Back to skill

Security audit

Openclaw_Teach

Security checks for vulnerabilities and agentic risk

Overview

The skill’s main purpose is coherent, but it can leave sensitive narration audio/transcripts behind and includes broad optional browser-history access.

Install only if you are comfortable with local screen capture and optional microphone transcription. Avoid demonstrating secrets, skip the browser-history cross-check unless needed, and manually check/delete /tmp teach_audio_* and teach_whisper_* artifacts after narrated runs until the skill fixes cleanup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/transcribe.py:28
Finding

Sensitive narration audio and plaintext transcripts persist in temporary directories

Content
View full analysis
str: out_dir = tempfile.mkdtemp(prefix="teach_whisper_") if shutil.which("whisper"): subprocess.run( ["whisper", wav, "--model", model, "--output_format", "txt", "--output_dir", out_dir], check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, ) else: subprocess.run( [sys.executable, "-m", "whisper", wav, "--model", model, "--output_format", "txt", "--output_dir", out_dir], check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, ) txt = os.path.join(out_dir, os.path.splitext(os.path.basename(wav))[0] + ".txt") return open(txt, encoding="utf-8").read() ``` ```python wav = os.path.join(tempfile.mkdtemp(prefix="teach_audio_"), "narration.wav") ``` ### Technical Analysis The transcription script creates two persistent temporary directories using `tempfile.mkdtemp()`: - `teach_audio_*` contains the extracted, unredacted narration as a WAV file. - `teach_whisper_*` contains the generated plaintext transcript. Neither directory is deleted after successful processing or when an exception occurs. The script also does not report these paths to the calling agent. Consequently, the cleanup instruction in `SKILL.md`, which covers the original recording and reported frame or part files, cannot reliably remove these hidden temporary artifacts. The transcript is read using `open()` without a context manager, although the more consequential issue is that the transcript and audio files remain on disk. Application-level redaction performed after transcription cannot protect the original WAV or raw Whisper output, both of which may contain passwords, one- ...[truncated 1304 chars]
Remediation
View remediation
str: with tempfile.TemporaryDirectory(prefix="teach_whisper_") as out_dir: if shutil.which("whisper"): cmd = [ "whisper", wav, "--model", model, "--output_format", "txt", "--output_dir", out_dir, ] else: cmd = [ sys.executable, "-m", "whisper", wav, "--model", model, "--output_format", "txt", "--output_dir", out_dir, ] subprocess.run( cmd, check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, ) txt = os.path.join( out_dir, os.path.splitext(os.path.basename(wav))[0] + ".txt", ) with open(txt, encoding="utf-8") as transcript_file: return transcript_file.read() ``` 2. Scope the extracted WAV similarly: ```python with tempfile.TemporaryDirectory(prefix="teach_audio_") as audio_dir: wav = os.path.join(audio_dir, "narration.wav") extract_audio(video, wav) transcript = run_whisper(wav, model) ``` 3. Place cleanup in `finally` blocks if scoped context managers cannot be used, ensuring deletion on success, interruption, extraction failure, and Whisper failure. 4. Restrict temporary-directory permissions to the current user and avoid globally readable temporary locations. 5. Add tests that execute both successful and failing transcription paths and verify that no `teach_audio_*` or `teach_whisper_*` directories remain afterward. 6. Update the cleanup documentation to explicitly cover extracted audio and raw transcript files. ]]>

T08 · Insecure Dependencies

Note
Location
SKILL.md:84
Finding

Unpinned Whisper installation guidance introduces supply-chain exposure

Content
View full analysis
Remediation
View remediation
" ``` 2. Maintain a lock file containing reviewed transitive dependency versions. 3. Use hash verification where practical: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Install the dependency in a dedicated virtual environment rather than the system Python environment. 5. Document the trusted package index explicitly and avoid unreviewed alternate indexes. 6. Regularly review and update the pinned dependency, including its transitive dependency tree and published security advisories. 7. Advise users not to execute package installation with administrator or root privileges. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description understates the behavior: the skill can record the screen, optionally record microphone audio, inspect browser history, and persist generated artifacts. Undeclared recording and data-collection behavior is dangerous because users and policy layers may grant trust based on the narrow description while the skill handles significantly more sensitive data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

md
- Ask what you are about to demonstrate (and whether to narrate).
- Record (default ~10 min cap). Stop with Ctrl-C or let it hit the cap.
- Sanity-check, then transcribe via vision (and Whisper if audio was captured).
- Write a draft `SKILL.md` to `~/.openclaw/workspace/skills/<slug>/` and report.

