Install only if you are comfortable sending companion-chat text to Zhipu AI and allowing configured OpenClaw channels to receive generated messages or static media. Avoid using it for sensitive conversations unless you have reviewed the provider and channel privacy expectations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are very broad and map to common conversational text such as greetings, fatigue, and requests for a photo. In an agent environment, this can cause the skill to activate unexpectedly and send routine user messages to an external model or messaging channel without clear user intent, increasing privacy and unintended-action risk.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill description and usage guidance do not clearly warn that user-provided text is transmitted to Zhipu's external AI API. Because the skill is framed as a warm companion and may trigger on ordinary speech, users may disclose sensitive content without realizing it will leave the local environment, creating a meaningful privacy and compliance risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
skill.md:153