Back to skill

Security audit

Nvidia Model Config

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local helper for adding NVIDIA model configuration to OpenClaw, with credential-handling cautions but no evidence of hidden or malicious behavior.

Install only if you want OpenClaw configured for NVIDIA models. Use --dry-run and --backup before writing, prefer NVIDIA_API_KEY or a protected env file instead of --key on the command line, review the optional systemd user override before enabling it, and avoid --inline-key except for short-lived local testing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs users to run a local script that reads and writes configuration files, consumes environment variables, and uses shell/systemd commands, yet the skill declares no permissions. That mismatch is a real security issue because it hides the skill's operational capabilities from reviewers and users, reducing informed consent and making it easier for a modified or future version to perform sensitive actions unexpectedly.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal