Back to plugin

Security audit

ZeroAPI Router

Security checks across malware telemetry and agentic risk

Overview

ZeroAPI is a disclosed OpenClaw routing plugin that changes local routing configuration and session model/account selection, with no evidence of hidden exfiltration or destructive behavior.

Install only if you want ZeroAPI to influence OpenClaw model/provider selection across sessions. Before restarting the gateway, review the generated zeroapi-config.json, the selected subscriptions/accounts, and any changes to agent defaults; disable channel advisories if you do not want ZeroAPI notices prepended to replies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation text is broad enough to activate on generic repo-help or product-explainer requests, which can cause the skill to engage outside explicit installation intent. In this skill, unexpected activation is meaningful because the workflow includes local plugin inspection, configuration changes, and restart-oriented guidance, increasing the chance of unintended system-affecting actions.

Session Persistence

Medium
Category
Rogue Agent
Content
- Qwen Portal OAuth
   - xAI Grok OAuth / SuperGrok when OpenClaw exposes native `xai` device-code or browser OAuth or Hermes exposes legacy `xai-oauth`

5. Write `~/.openclaw/zeroapi-config.json` with:
   - `version`: current plugin version
   - `routing_mode`: `balanced`
   - optional `routing_modifier`: `coding-aware`, `research-aware`, or `speed-aware`
Confidence
84% confidence
Finding
The skill instructs persistent modification of a user-scoped configuration file in the home directory, changing runtime routing behavior across sessions. Persistent state changes are security-relevant here because they can silently alter model selection and provider usage beyond the immediate conversation, especially when combined with later steps to align runtime state and restart services.

VirusTotal

62/62 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.