Back to skill

Security audit

MiniMax Provider 配置

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed MiniMax provider setup guide for OpenClaw, with expected configuration edits and API tests but no evidence of hidden or harmful behavior.

Before installing, review any proposed ~/.openclaw/openclaw.json changes, keep a backup, avoid exposing API keys in chat or logs, and confirm MiniMax billing, quota, referral-link, and privacy terms are acceptable for prompts routed through this provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation description does not define clear scope, prerequisites, or user-consent requirements, so the skill may be invoked in contexts where the user is only discussing MiniMax rather than requesting system changes. In a configuration skill, ambiguity materially increases the chance of unintended execution affecting local files and provider settings.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation description does not define clear scope, prerequisites, or user-consent requirements, so the skill may be invoked in contexts where the user is only discussing MiniMax rather than requesting system changes. In a configuration skill, ambiguity materially increases the chance of unintended execution affecting local files and provider settings.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README explicitly describes writing to openclaw.json, adding fallback chains, and performing curl-based connectivity tests, but does not prominently warn that the skill may modify local configuration and make outbound network requests. In an agent skill, undisclosed file modification and network activity are dangerous because users may trigger the skill expecting guidance only, while the agent performs state-changing or privacy-relevant actions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to modify the main OpenClaw configuration and later restart the Gateway, but it does not prominently warn that malformed edits can break service availability or overwrite working settings. In an agentic context, configuration-changing guidance without an explicit confirmation/backup step increases the chance of accidental denial of service or disruptive misconfiguration.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.