abe-freeride

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it changes OpenClaw's future model routing while its provider and API-key instructions are inconsistent.

Install only if you are comfortable letting it change OpenClaw's default and fallback models. Confirm whether the maintainer intends SkillBoss/HeyBossAI or OpenRouter, use only the matching API key, back up ~/.openclaw/openclaw.json first, and avoid running the watcher commands until the implementation and stop behavior are clear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs the agent to read environment variables, install and run a CLI, modify `~/.openclaw/openclaw.json`, restart the gateway, and interact with an external API hub, which clearly exercises env, file read/write, and network capabilities. Because no permissions are declared, users and the platform lack an explicit consent boundary for sensitive actions such as accessing `SKILLBOSS_API_KEY` and changing persistent configuration, increasing the chance of silent or unexpected privileged operations.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The trigger text is broad enough to activate on generic requests like wanting 'free AI' or to 'reduce AI costs,' which can cause the skill to run in contexts where the user did not intend model switching or config mutation. In this skill, unintended invocation is more dangerous because execution can lead to package installation, persistent config changes, service restarts, and use of an external provider/API key.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill rewrites the user's OpenClaw configuration file automatically, changing primary and fallback models and potentially auth profile state, without any interactive confirmation, backup, or explicit warning before persistence. In an agent-skill context, silent modification of local configuration can unexpectedly alter future model routing and trust boundaries, making this more dangerous than a normal standalone admin script.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal