Back to skill

Security audit

agent-council

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its stated OpenClaw/Discord agent-management purpose, but it makes powerful persistent configuration changes and has command-construction flaws that could run unintended shell commands if untrusted text is used.

Review this skill before installing in a real OpenClaw environment. Only run it with trusted agent names, prompts, channel names, workspace paths, and config values; avoid copying generated config.patch commands if any included text came from an untrusted source. Expect it to read your OpenClaw Discord bot configuration, modify gateway state, create or rename live Discord channels, write local agent files, and optionally create a recurring cron job.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup_channel.py:98
Finding

Shell Command Injection in Generated Gateway Configuration Command

Content
View full analysis
Dict[str, Any]: """Build gateway config patch for the channel.""" return { "channels": { "discord": { "guilds": { guild_id: { "channels": { channel_id: { "allow": True, "requireMention": False, "systemPrompt": context } } } } } } } ``` ```python print(f"\nopenclaw gateway config.patch --raw '{json.dumps(patch)}'") ``` ### Technical Analysis The user-provided `--context` value is inserted into a JSON object and then rendered inside a shell command enclosed by single quotes. JSON serialization escapes JSON metacharacters, but it does not escape single quotes for a POSIX shell. Consequently, a context containing a single quote can terminate the shell argument. Additional shell syntax can then introduce an arbitrary command. The command is not executed directly by the Python script, but the documented workflow explicitly instructs the operator to copy and run the generated command. This creates a command-injection boundary when context values are untrusted or supplied by another user or automation system. For example, a context with the following structure can break out of the quoted JSON argument: ```text description'; attacker-command; # ``` The final command displayed to the operator would contain shell syntax outside the intended `--raw` argument. ### Attack Path 1. An attacker influences the ...[truncated 1220 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rename_channel.py:104
Finding

Shell Command Injection While Generating a System-Prompt Update Command

Content
View full analysis
Optional[str]: """Check if systemPrompt contains old channel name.""" try: prompt = config['channels']['discord']['guilds'][guild_id]['channels'][channel_id].get('systemPrompt', '') if old_name in prompt: return prompt except (KeyError, TypeError): pass return None def build_system_prompt_patch(guild_id: str, channel_id: str, old_prompt: str, old_name: str, new_name: str) -> Dict[str, Any]: """Build gateway config patch to update systemPrompt.""" new_prompt = old_prompt.replace(old_name, new_name) return { "channels": { "discord": { "guilds": { guild_id: { "channels": { channel_id: { "systemPrompt": new_prompt } } } } } } } ``` ```python old_prompt = check_system_prompt_references(config, guild_id, channel_id, old_name) if old_prompt: print(f"\n⚠️ systemPrompt contains '{old_name}' - needs updating") patch = build_system_prompt_patch(guild_id, channel_id, old_prompt, old_name, new_name) print(f"\n📝 Run this command to update systemPrompt:") print(f"\nopenclaw gateway config.patch --raw '{json.dumps(patch)}'") ``` ### Technical Analysis The generated patch contains data loaded from the OpenClaw configuration and modified using the command-line `--old-name` and `--new-name` values. The resulting JSON is placed inside a single-quoted shell command ...[truncated 1809 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create-agent.sh:210
Finding

Gateway Configuration Injection Through Manual JSON Construction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (22)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · README.md (reported line 314)May include surrounding context.

})

text

### Send Messages to Agents

**Direct communication:**
```typescript

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 436)May include surrounding context.

})

text

### Send Messages to Agents

**Direct communication:**
```typescript

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · README.md (reported line 394)May include surrounding context.

text

**4. Agent-to-agent communication:**
Agents can send messages to each other:
```typescript
// In Watson's context
sessions_send({

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 516)May include surrounding context.

text

**4. Agent-to-agent communication:**
Agents can send messages to each other:
```typescript
// In Watson's context
sessions_send({

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A second aspect of the same mismatch is that the markdown presents autonomous-agent creation and complete system setup, but the supplied behavior appears centered on Discord channel setup/renaming and config manipulation. Overstating scope while understating sensitive actions increases the chance of unsafe invocation and accidental overtrust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A second aspect of the same mismatch is that the markdown presents autonomous-agent creation and complete system setup, but the supplied behavior appears centered on Discord channel setup/renaming and config manipulation. Overstating scope while understating sensitive actions increases the chance of unsafe invocation and accidental overtrust.

