Back to plugin

Security audit

Kling AI

Security checks across malware telemetry and agentic risk

Overview

This skill coherently connects OpenClaw to Kling AI for user-authorized image and video generation, with the main risk being normal credit-consuming OAuth use that is disclosed.

Install only if you intend to connect an existing Kling AI account to OpenClaw. Confirm billable generation settings before submission, use the plugin's OAuth login rather than sharing API keys, and log out through the provided command if you no longer want OpenClaw to retain Kling authorization.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Immediate submission with explicit approval:

> Submit immediately without asking again: create a 5-second, 16:9, 720p single-shot video. A vintage motorcycle slowly stops outside a convenience store on a rainy night.

Status check:
Confidence
92% confidence
Finding
The example explicitly instructs the agent to submit a credit-consuming generation request immediately without a confirmation step. In an OAuth-protected remote service context, this weakens user-consent safeguards and can lead to unintended paid actions or abuse if similar phrasing is followed automatically by the skill.

VirusTotal

62/62 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.