Back to plugin

Security audit

Potassium

Security checks across malware telemetry and agentic risk

Overview

This package is a disclosed Infomaniak integration that can read or change kDrive, Mail, kChat, and URL-shortener data when configured, with sensible default mutation and credential safeguards.

Install only if you intend to let OpenClaw access your Infomaniak account through INFOMANIAK_TOKEN. Keep blockMutating enabled unless you deliberately want write actions, consider configuring allowedDomains or allowedOperations to limit scope, and enable kChat inbound WebSocket or webhook modes only for channels where automated replies are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Exfiltration Commands

High
Category
Prompt Injection
Content
---
name: kchat-posting
description: Post messages to Infomaniak kChat through Potassium's native OpenClaw tools backed by the liquid-potassium Node SDK. Use when an agent needs to find kChat teams or channels, create kChat posts, reply in threads with root ids, or post after resolving a channel while following Infomaniak token safety rules.
homepage: https://github.com/OpenCow42/potassium-openclaw
user-invocable: true
metadata: {"openclaw":{"requires":{"config":["plugins.entries.potassium.enabled"],"env":["INFOMANIAK_TOKEN"]},"primaryEnv":"INFOMANIAK_TOKEN"}}
Confidence
90% confidence
Finding
Post messages to

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill’s activation guidance is very broad, covering many Infomaniak services and generic verbs like inspect or manage, which can cause the agent to invoke this skill for loosely related requests without clear user intent. Over-broad triggering increases the chance of unnecessary access to sensitive enterprise data or execution of actions in the wrong service context.

VirusTotal

60/60 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.