Content

No source excerpt is available for this finding.

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 470)May include surrounding context.

md
### Finding Discord IDs

**Enable Developer Mode:**
- Settings → Advanced → Developer Mode

**Copy IDs:**

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

md
### Finding Discord IDs

**Enable Developer Mode:**
- Settings → Advanced → Developer Mode

**Copy IDs:**

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 683)May include surrounding context.

md
1. **Organize channels in categories** - Group related agent channels
2. **Use descriptive channel names** - Clear purpose from the name
3. **Set specific system prompts** - Give each channel clear context
4. **Document agent responsibilities** - Keep SOUL.md updated
5. **Set up memory cron jobs** - For agents with ongoing work
6. **Test agents individually** - Before integrating into team

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/rename_channel.py (reported line 109)May include surrounding context.

python
try:
        prompt = config['channels']['discord']['guilds'][guild_id]['channels'][channel_id].get('systemPrompt', '')
        if old_name in prompt:
            return prompt
    except (KeyError, TypeError):
        pass
    return None

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 16)May include surrounding context.

md
- Optional cron job setup

**Discord Channel Management:**
- Create Discord channels via API
- Configure OpenClaw gateway allowlists
- Set channel-specific system prompts
- Rename channels and update references

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes Discord channel creation, gateway allowlists, and channel-specific prompts without warning that prompts, metadata, and agent interactions may be exposed to Discord infrastructure and channel participants. For multi-agent systems handling sensitive tasks, this omission can cause users to route confidential content into third-party chat surfaces unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly states that the tool updates gateway configuration, creates files, and restarts the gateway, but it does not clearly warn users that running the setup modifies local state and service configuration. In an agent skill context, this can lead users to invoke actions with side effects they did not fully anticipate, increasing the chance of accidental misconfiguration or disruption.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises and instructs use of capabilities that read environment/configuration, modify files, and make networked Discord API calls, but it does not declare an explicit tool/permission scope. That creates a confused-deputy risk where an agent may invoke the skill without the user understanding that local config, workspaces, and external Discord resources will be accessed or changed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The 'Use when' text is broad enough to match ordinary requests about agents or Discord organization, which may cause automatic selection outside the intended OpenClaw-admin context. Because the skill can alter configs, files, and external channels, overly broad routing increases the risk of unintended privileged actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 489)May include surrounding context.

md
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)

#### 2. Run Creation Script

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)

#### 2. Run Creation Script

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)

#### 2. Run Creation Script

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow describes creating resources, patching live gateway configuration, restarting the gateway, and updating workspace files without a strong confirmation or warning model. In an agent setting, that omission can lead to destructive or externally visible changes being performed as if they were harmless setup steps.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The script offers to establish persistent autonomous behavior via a cron job tied to an agent session, causing the agent to continue acting and writing data after the one-time setup completes. In an agent-management skill, this is materially security-relevant because it expands runtime scope and persistence, and could be abused or misunderstood in environments where long-lived autonomous actions need stricter governance.

Content

Scanner excerpt · scripts/create-agent.sh (reported line 294)May include surrounding context.

sh
echo -e "${YELLOW}📅 Memory System${NC}"
echo ""
echo "Would you like to set up a daily memory cron job for $NAME?"
echo "This will create a job that reviews and updates the agent's daily memory file."
echo ""
read -p "Create daily memory cron? (y/n): " -n 1 -r
echo ""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

If enabled, the script creates a recurring cron task that silently writes summaries into the agent workspace on an ongoing basis. This persistence can surprise operators, alter files after initial setup, and create an auditability/trust problem because future automated modifications are not prominently disclosed at creation time beyond a brief prompt.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 691)May include surrounding context.

md
## Requirements

**Bot Permissions:**
- `Manage Channels` - To create/rename channels
- `View Channels` - To read channel list
- `Send Messages` - To post in channels

Static analysis

No suspicious patterns detected.