Back to skill

Security audit

Lmstudio Model Switch

Security checks across malware telemetry and agentic risk

Overview

This is a coherent model-switching helper, but users should understand that API mode routes work to a cloud provider and switching changes OpenClaw configuration.

Install only from the real ClawHub artifact or trusted source, not the placeholder URL in the README. Use local mode for secrets, credentials, proprietary code, or regulated data. Before switching models, expect openclaw.json to be backed up and modified and the OpenClaw gateway to restart briefly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promotes switching between a local model and a cloud API provider, but it does not clearly warn that prompts, conversation content, and possibly sensitive user data may be transmitted off-device when the API mode is selected. In this context, the omission is materially risky because the skill is presented as a convenience feature for model switching, which can cause users to unknowingly route sensitive work to a third-party service.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents direct modification of `openclaw.json` and restarting the OpenClaw gateway service, but it does not present an explicit warning that these actions alter system behavior and may interrupt active sessions or break configuration if the edit is wrong. Even though backup/restore is mentioned, users are not clearly warned about service disruption and configuration risk before using the skill.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.