Model Migration

Security checks across malware telemetry and agentic risk

Overview

This is a coherent OpenClaw model-migration guide, with expected configuration changes but some operational cautions around API keys and installer commands.

Before using it, back up ~/.openclaw/openclaw.json, prefer the interactive auth login flow instead of putting API keys directly in shell commands, and review any remote installer script before running it. Expect the skill to change OpenClaw's configured provider/model and restart the OpenClaw gateway.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent/user to run multiple shell commands that modify authentication, model configuration, and service state, including non-interactive onboarding with secret-bearing CLI flags and gateway restarts, without any explicit warning, confirmation, or rollback guidance. In an agent setting, this can cause unintended reconfiguration, service disruption, or credential exposure in shell history/logs if executed automatically or copied blindly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal