Back to skill

Security audit

Openclaw Sage

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but a cache path validation flaw can let maintenance commands write or delete files outside the intended cache.

Review before installing. Use only trusted version tags, avoid untrusted --version values or environment overrides, and treat cache.sh refresh, cache.sh clear-docs, build-index.sh fetch/build, and track-changes.sh snapshot as commands that mutate local cache state. The package does not show malicious behavior, but it should validate cache paths before being used in less controlled agent environments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib.sh:28
Finding

Unvalidated Version Argument Allows Cache Directory Path Traversal

Content
View full analysis
/dev/null | wc -l | tr -d ' ') rm -f "${VERSION_CACHE_DIR}"/doc_*.txt \ "${VERSION_CACHE_DIR}"/doc_*.md \ "${VERSION_CACHE_DIR}/index.txt" \ "${VERSION_CACHE_DIR}/index_meta.json" echo "Cleared $count cached docs and index from version: $VERSION" ;; ``` ### Technical Analysis The `--version` argument is accepted as an arbitrary string and appended directly to `CACHE_DIR`. The implementation does not reject path separators, `..` components, absolute-path syntax, or other malformed version identifiers. Quoting the resulting variable prevents shell word splitting, but it does not prevent filesystem path traversal. For example, a version value such as `../../target` produces a path equivalent to: ```text /../../target ``` The scripts subsequently use that escaped path for directory creation, cache reads and writes, index generation, and deletion. In particular, `cache.sh clear-docs` deletes fixed filenames and matching `doc_*.txt` ...[truncated 1706 chars]
Remediation
View remediation
&2 return 1 fi } ``` 2. Explicitly reject `/`, `\`, empty values, `.` components, and `..` components regardless of platform. 3. Canonicalize both the cache root and candidate directory, then verify that the candidate remains beneath the cache root before creating, reading, writing, or deleting files: ```bash cache_root="$(cd "$CACHE_DIR" && pwd -P)" candidate="${cache_root}/${VERSION}" mkdir -p "$candidate" candidate="$(cd "$candidate" && pwd -P)" case "$candidate" in "$cache_root"/*) ;; *) echo "Error: version cache path escapes cache root" >&2 exit 1 ;; esac VERSION_CACHE_DIR="$candidate" ``` 4. Apply the containment check again immediately before destructive operations such as `clear-docs`, rather than relying solely on validation performed earlier. 5. Consider resolving user-facing version tags to an internal safe identifier, such as a validated slug or cryptographic hash, instead of using the raw argument as a directory name. 6. Add regression tests covering `../`, nested traversal, absolute paths, backslashes, `.`, `..`, malformed tags, and valid release names. Tests should verify that no directory or file outside `CACHE_DIR` is created, modified, or deleted. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description presents a broad documentation assistant with live retrieval, search, troubleshooting support, and change tracking. The supplied code chunk does something much narrower: it inspects cached files for one requested doc path and outputs metadata such as title, headings, word count, cache age, and URL. The script even states it 'does not fetch' and instructs the user to fetch/build cache separately. There is no evidence here of answering user questions, BM25 indexing/search, provider/setup guidance logic, or tracking documentation changes. This is a material description-to-behavior mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a full documentation QA/search expert with live doc fetching, BM25 retrieval, troubleshooting/help responses, and change tracking. The supplied code chunk is much narrower: it ensures a cached docs.json exists, optionally fetches it from a local source or GitHub, then uses Python to extract navigation page paths and group them by category for sitemap output. While this is loosely related to documentation handling and does perform limited live fetching/caching, it does not implement question answering, BM25 search, troubleshooting assistance, provider/configuration guidance, or change tracking. The primary purpose of this code is sitemap generation, which is materially different from the declared expert behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
### `./scripts/build-index.sh fetch`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
### `./scripts/build-index.sh fetch`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
### `./scripts/build-index.sh fetch`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
### `./scripts/build-index.sh fetch`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
### `./scripts/build-index.sh fetch`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/cache.sh (reported line 37)May include surrounding context.

sh
refresh)
    echo "Clearing docs.json cache for version: $VERSION"
    rm -f "${VERSION_CACHE_DIR}/docs.json"
    echo "docs.json cleared. Next sitemap.sh or build-index.sh fetch will re-fetch."
    ;;

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/cache.sh (reported line 43)May include surrounding context.

sh
clear-docs)
    count=$(ls "$VERSION_CACHE_DIR"/doc_*.txt 2>/dev/null | wc -l | tr -d ' ')
    rm -f "${VERSION_CACHE_DIR}"/doc_*.txt \
          "${VERSION_CACHE_DIR}"/doc_*.md \
          "${VERSION_CACHE_DIR}/index.txt" \
          "${VERSION_CACHE_DIR}/index_meta.json"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and documents shell, network, cache, and file-manipulation capabilities but does not declare any explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and can let an agent invoke broader capabilities than reviewers or operators expect, especially because several documented commands can fetch remote content and modify local cache state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented cache.sh clear-docs command deletes all cached documentation and the search index, yet the skill provides no warning, confirmation guidance, or recommendation to require explicit user consent before use. In an agent setting, that increases the chance of accidental destructive actions that can disrupt offline operation, erase local state needed for answers, or force future network refetches.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/cache.sh (reported line 62)May include surrounding context.

sh
if ! curl -sf --max-time 10 \
          -H "Accept: application/vnd.github+json" \
          -H "User-Agent: openclaw-sage" \
          "https://api.github.com/repos/openclaw/openclaw/tags?per_page=30" \
          -o "$TAGS_CACHE" 2>/dev/null; then
        echo "Error: failed to fetch tags from GitHub API" >&2
        exit 1

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The snippet recommends binding the gateway to 0.0.0.0, which exposes the service on all network interfaces by default. In documentation, this is risky because users may copy the example into production or internet-reachable environments without realizing it broadens attack surface and can permit unintended remote access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The changelog states that OPENCLAW_SAGE_LANGS defaults to en, which establishes a language preference in the skill's documented behavior. Because this file does not indicate user choice, opt-in, or a region-specific justification for that default, it may conflict with organizational language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The markdown documents cache.sh refresh and cache.sh clear-docs, including removal of cached docs, HTML, and index, but it does not include any caution that these commands delete local data. For markdown files, destructive or data-affecting behavior should be disclosed so users understand the impact before running the command.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file states OPENCLAW_SAGE_LANGS defaults to en, which imposes a language preference in natural-language behavior without indicating user choice or opt-in. The policy allows locale constraints when they are user-selectable or clearly justified, but this line presents English as the default behavior without such framing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The comment and default value set LANGS to en, which establishes an English-only default behavior. Under the stated policy, forcing a specific language without explicit user choice or opt-in is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.