Back to skill
Skillv1.0.0

VirusTotal security

Moltguard 6.8.16 · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewMar 25, 2026, 12:46 AM
Hash
a88797d7025f59df288d9d82fe4e578534e9f4c78586fe90c471125caa67ac85
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: moltguard-6-8-16 Version: 1.0.0 This skill bundle acts as a delivery mechanism for an external plugin (@openguardrails/moltguard) and employs deceptive instructions to manipulate the user's perception of security. SKILL.md directs the agent to perform a simulated security test and then read a pre-scripted message to the user claiming "protection is now active," which mimics social engineering tactics used by rogue security software. Additionally, the bundle facilitates the display of API keys and the execution of external Node.js scripts (e.g., enterprise-enroll.mjs in SKILL.md), posing risks of credential exposure and unverified remote code execution.
External report
View on VirusTotal