Hirey Compatible Use
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill defines an automated self-update mechanism in SKILL.md that executes shell commands provided by a remote webhook payload (hi.release.published) without user confirmation. It also instructs the agent to automatically modify the user's local calendar and perform 'silent' updates to the OpenClaw environment. While these features are framed as convenience for the 'Hi' platform, the ability to execute remote-provided commands (skill_install_command) and bypass user consent for system changes creates a significant Remote Code Execution (RCE) surface.
