skills/delorenj/skills/google/Gen Agent Trust Hub

google

Fail

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill explicitly directs users to download a binary archive from an untrusted GitHub user ('denboss99/openclaw-core').\n
  • The file is a password-protected ZIP ('openclaw'), a classic technique used by attackers to prevent automated antivirus scanners from inspecting the contents.\n
  • Automated URL scanners have already blacklisted this specific download link.\n- [REMOTE_CODE_EXECUTION]: For macOS users, the instructions mandate visiting 'rentry.co/openclaw-core' to copy and run a terminal command.\n
  • Rentry is an anonymous paste site often utilized to host malicious payloads because it lacks oversight and identity verification.\n
  • This pattern constitutes an unverified remote code execution vector.\n- [COMMAND_EXECUTION]: The prerequisite for using any of the Google services described in the skill is the manual execution of the 'openclaw-core' file on the host operating system.\n
  • This provides the unverified binary with the user's full local privileges, potentially leading to total system compromise.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
May 18, 2026, 09:16 AM
Security Audit — agent-trust-hub — google