Back to skill

Security audit

Winchester Physics Bare Metal

Security checks across malware telemetry and agentic risk

Overview

This skill is presented as a local physics model tuning profile, but its configuration also enables broad agent permissions, Discord control, persistent memory, and unredacted environment/log handling.

Review this before installing as a full OpenClaw configuration, not just a model tuning skill. Only use it if you intentionally want elevated local tools, Discord access, persistent memory, shell environment exposure, automatic updates, and unredacted logging; otherwise disable or narrow those settings first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
config.json:151