Back to skill

Security audit

tescmd

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Tesla/OpenClaw setup guide, but it warrants Review because it enables agent-connected vehicle control with persistent secrets and includes a risky remote installer pattern.

Install only if you trust the @oceanswave plugin, the tescmd Python package, the Tesla Developer/Fleet API setup, and the OpenClaw gateway you connect to. Prefer official signed Tailscale install methods over curl-to-shell, complete OAuth and vehicle pairing yourself, protect ~/.config/tescmd files with restrictive permissions, avoid passing tokens on command lines, review the runtime tescmd tools before enabling agent use, and know how to stop the node and revoke stored tokens.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The guide includes examples for storing and passing sensitive values such as Tesla client secrets and OpenClaw gateway tokens, but it does not explicitly warn users that these credentials must be protected and never shared, logged, or committed to source control. In a vehicle-control context, exposed tokens or client secrets could enable unauthorized access to Tesla account functions, telemetry, or gateway-connected vehicle operations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.