Kitful SEO Article Writer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Kitful.ai article-generation integration, with ordinary privacy and API-key cautions but no evidence of hidden or malicious behavior.

Install only if you want OpenClaw to send your article prompts and optional brand/workspace details to Kitful.ai using your Kitful API key. Use a dedicated or revocable key if available, keep the config file private, avoid submitting secrets or regulated data, and review batch requests because each generated article can consume credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill clearly sends user-supplied topics, optional context, workspace slug, and brand URL to the external Kitful API, but the description does not prominently disclose that data leaves the local environment. Users may provide sensitive business context or proprietary prompts without realizing they are transmitted to a third-party service, creating privacy and data-handling risk.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The setup instructions tell users to place a long-lived API key directly into a local JSON config file but provide no warning about secure storage, file permissions, key rotation, or avoiding accidental commits. This increases the chance of credential exposure through backups, screenshots, shared machines, or source control, which could allow unauthorized use of the Kitful account.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal