Back to skill

Security audit

Creator SKILL

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Deinai influencer-search connector, but users should know searches consume team credits.

Install only if you have a Deinai account and are comfortable giving OpenClaw an MCP token for that account. Searches spend team credits per influencer record returned, so use smaller page sizes when testing and revoke or rotate the token if it is exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation explicitly states that searches consume credits based on the number of returned influencers, but it does not instruct the agent to warn users or obtain confirmation before performing a billable action. In an agent skill, this can lead to unauthorized or surprising charges triggered by ordinary user requests, especially because the tool is framed as a normal search capability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.