Security audit
Model Switch Skill
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only skill for switching configured LLM providers, with the main risk being that future prompts may go to whichever provider the user selects.
Install this if you want help switching OpenClaw LLM providers. Verify the provider base URLs before use, use revocable provider API keys, keep ~/.openclaw/openclaw.json private, and remember that switching providers changes where future model requests may be processed.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
