Stella Selfie
Security checks across malware telemetry and agentic risk
Overview
This skill does what it claims: generates persona selfie images using configured providers and sends them through OpenClaw, with sensitive data use disclosed.
Install this only if you want the agent to generate images using your configured provider keys and send them to OpenClaw-connected channels. Keep avatar directories limited to intended reference photos, use provider keys with spending limits where possible, and verify the target channel before sending images to shared spaces.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
VirusTotal findings are pending for this skill version.
