OpenClaw Pro

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Gemini image generation tool whose network use and file creation match its stated purpose.

Install only if you are comfortable sending your prompts and any selected input images to Google's Gemini API. Avoid using sensitive images or private prompts unless that data handling is acceptable, and choose output filenames carefully because the script will create the requested file path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The script transmits user prompts and optionally local images to Google's remote API and writes the returned image to disk, but it does not present an explicit warning or confirmation about those side effects at the point of use. In an agent/skill context, this can cause unintentional disclosure of sensitive image content or prompts and unexpected file creation, especially if invoked indirectly by another tool or user workflow.

VirusTotal

38/38 vendors flagged this skill as clean.

View on VirusTotal