SecureSkill scanned proactive-agent by openclaw on 2026-04-20 using scanner version 0.1.0. Verdict: CAUTION. Risk score: 5/10. 6 findings across 10 analysis layers. Platform: openclaw.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 65d5f1fb-e729-419f-85ab-69e55f2d2842.
This skill is not overtly malicious, but it is more powerful than a simple prompt template. It teaches the agent to keep long-lived memory files, update its own operating documents, and run a local security audit that inspects credential-related files and the user's clawdbot configuration. I did not find any hidden network exfiltration or hook-based malware behavior. The main reason for caution is that it creates persistent cross-session influence and touches sensitive local files as part of its security-checking workflow.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Writes to
Runs
Permissions Requested
Network Calls
File Writes
6 behaviors were flagged for review. Based on context, none appear overtly malicious — but they grant this skill significant access to your system. This includes writing to agent configuration files (AGENTS.md, SOUL.md, TOOLS.md, MEMORY.md), permanently changing your agent's behavior across all future sessions. While this appears to be within scope of the skill's purpose, review the behaviors below before installing.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
The package is transparent about its core behavior: it wants the agent to maintain memory files, update workspace guidance, and operate more proactively over time.
The included shell script does not exfiltrate data, but it does inspect sensitive local areas such as .credentials, .env files, and the user's clawdbot config, which raises the risk above a purely documentation-only skill.
Persistent updates to AGENTS.md, SOUL.md, TOOLS.md, USER.md, MEMORY.md, and SESSION-STATE.md are intentional here, but they create durable influence across future sessions and should be treated as a meaningful security surface.
There are no hooks, no outbound network code, and no clear malicious payloads. The caution rating reflects moderate sensitivity and autonomy rather than evidence of active compromise.
What to do
Verify all outbound network endpoints match the skill's stated purpose
Check whether the undeclared capabilities are necessary for your use case
Review SKILL.md and reference files for instructions that manipulate agent behavior
This skill modifies agent config files that persist across all future sessions
Scan ID
65d5f1fb
Scanner
v0.1.0
Date
Apr 20, 2026
Risk Score
5
Skill Version
1.0.0
Skill License
unspecified