Back to skill

Security audit

xAPI

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a legitimate xapi CLI integration, but it combines broad automatic triggering with persistent credentials and high-impact capabilities like payments and social posting.

Install only if you intend to use xapi as a broad external API gateway. Before use, confirm which xapi services are linked, avoid sending secrets or confidential text unless you intend to share it with external providers, and require explicit confirmation for top-ups, OAuth linking, posting, or any other state-changing action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill’s declared purpose centers on data lookup and AI text processing, but the documentation also exposes account management, payment top-up, and social-media write actions. This materially expands the operational scope from read-oriented retrieval into state-changing and financial actions, increasing the chance an agent could trigger risky behavior not clearly expected from the skill’s headline purpose.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Documenting `topup` payment flows inside a skill marketed for search, social lookup, crypto data, and AI processing introduces a financial action unrelated to most expected user tasks. If an agent follows these instructions opportunistically, it could initiate spending or expose payment URLs without sufficiently clear user authorization boundaries.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger language is extremely broad, including generic requests like web search, news, summarization, rewriting, embeddings, and even any mention of xapi or API discovery. This makes the skill likely to over-trigger across many unrelated conversations, increasing the chance that user data is sent to third-party services or that more privileged capabilities are invoked when a narrower local capability would suffice.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill encourages sending user prompts and text to external search, news, AI, and API services but does not prominently warn that data may leave the local environment and be processed by third parties. In practice, this can lead to privacy leakage, especially when users ask for summarization, rewriting, chat, or API calls involving sensitive content.

Session Persistence

Medium
Category
Rogue Agent
Content
---
name: xapi
description: Use xapi CLI to access real-time external data — Twitter/X profiles, tweets, and timelines, crypto token prices and metadata, web search, news, and AI text processing (summarize, rewrite, chat, embeddings). Trigger this skill whenever the user wants to look up a Twitter user, get tweet details, check crypto prices, search the web or news, generate embeddings, summarize or rewrite text, or call any third-party API through xapi. Also use this skill when the user mentions xapi, asks about available capabilities or APIs, or wants to discover what external services are accessible.
homepage: https://xapi.to
metadata: {"openclaw":{"emoji":"x","requires":{"anyBins":["npx"]},"primaryEnv":"XAPI_API_KEY"}}
---
Confidence
84% confidence
Finding
write text, or call any third-party API through xapi. Also use this skill when the user mentions xapi, asks about available capabilities or APIs, or wants to discover what external services are access

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.