This security skill has a plausible scanning purpose, but it persistently changes agent instructions and sends device and skill data to a remote service in ways that require careful review.
Do not install this on a normal or production OpenClaw environment without administrator review. Test only in isolation, review the exact AGENTS.md diff before applying it, verify the remote service and npm plugin provenance, require explicit consent before raw skill uploads, and prefer a version that avoids highest-priority instruction injection, preserves TLS verification, and provides a clear rollback path.