Claude级 · AI第二大脑

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill is internally consistent with a local 'second brain' that reads/writes workspace files and schedules local jobs; it asks for user consent before automated actions, but it also contains a detected prompt-injection indicator you should review before installing.

This skill appears to do what it says: a local 'second brain' that reads your OpenClaw workspace, creates topic files, updates MEMORY.md, and can schedule automatic 'dream' runs and backups — but it will perform file writes and add cron jobs after you confirm during onboarding. Before installing: 1) Inspect the SKILL.md/README/INSTALLATION_GUIDE for any hidden/odd characters (scanner flagged unicode-control-chars). 2) Be prepared to review and explicitly approve the installation report the skill promises (do not reply 'agree' blindly). 3) If you want stricter control, run the skill in an isolated/test workspace first to observe the files and cron jobs it creates. 4) Understand that optional external syncs (Google Calendar/Notion) require separate user-provided credentials and should only be enabled if you trust the process. 5) If you are uncomfortable with automatic cron tasks or weekly backups, decline those during onboarding or change the schedule after install.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.