Add SiliconFlow Provider (98+ Models, Free Tier)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed setup guide for adding SiliconFlow as an OpenClaw model provider, with expected configuration and API-key handling risks.

Install this only if you want OpenClaw to use SiliconFlow. Review the provider, alias, and fallback changes before applying them, verify current pricing and free-tier limits, use a dedicated API key, avoid pasting real keys into shared terminals or chat transcripts, and protect the OpenClaw config file where the key is stored.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match generic admin requests such as adding Kimi, Qwen3, or free models, which could cause the skill to run outside its intended scope of configuring a specific provider. In an agentic system, over-broad activation increases the chance of unintended configuration changes and secret-handling flows being invoked without explicit operator intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to place API keys directly into shell commands and persistent configuration without any guidance on redaction, secure storage, shell history exposure, file permission hardening, or log leakage. This creates a realistic risk of credential compromise through terminal history, screenshots, process inspection, backups, or overly permissive config files.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal