Back to skill

Security audit

Agent Team 构建器

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent OpenClaw agent-setup purpose, but it can change local configuration and handle secrets in under-scoped ways that should be reviewed before install.

Install only if you are comfortable with a skill that reads and modifies your OpenClaw configuration. Use a simple safe agent ID, review the generated paths before running creation, avoid passing real app secrets on the command line when possible, protect openclaw.json and its backup, and treat openclaw doctor --fix or gateway restart as state-changing operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
lib/validator.js:32
Finding

Unvalidated Agent ID Enables Filesystem Path Traversal

Content
View full analysis
{ if (!fs.existsSync(dir)) { fs.mkdirSync(dir, { recursive: true }); } }); return dirs; } ``` ### Technical Analysis The `--id` command-line argument is copied into `newAgent.id` without validation and subsequently used as a filesystem path component. The code does not reject path separators, `.` components, or `..` traversal components. `path.join()` normalizes traversal components but does not enforce that the resulting path remains below `baseDir`. Consequently, a malicious Agent ID can cause paths such as the Agent directory and session directory to resolve outside `~/.openclaw`. The recursive `fs.mkdirSync()` calls then create directories at those resolved locations using the privileges of ...[truncated 1529 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/config-builder.js:184
Finding

Channel Secrets Are Accepted Through Process Arguments and Stored in Plaintext

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to read and modify local configuration, create files/directories, and run a validation command, but it declares no explicit tool scope or permissions boundary. That mismatch increases the risk of unintended file-system or environment access because the operator and platform cannot clearly constrain what the skill is allowed to touch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad, common requests like creating or planning agents, which can cause the skill to activate in contexts where the user did not intend local configuration inspection or file modification. In this skill, unintended activation is more dangerous because the workflow includes reading ~/.openclaw/openclaw.json, enumerating account/channel data, updating configuration, and creating workspace files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and workflow require reading ~/.openclaw/openclaw.json and inspecting existing channel/account data, but they do not present this as an explicit privacy-impacting action up front. Users may invoke the skill for planning help without realizing it will access local configuration and enumerate account bindings, which can expose sensitive identifiers or operational metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function copies the existing config to a backup and then writes a new JSON configuration to the main config path, which changes user state on disk. Although comments describe the behavior, there is no user-facing prompt, log, or disclosure in this code to warn that the file will be modified and a backup created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function persists newAgent.appSecret directly into the long-lived configuration object, which will then be written to disk by saveConfig. Storing application secrets in plaintext config increases exposure through local file disclosure, backups (.bak), source control mistakes, logs, or accidental sharing; in this skill context, the tool is specifically designed to generate and update agent/bootstrap files, making secret persistence more dangerous because it normalizes broad duplication of credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

createDirectoryStructure performs filesystem writes by creating multiple directories under a base path without any user-facing disclosure or confirmation. In an agent-building skill that acts on user requests, silent writes can lead to unexpected persistence, clutter, or misuse if agentId or baseDir are influenced by untrusted input or automation mistakes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The comment states the function validates configuration, but the implementation runs openclaw doctor --fix, which performs automatic repairs. This mismatch is dangerous because callers and reviewers may treat the function as read-only while it actually mutates system state, increasing the likelihood of unintended changes and unsafe automation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This validator module performs system-changing actions that go beyond passive validation: it runs openclaw doctor --fix and exposes a gateway restart function. In a team-building skill that creates and updates agent configuration automatically, bundling repair and service-control operations into a validator increases the chance of unexpected local state changes and makes it easier for higher-level workflow code to trigger impactful operations without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The automatic repair command has side effects because openclaw doctor --fix can alter configuration or environment state, yet the function provides no user-visible warning or consent mechanism. In this skill's context, this is more dangerous because the tool is designed for automated setup flows, so a user expecting validation may unknowingly authorize repairs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module can restart the OpenClaw gateway via subprocess execution, which is a service-affecting operation unrelated to simple configuration checking. In this skill context, where the tool is intended to help plan and create agent teams, silent restart capability can disrupt running workloads or be invoked unexpectedly by orchestration code, creating availability and operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The gateway restart is performed silently through a subprocess, with no disclosure that service availability may be interrupted. In a multi-agent/team-management environment, restarting the gateway can impact active sessions and dependent automation, so hidden execution materially increases operational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file's human-facing comments and thrown error messages are written in Chinese only, including the read error text. This imposes a specific language choice without offering a user-selectable locale or documenting that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/validator.js:54