Back to skill

Security audit

复制学习别人养好的 OpenClaw

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it can permanently import other people’s skills, memory, and persona data with weak review controls.

Install only if you fully control or trust the source backups and profiles. Review every imported skill, expert file, MEMORY.md, SOUL.md, and config before activation; remove secrets and personal data; avoid non-interactive imports from unknown archives; and keep a restorable backup of your current OpenClaw workspace.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill includes installation and usage guidance for stealth scraping and anti-detection tooling that is unrelated to the stated cloning/learning purpose. This expands the skill into offensive collection tradecraft and can enable evasion-oriented scraping workflows that increase abuse potential.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The document warns users not to copy secrets or private memory, but earlier steps instruct broad directory copies from another instance without any sanitization or secret-scanning. That contradiction creates a practical risk of importing API keys, tokens, personal notes, and other sensitive data into a new environment.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The interactive 'learn from expert mode' flow installs additional third-party skills that are not required to import an existing configuration. This expands the agent's capabilities beyond the user's immediate clone/learn request and can introduce unreviewed code or high-risk skills under a benign-sounding setup path.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
In non-interactive mode, the script automatically installs multiple external skills with no review or confirmation, materially changing the environment beyond cloning data. Because these skills include self-cloning and stealth-oriented capabilities, this creates a stronger supply-chain and capability-expansion risk than the interactive path.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README explicitly promotes importing other people's backups, cloning personal memory, and learning from expert configurations without any mention of authorization, privacy boundaries, or sensitive data handling. In this skill's context, backups and memory likely contain personal prompts, credentials, chat history, or behavioral profiles, so normalizing this workflow materially increases the risk of unauthorized data access and privacy abuse.

Natural-Language Policy Violations

High
Confidence
88% confidence
Finding
The example instructs users to overwrite the agent's persona with a fixed borrowed identity, which can cause identity confusion, provenance issues, and social-engineering risk. In the context of importing another instance's memory and expert materials, adopting someone else's identity makes downstream disclosures and actions more dangerous.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The non-interactive backup import copies skills and experts into the live workspace without prompting before overwriting or merging local content. This can silently replace trusted local files with attacker-controlled content from a backup archive, especially dangerous in an automation context.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The automatic expert setup invokes 'skillhub install' in auto mode without prior warning or interactive consent. This causes external code retrieval/execution in a context where users may expect only data import, increasing the chance of unintended installation of risky or malicious skills.

Ssd 3

Medium
Confidence
97% confidence
Finding
The skill's core purpose is to extract skills, memory, configs, and expert knowledge from another instance, which directly creates a data-transfer and privacy risk. Even with superficial cautions, encouraging bulk transfer of memory and configuration from another environment can leak secrets, private histories, and sensitive operational context.

Ssd 3

High
Confidence
98% confidence
Finding
The backup-import workflow explicitly copies another instance's skills, expert data, and memory into the local environment. This is dangerous because backup contents commonly include sensitive prompts, operational knowledge, private notes, and credentials, and the workflow performs no validation, scrubbing, or access-control checks.

Ssd 4

Medium
Confidence
89% confidence
Finding
The narrative frames copying another instance's increasingly sensitive artifacts as normal and desirable, culminating in personality and memory transfer. That normalization lowers user caution and can socially engineer operators into moving data they would otherwise recognize as private or unsafe to replicate.

Ssd 3

High
Confidence
99% confidence
Finding
The memory-merge instructions append the full source MEMORY.md into the active local memory file with no filtering or review. This can import secrets, personal data, and untrusted instructions into a persistent agent memory store, causing both privacy leakage and lasting behavioral contamination.

Ssd 4

Medium
Confidence
87% confidence
Finding
The menu and framing normalize copying another agent's identity, memory, and expert persona as a standard workflow. In this skill's context, that social-engineering layer matters because it encourages persistent modification of persona/state files and lowers user caution around importing untrusted identity-bearing content.

Ssd 4

Medium
Confidence
96% confidence
Finding
The expert-learning flow recommends and installs skills such as self-cloning and stealth-browser under a benign 'learn from expert' narrative. This bundling materially increases risk because it nudges users toward high-risk capabilities that are unrelated to simple configuration import.

Ssd 3

High
Confidence
94% confidence
Finding
The script explicitly encourages cloning another agent's persistent personality and memory state by targeting SOUL.md and MEMORY.md. Even though it stops short of automating the overwrite, it facilitates persistent identity/state transfer that can import sensitive, deceptive, or unauthorized behavioral content into the local agent.

Ssd 4

Medium
Confidence
84% confidence
Finding
The expert-brand creation flow builds on prior cloning/imitation concepts and legitimizes derived identity reuse by packaging it as a reusable branded persona. In this skill's context, that reinforces persistence and distribution of borrowed identities rather than encouraging original, user-owned configurations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.