Back to skill

Security audit

Openclaw Arbiter

Security checks for vulnerabilities and agentic risk

Overview

This local auditing skill also includes high-impact commands that can quarantine or delete other skills, including a path-handling flaw that can reach outside the intended skills directory.

Review this carefully before installing. It is not just a passive auditor: it can rename, quarantine, and permanently remove other skills, and the revoke command needs path validation and confirmation safeguards before it should be trusted in a real workspace. I found no evidence of network exfiltration, remote code loading, credential theft, or hidden background persistence.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/arbiter.py:705
Finding

Path Traversal in Skill Revocation Allows Arbitrary Directory Deletion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/arbiter.py:279
Finding

Unsupported Script and Instruction Formats Can Bypass Security Enforcement

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The revoke path can permanently remove other installed skills by copying them to a vault and then recursively deleting the original directory. In a multi-skill workspace, this gives the tool powerful destructive capability over peer components that is not necessary for passive auditing and can cause denial of service or irreversible loss if triggered accidentally or abusively.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and documents code that audits installed skills for network, subprocess, file I/O, environment variables, and unsafe operations, but its manifest declares no explicit tool scope or permissions. That mismatch means the skill likely requires broad local access without transparent permission boundaries, increasing the risk of over-privileged execution and making it harder for users or platforms to evaluate what the skill can actually do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill presents itself as a permission auditor, but its documented scope includes active countermeasures such as subversion, quarantine, revocation, and defense sweeps. That mismatch matters because users may grant trust to an auditing tool that can also modify or remove other skills, increasing the chance of unsafe deployment and abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The revocation flow performs destructive filesystem operations without any confirmation prompt, interlock, or dry-run. This makes operator mistakes, malicious invocation, or accidental targeting much more damaging because a single command can delete a skill directory immediately.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The protect sweep automatically renames skill directories to quarantine them based on pattern matches and policy evaluation. Because the scanner is heuristic and can generate false positives, auto-disabling installed skills can be abused or can unexpectedly break the environment, turning an audit tool into an enforcement mechanism without per-skill confirmation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The revoke docstring claims the skill is 'moving it to the quarantine vault first,' implying a simple relocation. The implementation instead creates metadata, copies the entire tree into a vault with shutil.copytree, and then deletes the original with shutil.rmtree, which is a different and more destructive sequence than described.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/arbiter.py:122