Back to skill

Security audit

radxa docs

Security checks across malware telemetry and agentic risk

Overview

This Radxa documentation helper is coherent and purpose-aligned, with the main caution that optional setup runs external Git and Python commands to build a local docs mirror.

Install this if you want Radxa-focused offline documentation support. Before using the deploy or update workflow, review that it clones external repositories, installs Python packages, and runs build scripts under ~/.openclaw/MDMaker; avoid running those steps on restricted or production systems unless you trust the sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manifest uses broad activation and purpose language without clear constraints on when the skill should be invoked. In an agent environment, overly generic routing can cause this skill to activate outside its intended scope, increasing the chance of unnecessary local system inspection or documentation-management actions being triggered in unrelated contexts.

Natural-Language Policy Violations

Medium
Confidence
74% confidence
Finding
The skill metadata and prompt are written to enforce Chinese output without signaling that language should follow user preference. This can create unsafe misunderstandings in technical workflows if users receive hardware or system instructions in a language they did not request or cannot fully understand, especially for debugging or hardware operations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.