Claude级 · AI第二大脑
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill is internally consistent with a local 'second brain' that reads/writes workspace files and schedules local jobs; it asks for user consent before automated actions, but it also contains a detected prompt-injection indicator you should review before installing.
This skill appears to do what it says: a local 'second brain' that reads your OpenClaw workspace, creates topic files, updates MEMORY.md, and can schedule automatic 'dream' runs and backups — but it will perform file writes and add cron jobs after you confirm during onboarding. Before installing: 1) Inspect the SKILL.md/README/INSTALLATION_GUIDE for any hidden/odd characters (scanner flagged unicode-control-chars). 2) Be prepared to review and explicitly approve the installation report the skill promises (do not reply 'agree' blindly). 3) If you want stricter control, run the skill in an isolated/test workspace first to observe the files and cron jobs it creates. 4) Understand that optional external syncs (Google Calendar/Notion) require separate user-provided credentials and should only be enabled if you trust the process. 5) If you are uncomfortable with automatic cron tasks or weekly backups, decline those during onboarding or change the schedule after install.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
