SecureSkill scanned byterover by byteroverinc on 2026-04-21 using scanner version 0.1.0. Verdict: CAUTION. Risk score: 5/10. 6 findings across 10 analysis layers. Platform: OpenClaw.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 8a549201-02af-41dc-81d5-be202d542c8a.
This skill is not overtly malicious, and it does not include any scripts or hidden code that run on your machine by themselves. However, it strongly pushes the agent to install and use an external ByteRover CLI before doing normal work, and some of those commands can send your project context or file contents to LLM providers or cloud services. In practice, this is more of a trust-and-scope review issue than a malware issue. If you install it, do so knowing it expands your workflow to an external tool and networked memory system.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Writes to
Runs
Talks to
Permissions Requested
Network Calls
File Writes
6 behaviors were flagged for review. Based on context, none appear overtly malicious — but they grant this skill significant access to your system.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
There is no executable code in this package, which materially lowers risk compared with skills that ship shell scripts or lifecycle hooks.
The main concern is trust expansion: the skill asks the agent to install and rely on an external CLI that is not part of this reviewed package.
The documentation openly states that some commands send query text and included file contents to configured LLM providers and that cloud sync is available, so users should treat this as a networked integration rather than a purely local helper.
The wording is unusually forceful for an injected skill, telling the agent to use ByteRover before any work and before performing actions, which can override normal task prioritization.
This lands in CAUTION rather than BLOCK because the risky behavior is documented and indirect, with no embedded scripts, hooks, credential theft, or scanner-evasion content in the package itself.
What to do
Verify all outbound network endpoints match the skill's stated purpose
Check whether the undeclared capabilities are necessary for your use case
Audit all imported dependencies for known vulnerabilities before installing
Scan ID
8a549201
Scanner
v0.1.0
Date
Apr 21, 2026
Risk Score
5
Skill Version
3.3.0
Skill License
unspecified