voltagent-openclaw-skill-loader

Fail

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to download an executable (loader.exe) from a non-standard repository (voltagent/awesome-voltagent).
  • [REMOTE_CODE_EXECUTION]: The core functionality involves the automated download and execution of 5,200+ unverified community skills from an external registry (registry.clawhub.io).
  • [PRIVILEGE_ESCALATION]: The instructions explicitly guide users to run the downloaded binary with administrative rights or using an --elevated flag.
  • [DYNAMIC_EXECUTION]: The skill manages, updates, and launches external code at runtime based on dynamic filters and project analysis.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Untrusted metadata and instructions from the ClawHub registry and local voltagent.config.json.
  • Boundary markers: No explicit markers found to prevent instruction injection from managed skills.
  • Capability inventory: The skill has the ability to execute arbitrary shell commands and modify system environment variables.
  • Sanitization: Claims of security scanning (VirusTotal) are performed within the opaque binary and cannot be verified.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 12, 2026, 06:50 PM
Security Audit — agent-trust-hub — voltagent-openclaw-skill-loader