Model Rate Limit Recovery

Security checks across malware telemetry and agentic risk

Overview

This is a coherent rate-limit recovery guide, but it needs review because it can expose API keys and change or rerun scheduled jobs without much safety guidance.

Install only if you intend to let the agent help troubleshoot OpenClaw rate-limit failures. Do not paste real API keys directly into shell history or shared terminals; use a secrets manager or protected env file, redact env output, and verify any cron patch before applying or rerunning jobs because reruns may duplicate external actions or incur API costs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill includes concrete instructions for exporting and storing multiple API keys in shell environment variables, but it does not warn about secret exposure through shell history, process inspection, logs, screenshots, or accidental inclusion in scripts and shared terminals. In this operational context, users are likely to copy-paste these commands during incident recovery, which increases the chance of credential leakage and subsequent unauthorized API usage.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal