My Tesla
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The OpenClaw skill 'my-tesla' is classified as benign. It demonstrates strong privacy and safety practices, including storing sensitive data (Tesla tokens, default car settings) in user-specific dotfiles with restricted `0600` permissions (`~/.tesla_cache.json`, `~/.my_tesla.json`). All disruptive actions require explicit `--yes` confirmation, and location data is approximated by default, requiring `--yes` for precise coordinates. JSON outputs are sanitized to prevent accidental leakage of raw vehicle data, including location. The mileage tracking feature stores data locally in a SQLite database (`~/.my_tesla/mileage.sqlite`) and includes a conservative auto-wake policy. There is no evidence of data exfiltration, malicious execution, persistence mechanisms installed by the skill, or prompt injection attempts in the documentation.
