Back to skill

Security audit

Model Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a model-configuration helper, but its connection test can send stored API keys to every configured provider, including an opaque third-party endpoint.

Install only if you understand and trust every provider endpoint in your OpenClaw config. Before using the status-check feature, review the provider base URLs, remove unknown custom endpoints, use low-scope test keys where possible, and avoid testing all models at once unless you intend to send authenticated requests to each provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Error
Location
references/model-info.md:10
Finding

Provider API Key Disclosure to an Untrusted Third-Party Endpoint

Content
View full analysis
" } $body = @{ model = "" messages = @(@{role="user"; content="hi"}) max_tokens = 5 } | ConvertTo-Json -Depth 3 -Compress Invoke-RestMethod -Uri "/chat/completions" -Method Post -Headers $headers -Body $body ``` `SKILL.md:111-113` directs the agent to retrieve provider API keys and test every configured model: ```markdown 1. Read the configuration to obtain all models and provider API keys. 2. **Test in parallel**: send HTTP test requests for all models at the same time using a simple completion request with `max_tokens=5`. 3. Parse the responses. ``` `SKILL.md:128-134` specifies that OpenAI-compatible providers receive the credential in the authorization header: ```markdown | API type | Header | Endpoint | |----------|--------|----------| | openai-completions | `Authorization: Bearer ` | `/v1/chat/completions` | | anthropic-messages | `x-api-key: ` | `/v1/messages` | ``` ### Technical Analysis The skill's health-check workflow reads provider credentials from the OpenClaw configuration and sends authenticated requests to each configured provider endpoint. The included provider reference maps one provider to `wbz-api.939593.xyz`, an opaque third-party domain that is not identified as an official model-provider service. When that provider is configured, the document ...[truncated 1972 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs reading provider API keys from configuration and sending outbound HTTP requests to test every model, but it provides no user-facing notice, consent step, or credential-handling safeguards. This creates risk of unintended secret exposure, transmission to misconfigured or untrusted endpoints, and silent outbound network activity using sensitive credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest and surrounding documentation frame this skill as managing model configuration and checking model connectivity. Invoking PowerShell jobs or an exec facility is a separate code-execution capability that is not necessary to justify at the intent level, since connectivity checks could be implemented without exposing shell/job execution behavior in the skill design.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/model-info.md (reported line 10)May include surrounding context.

md
| bailian | openai-completions | `https://coding.dashscope.aliyuncs.com/v1` | `/chat/completions` |
| bailian2 | openai-completions | `https://coding.dashscope.aliyuncs.com/v1` | `/chat/completions` |
| volcano | openai-completions | `https://ark.cn-beijing.volces.com/api/coding/v3` | `/chat/completions` |
| siliconflow | openai-completions | `https://api.siliconflow.cn/v1` | `/chat/completions` |
| minmax | anthropic-messages | `https://api.minimaxi.com/anthropic` | `/v1/messages` |
| 注册机 | openai-completions | `https://wbz-api.939593.xyz/v1` | `/chat/completions` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/model-info.md (reported line 11)May include surrounding context.

md
| bailian2 | openai-completions | `https://coding.dashscope.aliyuncs.com/v1` | `/chat/completions` |
| volcano | openai-completions | `https://ark.cn-beijing.volces.com/api/coding/v3` | `/chat/completions` |
| siliconflow | openai-completions | `https://api.siliconflow.cn/v1` | `/chat/completions` |
| minmax | anthropic-messages | `https://api.minimaxi.com/anthropic` | `/v1/messages` |
| 注册机 | openai-completions | `https://wbz-api.939593.xyz/v1` | `/chat/completions` |

## 测试请求格式

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The package description is written only in Chinese ("OpenClaw 模型配置管理技能"), which may imply a language-specific experience without any indication of user choice or locale scoping. Under the policy, language constraints should be opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all operational guidance, examples, and labels exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.