It never runs the learned skill unprompted, and never embeds credentials.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes local Python scripts, shell commands, and file operations but does not declare any tool scope or permission boundaries. In a system that relies on explicit capability declarations, this increases the risk of overbroad execution and makes it harder to constrain or audit what the skill may access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The optional DevTools/browser history inspection expands the skill from workflow capture into collection of browsing-history data, which is more sensitive and not necessary for the core recording-to-skill function. Even though the text says it is consent-gated, adding history access broadens privacy exposure and creates a path to collect unrelated URLs or activity.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
constants. If ambiguity would materially change the skill, ask the user
   concise questions and wait for answers.

7. **Write the skill.** Create
   `~/.openclaw/workspace/skills/<derived-slug>/SKILL.md` with:

   - frontmatter: `name` (lowercase-hyphen, ≤64 chars), `description` (one line,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/frames.py (reported line 32)May include surrounding context.

python
def probe_duration(video: str):
    try:
        return float(
            subprocess.check_output(
                ["ffprobe", "-v", "error", "-show_entries", "format=duration",
                 "-of", "csv=p=0", video],
                stderr=subprocess.DEVNULL,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/frames.py (reported line 43)May include surrounding context.

python
def extract_frame(video: str, t: float, out_png: str) -> None:
    subprocess.run(
        ["ffmpeg", "-y", "-ss", str(t), "-i", video, "-frames:v", "1", out_png],
        check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,
    )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/frames.py (reported line 97)May include surrounding context.

python
parts = math.ceil(size / (max_mb * 1024 * 1024))
        seg = max(0.1, dur / parts)
        pattern = os.path.join(tmp, "demo_part_%03d.mp4")
        subprocess.run(
            ["ffmpeg", "-y", "-v", "error", "-i", video, "-c", "copy", "-map", "0",
             "-f", "segment", "-segment_time", str(seg), "-reset_timestamps", "1", pattern],
            check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/record.py (reported line 25)May include surrounding context.

python
"""Best-effort default microphone device per OS."""
    if system == "Windows":
        try:
            out = subprocess.check_output(
                ["ffmpeg", "-list_devices", "true", "-f", "dshow", "-i", "dummy"],
                stderr=subprocess.STDOUT, text=True,
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/record.py (reported line 81)May include surrounding context.

python
def probe_duration(out_path: str):
    try:
        out = subprocess.check_output(
            ["ffprobe", "-v", "error", "-show_entries", "format=duration",
             "-of", "csv=p=0", out_path],
            stderr=subprocess.DEVNULL,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/record.py (reported line 110)May include surrounding context.

python
print(f"RECORD_CMD {' '.join(cmd)}", file=sys.stderr)
    print(f"AUDIO {'on' if with_audio else 'off'}", file=sys.stderr)

    proc = subprocess.Popen(cmd, stderr=subprocess.DEVNULL)
    print(f"FFMPEG_PID {proc.pid}", file=sys.stderr)

    try:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transcribe.py (reported line 20)May include surrounding context.

python
def extract_audio(video: str, wav: str) -> None:
    subprocess.run(
        ["ffmpeg", "-y", "-i", video, "-vn", "-ac", "1", "-ar", "16000",
         "-f", "wav", wav],
        check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transcribe.py (reported line 30)May include surrounding context.

python
def run_whisper(wav: str, model: str) -> str:
    out_dir = tempfile.mkdtemp(prefix="teach_whisper_")
    if shutil.which("whisper"):
        subprocess.run(
            ["whisper", wav, "--model", model, "--output_format", "txt",
             "--output_dir", out_dir],
            check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transcribe.py (reported line 36)May include surrounding context.

python
check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,
        )
    else:
        subprocess.run(
            [sys.executable, "-m", "whisper", wav, "--model", model,
             "--output_format", "txt", "--output_dir", out_dir],
            check=True, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,

Static analysis

No suspicious patterns detected.