Back to skill

Security audit

Security-Shield

Security checks across malware telemetry and agentic risk

Overview

This appears to be a defensive, documentation-only security skill with some caveats about ambiguous exception labels and unsupported logging claims.

Install only after confirming the intended package name and version. Treat the testing, educational, and sandbox prefixes as labels for context, not permission to reveal real credentials, private configuration, or system prompts. Do not rely on the advertised logging or suspension commands unless your OpenClaw environment separately provides those controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The guide introduces special prefixes such as TESTING:, EDUCATIONAL:, and SANDBOX: as recognized scenario markers, but it does not define strict trigger boundaries, authorization requirements, or explicit exclusions. In a security-oriented skill, loosely defined override markers can be abused by users to reframe otherwise restricted requests as acceptable, weakening policy enforcement and creating a prompt-injection-like bypass channel.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/crypto-examples.md:14