Back to skill

Security audit

JARVIS AI Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is for controlling real robotic arms and grippers, but the package lacks the declared implementation file and does not document adequate safety gates for physical movement.

Review before installing or using with real hardware. Only use this with a verified local implementation, supervised operation, explicit operator confirmation for movement, configured workspace and force limits, simulation or dry-run defaults, and an independent emergency stop. Do not rely on the advertised collision detection or safety claims until the missing implementation is supplied and reviewed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:24
Finding

Safety-Critical Robot Commands Lack Mandatory Control Safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-35
Related Locations: SKILL.md:38-45, SKILL.md:54-59
Vulnerability Type: Unsafe physical actuation without documented authorization, validation, or fail-safe controls
Risk Level: High

Vulnerable Code

python
from openclaw_control import init_claw, get_claw

# Initialize claw
claw = init_claw()

# Control operations
claw.grab(force=50.0)
claw.move_to(10, 20, 30)
claw.release()

The documented voice interface also exposes direct physical actions:

text
- "Jarvis, grab the object"
- "Jarvis, move to 10 20 30"
- "Jarvis, rotate 45 degrees"
- "Jarvis, release"
- "Jarvis, return to home"
- "Jarvis, claw status"

The stated operating envelope includes potentially hazardous industrial equipment:

text
- Reach: 2-3 meters (model-dependent)
- Payload: 3-500 kg (model-dependent)
- Precision: ±0.03-0.1 mm
- Speed: 1-7000 mm/s
- Response Time: <10ms

Technical Analysis

The skill documentation presents initialization followed by immediate grab, move_to, and release operations. It does not require operator authentication, role-based authorization, explicit confirmation, coordinate validation, workspace limits, force or speed bounds, human-presence checks, or simulation before physical execution.

Collision detection is advertised as a feature, but the documented execution procedure does not establish that collision checking is mandatory before movement. No emergency-stop procedure, communications-loss behavior, command timeout, or fail-closed state is documented.

Because the interface accepts voice and programmatic commands, an inaccurate transcription, malformed input, unauthorized speaker, or upstream instruction manipulation could be converted into physical movement without an intervening safety gate.

Attack Path

  1. An attacker, unauthorized nearby speaker, or compromised upstream ...[truncated 1155 chars]
Remediation
View remediation

Remediation Suggestions

  • Require authenticated operators and role-based authorization before exposing hardware-control functions.
  • Require explicit operator confirmation for physical movement, especially for voice-originated commands.
  • Validate every coordinate, orientation, speed, force, duration, and axis against model-specific limits.
  • Enforce configured workspace boundaries, exclusion zones, and self-collision constraints.
  • Default to simulation or dry-run mode until hardware execution is explicitly enabled.
  • Require collision checks and human-presence safety checks before and during every movement.
  • Use conservative default speed and force limits rather than relying on caller-supplied values.
  • Implement watchdog timers, command expiration, communications-loss handling, and a fail-closed safe state.
  • Document and test an independent hardware emergency stop that cannot be overridden through the skill.
  • Record authenticated command provenance and safety-validation results in an audit log.
  • Add negative tests proving that unauthorized, out-of-range, stale, malformed, and unconfirmed commands cannot actuate hardware.

T08 · Insecure Dependencies

Warning
Location
skill.json:25
Finding

Declared Robot-Control Implementation Is Missing from the Package

Content
View full analysis

Vulnerability Details

File Location: skill.json:25
Related Location: SKILL.md:19-22
Vulnerability Type: Missing required implementation with unsafe module-resolution risk
Risk Level: Medium

Vulnerable Configuration

skill.json declares a required implementation file:

json
"requiredFiles": ["openclaw_control.py"],

SKILL.md identifies and imports that implementation:

text
## Implementation
- **Module**: `openclaw_control.py`
- **Primary Library**: `OpenClaw SDK`
- **Communication**: USB Serial, Ethernet, ROS
python
from openclaw_control import init_claw, get_claw

However, the audited package contains only SKILL.md and skill.json; openclaw_control.py is absent.

Technical Analysis

The package cannot supply the implementation it declares as required. As a result, none of the advertised hardware discovery, communication, collision detection, or physical safety behavior can be verified from the artifact.

If a consumer follows the documented import despite the missing local file, Python may resolve openclaw_control from another location on sys.path, such as the working directory, an installed package, or another environment-controlled path. A malicious or unintended module with that name could therefore be imported in place of the expected implementation.

This is a conditional module-resolution or dependency-confusion risk rather than evidence that this package itself contains malicious code. The project provides no version, hash, trusted source, or local implementation that would bind the import to reviewed code.

Attack Path

  1. A consumer installs or copies the skill and follows its documented import example.
  2. The declared local openclaw_control.py file is unavailable.
  3. An attacker places a module named openclaw_control in an earlier Python import location, or causes an untrusted package with that import name to be installe ...[truncated 962 chars]
Remediation
View remediation

Remediation Suggestions

  • Include the declared openclaw_control.py implementation in the package.
  • Make installation or loading fail closed when any file listed in requiredFiles is absent.
  • Resolve the implementation through a package-relative import rather than an ambiguous top-level import.
  • Package the implementation under a unique namespace to reduce module-name collisions.
  • Pin every third-party dependency to reviewed versions and verify package origin and cryptographic hashes.
  • Provide a lock file or reproducible dependency manifest.
  • Avoid automatically installing a package solely because its name matches a missing import.
  • Verify the implementation's signature or checksum before granting it serial, network, ROS, or robotic-controller access.
  • Add continuous-integration checks that compare requiredFiles against the actual package contents.
  • Review and test the supplied implementation's authorization, bounds checking, collision prevention, and emergency-stop behavior before enabling physical hardware.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill documents direct control of a physical robotic arm and gripper, including movement, grabbing, and release commands, but provides no safety warnings, access restrictions, environment checks, or human-in-the-loop safeguards. Because it enables real-world actuation with potentially heavy, fast-moving equipment, omission of explicit safety constraints materially increases the risk of injury, equipment damage, or unsafe autonomous operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest advertises direct robotic arm, gripper, force-sensing, collision-detection, and sequence-execution capabilities but provides no visible warning, gating, or safety constraints about physical-world consequences. In a hardware-control skill, omission of operator safety guidance and authorization expectations can lead to unsafe invocation, unintended movement, damage to equipment, or injury to nearby users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.