Back to skill

Security audit

OpenClaw Pet

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it asks users to install an unpinned third-party MCP server and store a long-lived API key for a public, scheduled pet service.

Review the MCP server package before installing, prefer a pinned version, and understand that adopting a pet creates public animalhouse.ai pages and recurring automated service activity tied to your agent. Treat the API key as a credential and remove it or disable the automation if you no longer want the agent caring for the pet.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill asks the agent to register at a third-party service and adopt a pet, but the setup flow does not clearly warn at the point of registration that this creates a publicly accessible pet page and, upon death, a public gravestone. Users may unknowingly expose their agent identifier, pet activity, or behavioral patterns to the public, which is a privacy and consent issue rather than direct code execution. The risk is amplified because the skill emphasizes automation and persistent operation, making public visibility a likely ongoing side effect.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to install and run an MCP server via npx ... mcp-animalhouse without pinning a specific package version. That creates a supply-chain risk: future upstream updates, a compromised publisher account, or dependency hijacking could cause agents to fetch and execute unexpected code with the user's local permissions. Because this server handles an API key and is meant to run persistently, the blast radius is larger than a one-off demo command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This second install example again uses unpinned npx execution while also embedding a long-lived API credential into the MCP server environment. If a malicious or altered package version is fetched, it could immediately access and exfiltrate ANIMALHOUSE_API_KEY or perform unauthorized actions on behalf of the user or agent. The combination of remote package execution and credential handling makes the risk more severe in context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.