Is d-wwei/openclaw-nim-skill safe?
Use with caution. d-wwei/openclaw-nim-skill is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the openclaw-nim-skill skill by d-wwei a trust score of 78/100 with 3 findings (1 critical, 1 high).
https://github.com/openclaw/skills/tree/main/skills/d-wwei/openclaw-nim-skill
Is d-wwei/openclaw-nim-skill safe to install?
This NVIDIA NIM integration skill provides legitimate functionality for calling external AI models but has a critical SSL security flaw that disables certificate verification. While the core functionality is benign, the disabled SSL verification creates vulnerability to man-in-the-middle attacks.
What security issues were found in d-wwei/openclaw-nim-skill?
Category Scores
Findings (3)
CRITICAL SSL Certificate Verification Disabled -60 ▶
The Python script disables SSL certificate verification with 'ctx.check_hostname = False' and 'ctx.verify_mode = ssl.CERT_NONE', making API communications vulnerable to man-in-the-middle attacks where attackers could intercept API keys and prompt data.
HIGH User Prompts Sent to External APIs -30 ▶
By design, this skill transmits all user prompts to external NVIDIA API servers, which could include sensitive information. Users should be aware that their conversational data leaves the local environment.
MEDIUM API Key Management Required -25 ▶
The skill requires users to manage and store NVIDIA API credentials in environment variables, adding complexity and potential for credential exposure if not handled properly.
Should I install d-wwei/openclaw-nim-skill?
Oathe's verdict for d-wwei/openclaw-nim-skill is CAUTION with a trust score of 78/100. Recommendation: Install with caution.