SecureSkill scanned proactive-agent by halthelobster on 2026-05-22 using scanner version 0.1.0. Verdict: SAFE. Risk score: 3/10. No threats detected across 10 analysis layers. Platform: OpenClaw.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 624dcd76-299b-492c-90d8-a1e6f051e636.
This skill is a large set of instructions and templates for turning an agent into a proactive assistant with memory, onboarding, and heartbeat routines. It does change a lot of persistent workspace files, so installing it means letting the skill shape how the agent behaves across future sessions. The included shell script is a local security audit tool that reads config and scans files for obvious issues, but it does not phone home. Overall, it looks like an aggressive but transparent productivity framework rather than a malicious package.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Writes to
Runs
Talks to
Permissions Requested
Network Calls
File Writes
3 behaviors were flagged for review. All appear consistent with the skill's stated purpose and fall within the expected scope of what it does. Notably, this skill modifies agent configuration files (AGENTS.md, SOUL.md, TOOLS.md, MEMORY.md), which will persist across future sessions — but this is consistent with its described functionality.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
The package is dominated by markdown instructions that define agent behavior, memory practices, onboarding, and heartbeat routines; there is no hidden executable logic beyond one local audit script.
The main security consideration is persistence: the skill encourages the agent to keep rewriting AGENTS.md, SOUL.md, USER.md, TOOLS.md, MEMORY.md, and related notes, which can strongly influence future sessions if installed.
The included shell script does inspect local files and a home-directory Clawdbot config, but it does not send data anywhere and behaves like a local audit utility rather than an exfiltration mechanism.
Several scanner hits are explained by defensive documentation quoting phrases like 'ignore previous instructions' as examples of prompt injection to detect, not as instructions for the agent to obey.
This is best treated as a powerful behavior-shaping skill that deserves review before use in sensitive environments, but the evidence does not support a malicious or blocking classification.
What to do
No threats detected across all 10 analysis layers
Monitor for future version changes that may introduce new capabilities
Scan ID
624dcd76
Scanner
v0.1.0
Date
May 22, 2026
Risk Score
3
Skill Version
3.1.0
Skill License
unspecified