Back to skill

Security audit

Skill Creator Enhanced

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for creating and publishing OpenClaw skills, with one copyable shell example that should be hardened before use.

Review and harden the sample test script before using it: validate skill names, quote variable expansions, and install only trusted or pinned skills. The reviewed artifact itself is a Markdown guide and does not execute commands automatically.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:340
Finding

Unvalidated and Unquoted Shell Input in the Test Script Template

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 340–351
Vulnerability Type: Unvalidated shell argument, word splitting, pathname expansion, and CLI option injection
Risk Level: Medium

bash
SKILL_NAME=$1

echo "Testing skill: $SKILL_NAME"

# Validate structure
clawhub validate $SKILL_NAME

# Test installation
clawhub install $SKILL_NAME

# Verify installation
ls -la ~/.openclaw/workspace/skills/$SKILL_NAME

Technical Analysis

The documented test script assigns the first caller-controlled positional argument to SKILL_NAME and subsequently expands it without double quotes. Unquoted shell expansion permits word splitting and pathname expansion, so one supplied value can become multiple command-line arguments or expand into matching filesystem paths.

A value beginning with a hyphen may also be interpreted as an option by clawhub or ls, depending on each command's argument parser. This creates a CLI option-injection risk. The template additionally installs a registry skill without pinning an immutable or explicitly reviewed version, meaning the installed content can vary over time.

Shell metacharacters contained only in the expanded variable are not automatically reparsed as shell syntax. The directly supported exploitation mechanisms are therefore argument splitting, wildcard expansion, and option injection rather than arbitrary shell-command execution.

Because the vulnerable content is a documentation template rather than an automatically executed project script, exploitation requires a user or agent to copy or execute the example.

Attack Path

  1. A user or agent adopts the test script shown in SKILL.md.
  2. An attacker supplies or recommends a specially formed skill-name argument containing whitespace, wildcard characters, or an option-like prefix.
  3. The shell expands the unquoted value into one or more arguments.
  4. clawhub validate, clawhub install, or ls proces ...[truncated 936 chars]
Remediation
View remediation

Remediation Suggestions

Validate the argument against the documented skill-name syntax, quote every variable expansion, reject option-like or malformed values, and use an end-of-options marker where the target command supports it:

bash
#!/bin/bash
set -euo pipefail

SKILL_NAME=${1:?Usage: test-skill.sh <skill-name>}

if [[ ! $SKILL_NAME =~ ^[a-z0-9][a-z0-9-]*$ ]]; then
    printf 'Invalid skill name: %s\n' "$SKILL_NAME" >&2
    exit 1
fi

printf 'Testing skill: %s\n' "$SKILL_NAME"

clawhub validate -- "$SKILL_NAME"
clawhub install -- "$SKILL_NAME"
ls -la -- "$HOME/.openclaw/workspace/skills/$SKILL_NAME"

Confirm that the installed clawhub version supports --; otherwise, rely on strict allowlist validation and the command's documented safe argument syntax. Pin an exact trusted skill version where supported, verify publisher identity and integrity metadata before installation, and test the hardened script with whitespace, wildcard, and hyphen-prefixed inputs.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
|------|--------|---------|
| 1 | Plan skill | Define purpose, audience, triggers |
| 2 | Create structure | Use templates |
| 3 | Write SKILL.md | Follow guidelines |
| 4 | Add resources | Scripts, references, assets |
| 5 | Validate | Run validation |
| 6 | Test | Real-world testing |

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 351)May include surrounding context.

clawhub install $SKILL_NAME

Verify installation

ls -la ~/.openclaw/workspace/skills/$SKILL_NAME

echo "Test complete"

text

Static analysis

No suspicious patterns detected.