Back to skill
Skillv0.6.1
VirusTotal security
Skill · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
BenignApr 30, 2026, 4:16 AM
- Hash
- 02089410d5b82ba5e7c319fac05394f0f51b3848e56cef80981c7affc209187a
- Source
- palm
- Verdict
- benign
- Code Insight
- Type: OpenClaw Skill Name: skill-shield Version: 0.6.1 The OpenClaw AgentSkills skill-shield is a security audit tool designed to scan other skills for dangerous patterns. Its `scan.py` code implements robust detection logic, including anti-obfuscation analysis and extensive context-aware false positive reduction mechanisms (e.g., ignoring its own pattern definitions, reducing severity for code in comments/documentation). The `SKILL.md` clearly describes its legitimate security purpose and usage, without any hidden prompt injection commands. While the provided `reports/report.json` and `reports/report.md` show an older version of the scanner (v0.2.0) flagging itself with a 'D' rating due to an undeclared permissions and a false positive `base64_decode` finding, this reflects the scanner's transparency and the developers' subsequent improvements (v0.6.1) to reduce such false positives, rather than malicious intent. The skill's functionality is entirely aligned with its stated purpose of security auditing, with no evidence of data exfiltration, unauthorized execution, or persistence.
- External report
- View on VirusTotal
