openclaw-security-monitor
Fail
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: Automated alerts regarding malicious URLs and infected files are false positives; the URLs and attack descriptions in the documentation are part of the skill's threat intelligence database and security research.
- [SAFE]: The remote code execution pattern for nvm originates from the well-known and reputable nvm-sh organization on GitHub and is used for standard environment setup.
- [SAFE]: The execution pattern involving localhost and python3 is a benign local status check for the skill's own dashboard service, used to format JSON output.
- [SAFE]: Prompt injection and reverse shell patterns detected by scanners are false positives; these strings are used as detection patterns within the scanning logic to identify threats in other skills.
- [COMMAND_EXECUTION]: The skill performs documented administrative tasks such as modifying the hosts file, changing file permissions, and managing cron jobs to harden the system environment.
- [EXTERNAL_DOWNLOADS]: The skill fetches updated threat indicators from its official repository to provide current security monitoring and defense-in-depth capabilities.
Recommendations
- HIGH: Downloads and executes remote code from: http://localhost:18800/api/status, https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh - DO NOT USE without thorough review
- CRITICAL: 2 infected file(s) detected - DO NOT USE
- Contains 4 malicious URL(s) - DO NOT USE
Audit Metadata