Kimi Usage Monitor

Security checks across malware telemetry and agentic risk

Overview

This skill appears intended for Kimi quota monitoring, but it should be reviewed because its browser automation can inspect broader authenticated browser content than the Kimi console.

Review before installing. Use this only if you are comfortable giving the skill OpenClaw browser access to a logged-in Kimi session. Keep the attached browser context limited to the Kimi console, and consider changing the scraper to select the exact Kimi console tab from the tab list before taking any snapshots. For autonomous use, change the subagent guard to fail closed when quota checks cannot be completed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal