SkillReported removedCoverage: CoveredPrimary source

x-trends-nvdfx (bundled Windows executable)

Reported by Community report on GitHub (plgonzalezrx8) on . Names, numbers, and dates are as the sources state them.

What it did

The skill shipped a Windows executable named openclaw-agent.exe. The reporter says multiple antivirus engines on VirusTotal flagged it as malicious.

Skill names as reported

  • x-trends-nvdfx

Techniques

  • Bundled executable

Status, as stated by the source

On 13 March 2026 an OpenClaw maintainer wrote that the skill is no longer public and the publisher is no longer reachable.

We do not check the registry ourselves. “Unknown” means no source we found says the skill was removed.

Would Ironheights flag this pattern?

Covered

A bundled .exe is flagged by IH-BIN-001 (high). Ironheights does not judge whether the executable is malware; it flags that one is there.

Rules that fire on a harmless, synthetic copy of the reported pattern. We did not scan the original malware, and a rule firing on the pattern is not a promise about every variant.

Sources

  1. openclaw/clawhub issue #93: Found a malicious skill uploaded by an user. Including malicious binary report.(opens in a new tab)GitHub (openclaw/clawhub issue tracker) · primary
  2. Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap(opens in a new tab)Bitdefender Labs · secondaryNames hightower6eu among the publishers of malicious skills; does not discuss this skill.

Sources are the only outbound links on this page. We never link to the skills themselves or publish their payloads.

Rules that look at neighbouring patterns. They are listed for reading, not as coverage of this entry.