Back to skill

Security audit

Openclaw Skill

Security checks across malware telemetry and agentic risk

Overview

This personal finance skill is coherent and disclosed, but users should be careful because it can create local financial records through an external CLI.

Install this only if you want an agent to help manage personal finance records. Review the external npm/GitHub CLI before use, keep the local data directory private, and require confirmation before adding transactions, setting budgets, or changing existing records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The auto-trigger keywords are broad generic finance terms such as "money," "finance," and "income," plus broad behavioral cues like "manage money." This can cause the skill to activate in ordinary conversations and lead an agent to execute local CLI finance actions in the wrong context, increasing the chance of unintended data creation or disclosure of personal financial records.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal