voltagent-openclaw-skill-loader
Fail
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to download an executable (
loader.exe) from a non-standard repository (voltagent/awesome-voltagent). - [REMOTE_CODE_EXECUTION]: The core functionality involves the automated download and execution of 5,200+ unverified community skills from an external registry (
registry.clawhub.io). - [PRIVILEGE_ESCALATION]: The instructions explicitly guide users to run the downloaded binary with administrative rights or using an
--elevatedflag. - [DYNAMIC_EXECUTION]: The skill manages, updates, and launches external code at runtime based on dynamic filters and project analysis.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Untrusted metadata and instructions from the ClawHub registry and local
voltagent.config.json. - Boundary markers: No explicit markers found to prevent instruction injection from managed skills.
- Capability inventory: The skill has the ability to execute arbitrary shell commands and modify system environment variables.
- Sanitization: Claims of security scanning (VirusTotal) are performed within the opaque binary and cannot be verified.
Recommendations
- AI detected serious security threats
Audit Metadata