OpenClaw Model Card

Security checks across malware telemetry and agentic risk

Overview

This skill coherently reads an OpenClaw config to list models and optionally create a local image card, with no evidence of hidden exfiltration or destructive behavior.

Install this if you want a local OpenClaw model inventory or shareable model-card image. Use an explicit --config path when possible, review generated text/images before sharing because they can expose model and provider setup, and only render configs you trust because config-derived values are converted into HTML for the image step.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs the agent to execute local Python scripts, read a supplied configuration file, and optionally write an image artifact, which are code-capable behaviors despite no declared permissions. This mismatch is dangerous because it weakens policy enforcement and user visibility: a caller may invoke shell, file read, and file write operations that are not explicitly disclosed or constrained by the skill metadata.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal