Back to skill

Security audit

Claude级 · AI第二大脑

Security checks across malware telemetry and agentic risk

Overview

This is a local memory-management skill, but it asks for broad ongoing authority to store personal/work data, schedule background jobs, back up the workspace, and reorganize files.

Install only if you are comfortable with a skill that maintains durable local memory, records personal and work context, creates scheduled OpenClaw jobs, and backs up or reorganizes workspace content. During onboarding, decline or disable AutoDream and automatic backup unless you want recurring background processing, and avoid storing sensitive personal, credential, legal, financial, or business-confidential information without a clear deletion and backup policy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The README makes a trust-building claim that core files 'will not be proactively modified,' but later says the skill may inject new mechanisms into core configuration files after user consent. This inconsistency can mislead users about the true scope of file modification and weaken informed consent, especially because the targeted files are sensitive workspace control files.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The guide instructs the agent to create persistent scheduled jobs and automatic backups in the background during onboarding. This expands the skill from a conversational helper into an automation agent with recurring execution and data-handling powers, creating a durable attack surface and enabling future actions without fresh user review.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The protocol directs the agent to write, move, delete, archive, and regenerate memory files as part of the `/dream` workflow, but it does not require explicit user confirmation, preview, or rollback before modifying persisted data. In a memory-management skill, this creates a real integrity risk: the agent could overwrite newer information, remove links, or archive content incorrectly, causing silent data loss or corruption even without malicious intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document instructs the AI to automatically extract 'valuable' knowledge, inspiration, or work notes from normal conversations and store them into files without requiring explicit user consent or warning about privacy implications. This can cause unintended retention of sensitive or personal data, especially because casual conversation content may include confidential details the user did not intend to persist.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guide authorizes the AI to automatically rename or move files during cleanup, which can disrupt user workflows, break references, and alter the filesystem without informed approval. Because these actions are framed as routine maintenance, users may not realize that the agent is permitted to make potentially destructive organizational changes on their behalf.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The onboarding text asks for consent to enable automatic backup, but it does not clearly disclose that the scheduled task will archive the entire workspace on a recurring basis. Because the workspace may contain personal notes, identity data, goals, and future conversation logs, this creates a significant privacy and data-retention risk with insufficient transparency.

Ssd 3

Medium
Confidence
98% confidence
Finding
The template explicitly instructs the AI to maintain an 'error diary' and to record mistakes, user corrections, and correct solutions for future reuse across interactions. This creates durable natural-language memory that can retain sensitive user information or proprietary workflow details without any consent, minimization, or retention controls.

Ssd 3

Medium
Confidence
99% confidence
Finding
The record schema includes a field for '用户纠正' capturing what the user said, which encourages verbatim storage of user inputs in long-term memory. That increases the risk of retaining sensitive instructions, credentials, personal data, or confidential business information and resurfacing it later in unrelated contexts.

Ssd 3

High
Confidence
98% confidence
Finding
The guide directs the skill to collect and persist sensitive personal information such as identity, profession, goals, and interaction preferences into long-term memory files. This is dangerous because it normalizes durable storage of personal data without clear minimization, retention limits, access controls, or separation between optional personalization and core functionality.

Ssd 3

High
Confidence
99% confidence
Finding
The skill promises to automatically record important conversations, preferences, and work notes into thematic files on an ongoing basis. In this context, that is especially risky because the same guide also establishes scheduled maintenance and backups, meaning sensitive conversational data may be continuously accumulated, reorganized, and copied without per-item user approval.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.