Back to skill
Skillv2.0.0

VirusTotal security

Process-Diagram-Pro · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewMar 29, 2026, 4:26 PM
Hash
43eca359ecdf9c1d6bebd7708d9fbd4cd947b7e0ad2742ebfbace89cca999ff4
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: process-diagram-pro Version: 2.0.0 The core Python logic for generating chemical diagrams (chem_diagram_v3) appears benign and aligns with the stated purpose. However, the SKILL.md file contains highly irregular and risky instructions directing the AI agent to install external software (agent-browser via npm) and browse external URLs (specifically a Feishu/Lark wiki) to 'troubleshoot' or 'research.' This pattern is a significant indicator of an indirect prompt injection vector, where the agent could be manipulated by malicious instructions hosted on the external site. The inclusion of browser-based automation and global package installation instructions is unnecessary and dangerous for a diagramming tool.
External report
View on VirusTotal