Back to skill

Security audit

Codex Reset Radar

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Codex quota alert monitor, but it needs review because it schedules recurring agent runs that post chat alerts from unvalidated remote data.

Install only if you are comfortable with a recurring OpenClaw cron job that checks a third-party endpoint and posts alerts to your default chat channel. Review the destination channel, schedule, and agent permissions first, and prefer adding schema validation or deterministic message rendering before enabling frequent automated runs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/codex-radar-check.py:44
Finding

Untrusted Remote Data Is Forwarded to an AI Agent Without Validation

Content
View full analysis
dict: """GET *url*, parse JSON, return dict. Raises on failure.""" req = urllib.request.Request( url, headers={"User-Agent": "codex-radar-check/1.0", "Accept": "application/json"}, ) with urllib.request.urlopen(req, timeout=REQUEST_TIMEOUT) as resp: raw = resp.read() return json.loads(raw) ``` Remotely supplied strings are copied into event descriptions and output fields. Representative affected code includes: ```python # --- window_open boolean --- was = bool(prev.get("window_open")) now = bool(curr.get("window_open")) if was != now: last_win = raw_data.get("last_window") or {} opened_at = last_win.get("opened_at") or raw_data.get("checked_at") scope = last_win.get("scope") or "Codex 用户" if now: events.append( { "type": "window_opened", "detail": "Codex 用量重置窗口已开启", "opened_at": opened_at, "scope": scope, } ) else: events.append( {"type": "window_closed", "detail": "Codex 用量重置窗口已关闭"} ) # --- status string --- old_status = str(prev.get("status") or "") new_status = str(curr.get("status") or "") if old_status != new_status: events.append( { "type": "status_change", "detail": f"状态从 {old_status} 变为 {new_status}", "from": old_status, "to": new_status, } ) # --- current_window.state --- old_cws = str(prev.get("current_window_state") or "") new_cws = str(curr.get("current_window_stat ...[truncated 4433 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Cron Setup

Create an OpenClaw cron job (recommended: hourly 8 AM–11 PM, silent overnight). The delivery target will automatically use your default agent chat channel:

json

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains multiple user-facing status and error strings in Chinese and hard-codes an Asia/Shanghai timezone, but does not offer any language or locale selection. The policy explicitly allows locale constraints only when users can opt in or when the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.