Back to skill

Security audit

openclaw-skill-eeta-audit

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for auditing OpenClaw skills, and its risky-looking snippets are presented as security examples rather than hidden behavior.

This skill is reasonable to install as an audit aid. Treat its command examples as illustrative, and if you run suggested scanners such as npx-based ESLint, prefer pinned versions or a reviewed local installation in a sandbox without unnecessary secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/skill-security-checklist.md:599
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: references/skill-security-checklist.md:599
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
npx eslint scripts/ --plugin security

Technical Analysis

The security checklist recommends invoking ESLint through npx without requiring a reviewed local installation, pinned package versions, a lockfile, or integrity verification.

When the requested executable is unavailable locally, npx may obtain and execute a package from the configured npm registry. The code ultimately executed during an audit can therefore differ from the code reviewed with this Skill. This creates a supply-chain boundary in a security-sensitive workflow.

An attacker would need to compromise a resolved package, its maintainer or registry distribution path, or influence package resolution or registry configuration. The issue does not establish that the referenced packages are malicious; the risk arises from allowing mutable third-party code to execute without pinning and verification.

Attack Path

  1. An agent follows the documented automated security-scanning procedure.
  2. The required executable or plugin is not present in the local project.
  3. npx resolves dependencies through the configured npm registry.
  4. A compromised package release, dependency, registry account, or resolution path supplies attacker-controlled code.
  5. Package installation behavior or the resolved executable runs under the auditing process's identity.
  6. The malicious code accesses resources available to that process, potentially including repository files, environment variables, credentials, and network access.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user or agent running the audit. The accessible scope depends on the surrounding sandbox and may include:

  • Read or modification access to the audited repository.
  • Ac ...[truncated 417 chars]
Remediation
View remediation

Remediation Suggestions

  1. Declare reviewed versions of eslint and eslint-plugin-security as development dependencies and pin them through a committed lockfile.
  2. Install dependencies deterministically in an isolated environment:
    bash
    npm ci --ignore-scripts
    
  3. Invoke only the verified local executable:
    bash
    ./node_modules/.bin/eslint scripts/
    
  4. Prevent automatic remote package acquisition, for example by using an npx mode that refuses installation where supported.
  5. Verify lockfile integrity and review dependency provenance before execution.
  6. Run scanners in a sandbox with read-only repository access where practical, no unnecessary secrets in the environment, restricted outbound networking, and no administrative privileges.
  7. Document the exact scanner and plugin versions required by the Skill.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
OpenClaw Skills are modular capability extensions for AI agents, defined by `SKILL.md` files with YAML frontmatter and prompt instructions. This skill evaluates

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/skill-security-checklist.md (reported line 38)May include surrounding context.

Shell command execution

exec() eval() subprocess.run(shell=True) os.system() child_process.execSync()

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/skill-security-checklist.md (reported line 107)May include surrounding context.

❌ DANGEROUS - Unvalidated paths

user_path = input("Enter file path: ") with open(user_path, 'r') as f: content = f.read() # Could read /etc/passwd!

text

**Example Fix**:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/skill-security-checklist.md (reported line 310)May include surrounding context.

❌ DANGEROUS - Unvalidated paths

user_path = input("Enter file path: ") with open(user_path, 'r') as f: content = f.read() # Could read /etc/passwd!

text

**Example Fix**:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises broad trigger phrases such as general requests to evaluate, compare, review, or scan skills, which can overlap with ordinary conversation and cause unintended activation. In an agent ecosystem, ambiguous activation increases the chance that the skill runs in contexts the user did not clearly intend, potentially producing misleading security judgments or causing downstream tooling/workflow actions based on a mistaken invocation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/skill-security-checklist.md (reported line 420)May include surrounding context.

md
- Vendor-controlled package managers

**Untrusted Sources**:
- Random GitHub repos without verification
- Unofficial mirrors
- Direct download links without checksums

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/skill-security-checklist.md (reported line 483)May include surrounding context.

python
# ❌ DANGEROUS - Certificate validation disabled
import requests
requests.get("https://example.com", verify=False)  # No SSL verification!

# ✅ SAFE - Proper certificate validation
requests.get("https://example.com", verify=True)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/skill-security-checklist.md:79