Baidu Search.Bak

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Baidu web search skill that sends user queries to Baidu using a configured API key, with no hidden persistence or unrelated data access found.

Install only if you intended to use this Baidu Search fork. Use a dedicated Baidu API key if possible, keep ~/.openclaw/openclaw.json private and out of source control or synced backups, rotate the key if exposed, monitor Baidu usage or billing, and avoid sending confidential search terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guide instructs users to place a live API key directly into a local JSON config file and provides no warning about credential sensitivity, file permissions, accidental backup/sync exposure, or avoidance of committing secrets to source control. While this is common operational documentation, it normalizes insecure secret handling and can lead to credential disclosure if the config file is readable by other users, synced to cloud storage, or copied into logs/support bundles.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal