OpenClaw Infer

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward guide for using the OpenClaw inference CLI, with expected provider and file-output behavior but no hidden or destructive instructions.

Install only if you trust the npm openclaw package and the providers configured behind it. Treat prompts, search queries, audio, images, and videos passed to infer commands as data that may leave the local environment, and avoid sending secrets or regulated personal data unless authorized.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly promotes provider-backed inference features including model, image, audio, video, web-search, and embeddings, which inherently transmit user prompts, files, or queries to external services. The documentation does not warn users that sensitive text, media, or search content may leave the local environment, creating privacy and compliance risk if operators assume the CLI is purely local.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal