Weibo Channel Config

Security checks across malware telemetry and agentic risk

Overview

This is a narrow Weibo setup helper that stores the Weibo AppId and AppSecret in OpenClaw configuration.

Use this only when you intend to connect a Weibo app to OpenClaw. Prefer least-privileged or test credentials, remember the AppSecret will be stored persistently in OpenClaw configuration, and rotate it if it may have appeared in logs, transcripts, or a shared terminal.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to collect an AppSecret and persist it via CLI configuration, but it provides no warning to the user about where the secret will be stored, how long it will persist, or who/what processes may later access it. In an agent setting, this increases the risk of credential exposure through shell history, logs, transcripts, config files, or overbroad host access, especially because the secret is handled as plain text.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal