ernie-integration

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate setup guide for using Baidu ERNIE/Qianfan with Clawdbot, with expected privacy and credential-handling caveats.

Install only if you intend Clawdbot requests for this model to be sent to Baidu Qianfan under your API account. Protect the ERNIE_API_KEY like a password, avoid committing shell/config files that contain it, do not send secrets or regulated data unless approved, and ignore the missing test-script instruction unless the script is supplied by a trusted source and reviewed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The README instructs users to send requests and credentials to Baidu's external Qianfan endpoint, but it does not clearly warn that prompts, metadata, and potentially sensitive data will leave the local environment and be processed by a third party. In an agent skill context, this omission can lead users to unknowingly route proprietary or regulated data to an external provider, creating privacy, compliance, and data-governance risk.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal