Back to skill

Security audit

Kimi IM CLI

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Kimi group-chat workflow helper that reads chat context and may store workspace-scoped group memory, with no evidence of hidden or destructive behavior.

Install this only if you want your agent to use kimiim-cli for Kimi group or thread work. Expect it to read group rules, members, recent messages, and relevant files before replying, and to keep group task memory or produced files under the local .openclaw workspace directory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is extremely broad and mandatory, causing the skill to auto-apply to nearly any Kimi group, session, message, file, attachment, or collaboration scenario. In an agent system, this can over-trigger privileged chat/file handling behavior and expand the contexts where the agent reads room history, member rosters, and workspace files, increasing the chance of unnecessary data exposure or misuse.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to persist group memory locally and later also supports downloading Kimi IM files, but it provides no explicit safeguards, consent checks, retention limits, or warnings about sensitive data handling. In a multi-agent chat context, group rules, recent messages, attachments, and derived summaries may contain confidential information, so automatic local storage can create unintended data retention and leakage risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.