Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/nextcloud.js:15147
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a disclosed Nextcloud integration, but it needs a Nextcloud app password and can read, create, edit, upload, download, and delete account data.
Install only if you want OpenClaw to access and modify your Nextcloud data. Use a dedicated app password, avoid administrator credentials, test with low-risk data first, and be careful with upload, edit, and delete commands. The registry metadata appears stale, so rely on SKILL.md and script review rather than the registry requirement fields alone.
55/55 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access