xAI Image Generator

Security checks across malware telemetry and agentic risk

Overview

The skill’s stated image-generation purpose is coherent, but the reviewed bundle is missing the main executable that would handle the API key, prompts, network calls, and generated files.

Review or obtain the missing xai-gen executable from a trusted source before installing or providing an xAI API key. Use a dedicated limited-scope key if possible, expect prompts to be sent to xAI, avoid confidential or personal data in prompts, and only persist the API key in shell profiles if you accept local plaintext exposure.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README explicitly advertises automatic attachment of generated images to downstream OpenClaw messages, but it does not warn users that prompts or generated files may be propagated beyond the local tool boundary. In agent workflows, this can cause unintended disclosure of sensitive or misleading content if images are auto-attached without operator review.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal