Back to skill

Security audit

个人RPG

Security checks across malware telemetry and agentic risk

Overview

This is a local task-tracking RPG skill that saves progress on disk and shows no evidence of hidden sharing or unsafe actions.

Before installing, understand that task descriptions, completion history, achievements, stats, and character progress are stored as local JSON files under the OpenClaw workspace. Avoid entering sensitive personal details unless you are comfortable retaining them there, and delete the local personal-rpg data directory if you want to reset or remove the records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
95% confidence
Finding
The documentation explicitly shows that the skill stores persistent data under a local filesystem path, but it does not clearly warn users that their task descriptions, progress, and character data will be written to disk. This creates a real privacy and transparency issue because users may enter sensitive personal routines or goals without understanding that the information persists locally.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.