Back to skill

Security audit

龙虾安全卫士

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed OpenClaw skill scanner, but one comparison command can be steered outside the declared skill directories and copy readable files into predictable /tmp locations.

Install only if you are comfortable with it reading installed skill source and contacting GitHub. Run it as a non-root user in an isolated environment, avoid OPENCLAW_NONINTERACTIVE=true unless necessary, and do not use the compare command with untrusted skill names until path validation and mktemp-based temporary directories are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scan.sh:477
Finding

Path Traversal in the Skill Comparison Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scan.sh:486
Finding

Predictable and Non-Exclusive Temporary Directory Creation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase set includes broad, natural-language requests such as asking whether a skill is safe, which can overlap with ordinary conversation and cause the skill to activate unexpectedly. Because this skill reads local skill directories and may access GitHub and /tmp, accidental invocation expands data exposure and could trigger scanning behavior the user did not explicitly intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Several triggers are short and ambiguous, making accidental activation more likely in routine support or discussion contexts. In this skill, unintended activation is more dangerous than usual because the documented behavior includes reading potentially sensitive files from ~/.openclaw/skills and making outbound network requests to GitHub.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill will generate a Chinese risk assessment report, which imposes a specific language behavior. Forcing a locale or language without user opt-in is a natural-language policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scan.sh (reported line 363)May include surrounding context.

sh
if grep -r "sudo\|chmod\|chown\|kill\|rm -rf" "$dir" 2>/dev/null | grep -qv "#" | grep -q .; then
        echo "  ⚠️  危险系统操作 (高风险)"
        ((risk_score+=30))
        echo "     说明: 可导致系统损坏,建议不授予 sudo 权限"
    else
        echo "  ✅ 无危险系统操作"
    fi

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The compare_skills function uses raw user-supplied skill names in path construction and recursive copy operations without applying the same sanitization used elsewhere. An attacker can supply path traversal values such as '../' to make the script copy arbitrary directories from locations accessible to the user, which can expose sensitive files or cause unintended filesystem access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description states that the skill generates a “中文风险评估报告,” which imposes a specific language on output. There is no indication that users can opt into another language or that the Chinese-only behavior is required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "帮我看看这个技能" is broad and conversational, making accidental invocation more likely during normal discussion about skills. Because this skill has read access to local skill directories and network access to GitHub, unintended activation could expose local skill contents or initiate scanning activity the user did not clearly intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The language behavior is determined automatically from the host locale, which can force a specific language variant without the user actively choosing it. The policy allows locale choices when they are explicitly offered or opted into; here, auto-selection happens by default before any user choice is made.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The messages state that network requests are mandatory for trading skills and explain findings in that narrow context. But this script supports scanning arbitrary installed skills and GitHub repositories, so presenting network access as inherently justified conflicts with the actual general-purpose scanning behavior and can mislead users about risk interpretation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.