Model Manager

Security checks across malware telemetry and agentic risk

Overview

The skill appears to make disclosed OpenClaw configuration changes, but it can delete live model and alias entries without enough safety controls.

Review the exact OpenClaw config changes before installing or using this skill. Back up openclaw.json first, confirm no aliases or defaults still reference removed models/providers, and keep rollback instructions handy. This does not look malicious from the supplied evidence, but it deserves Review because a mistake could disrupt future agent behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs deleting model and alias entries from the live OpenClaw configuration but does not require backups, validation, or user confirmation before destructive changes. This creates a real risk of accidental service disruption, loss of working model routes, or broken defaults if the removed entries are still referenced elsewhere.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal