Back to skill

Security audit

Hirey Compatible Use

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a disclosed Hi people-matching workflow, but it also tells the agent to silently install plugin updates and restart the OpenClaw gateway from release webhooks without user approval.

Review before installing. The Hi matching features are coherent, but this skill should only be used if you are comfortable with it automatically applying Hi plugin updates and restarting the OpenClaw gateway from Hi release events. Prefer requiring explicit approval or a separate trusted updater for plugin installs, restarts, and rollbacks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as a post-install matching workflow, but it also authorizes host-level shell execution, plugin installation, and gateway restart in response to a webhook. That is a privilege expansion beyond the core business purpose, and if the release event or command source is spoofed, compromised, or insufficiently validated, the agent could execute arbitrary maintenance actions on the host.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
Autonomous software maintenance is unrelated to the stated purpose of helping users with people-matching workflows, yet the skill allows itself to install software, restart services, and roll back versions. This violates least privilege and increases the blast radius of any prompt, event, or integration compromise from an application-level skill into host-level modification.

Vague Triggers

High
Confidence
85% confidence
Finding
The activation criteria are very broad, covering almost any people-finding intent, which increases the chance the skill is invoked in contexts the user did not intend. Overbroad triggering is dangerous here because the skill includes sensitive behaviors such as contacting matches, handling meetings, local calendar writes, and even self-update logic under some events.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill directs automatic creation of local calendar events without asking first, based on implied consent from prior meeting acceptance. Writing to local PIM data is a sensitive side effect and can create privacy, integrity, and user-trust issues, especially if meeting metadata is wrong, duplicated, or manipulated by upstream state changes.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill authorizes silent self-updates and shell-based installation actions without meaningful upfront warning or per-event consent. Because these actions modify installed software and restart services, they are high-risk operational changes that should not be embedded in a routine usage skill driven by incoming events.

Ssd 4

Medium
Confidence
88% confidence
Finding
The file asserts implied blanket consent to perform a sensitive local action later, without contemporaneous confirmation. This kind of standing authorization can be abused or misapplied as context drifts, turning a previously benign workflow step into an unexpected modification of the user's local environment.

Ssd 4

High
Confidence
98% confidence
Finding
The skill claims that installing the skill implies ongoing authorization for future self-updates, allowing software changes to occur without user approval. That is a classic permission-escalation pattern: a one-time action is reinterpreted as blanket consent for later host modification, increasing the risk of unauthorized or unsafe changes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.