Back to skill
Skillv2.0.0
VirusTotal security
Process-Diagram-Pro · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
ReviewMar 29, 2026, 4:26 PM
- Hash
- 43eca359ecdf9c1d6bebd7708d9fbd4cd947b7e0ad2742ebfbace89cca999ff4
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: process-diagram-pro Version: 2.0.0 The core Python logic for generating chemical diagrams (chem_diagram_v3) appears benign and aligns with the stated purpose. However, the SKILL.md file contains highly irregular and risky instructions directing the AI agent to install external software (agent-browser via npm) and browse external URLs (specifically a Feishu/Lark wiki) to 'troubleshoot' or 'research.' This pattern is a significant indicator of an indirect prompt injection vector, where the agent could be manipulated by malicious instructions hosted on the external site. The inclusion of browser-based automation and global package installation instructions is unnecessary and dangerous for a diagramming tool.
- External report
- View on VirusTotal
