Security audit
添加QQBot账号
Security checks across malware telemetry and agentic risk
Overview
This is a clear instruction-only guide for adding a QQ Bot account to OpenClaw, with the main risks disclosed as credential handling and persistent gateway configuration changes.
Install this only if you intend to manage QQ Bot accounts in OpenClaw. Back up openclaw.json before editing, protect appId/clientSecret values, prefer the credentials store or SecretRef for production, and enable a separate agent workspace only when you want independent memory and persona for that bot.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
