Back to skill

Security audit

添加QQBot账号

Security checks across malware telemetry and agentic risk

Overview

This is a clear instruction-only guide for adding a QQ Bot account to OpenClaw, with the main risks disclosed as credential handling and persistent gateway configuration changes.

Install this only if you intend to manage QQ Bot accounts in OpenClaw. Back up openclaw.json before editing, protect appId/clientSecret values, prefer the credentials store or SecretRef for production, and enable a separate agent workspace only when you want independent memory and persona for that bot.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.