Back to skill

Security audit

Openclaw Security

Security checks for vulnerabilities and agentic risk

Overview

This security-suite skill is mostly coherent, but it can bulk install, update, execute, and run automated remediation across many other skills without strong review or confirmation controls.

Review before installing. Use this only in a workspace where you are comfortable letting it install and execute the named security skills. Prefer manually reviewing or pinning the 11 dependent skills first, avoid running update or protect unattended, and treat protect as a state-changing response action rather than a scan.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/security.py:279
Finding

Unpinned Third-Party Skills Are Installed and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: scripts/security.py:179-207, 279-284, 573-578
Vulnerability Type: Supply-chain trust failure involving mutable, unverified third-party skills
Risk Level: High

Vulnerable Code

python
def installed_skills(workspace):
    """Return dict of installed security skill names -> their directories."""
    sd = skills_dir(workspace)
    found = {}
    if not sd.exists():
        return found
    for name in SKILLS:
        skill_dir = sd / name
        if skill_dir.is_dir() and (skill_dir / "SKILL.md").exists():
            found[name] = skill_dir
    return found


def run_skill(python, skill_dir, script_rel, args, workspace,
              ws_before=False, capture=True):
    """Run a skill's script with the given arguments.

    ws_before: if True, --workspace goes before the command args (subparser tools).
               if False, --workspace goes after the command args.
    """
    script = skill_dir / script_rel
    if not script.exists():
        return None, f"Script not found: {script}", 1

    ws_args = ["--workspace", str(workspace)]
    if ws_before:
        cmd = [python, str(script)] + ws_args + args
    else:
        cmd = [python, str(script)] + args + ws_args

    try:
        result = subprocess.run(
            cmd,
            capture_output=capture,
            text=True,
            timeout=60,
            cwd=str(workspace),
        )
python
result = subprocess.run(
    [clawhub, "install", name, "--workdir", str(workspace)],
    capture_output=True,
    text=True,
    timeout=60,
)
python
result = subprocess.run(
    [clawhub, "update", name, "--workdir", str(workspace)],
    capture_output=True,
    text=True,
    timeout=60,
)

Technical Analysis

The installation and update operations identify dependencies only by mutable ClawHub package names. The orchestrator does not pin audited versions or immutable digests and does not verify package checksums, cryptographi ...[truncated 2339 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each third-party skill to a reviewed immutable version and, where supported, a content digest or commit hash.
  2. Maintain a trusted manifest containing each skill's approved publisher identity, version, script paths, and cryptographic hashes.
  3. Verify package signatures and hashes before activation and before every execution, failing closed on missing or invalid verification data.
  4. Download updates into a staging directory, validate their complete contents, and activate them atomically only after verification succeeds.
  5. Do not treat the presence of SKILL.md as evidence of trust. Validate all executable files against the trusted manifest.
  6. Reject symlinked skill directories and scripts, and check that resolved paths remain under the intended workspace skill directory.
  7. Check file ownership and permissions to prevent untrusted local users from replacing installed scripts.
  8. Restrict child processes using available operating-system sandboxing controls. Provide only required filesystem paths, environment variables, and network access.
  9. Remove unnecessary sensitive environment variables before invoking child skills.
  10. Record the verified package identity, version, digest, and verification result in an audit log for every installation, update, and execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The protect command invokes automated remediation actions across multiple tools with no warning, preview, or per-tool confirmation, even though 'countermeasures' may modify files, permissions, credentials, or network-related controls. In a security suite, remediation is contextually more dangerous than scanning because users may expect safe diagnostics while the command can trigger irreversible or disruptive changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to run install, setup, update, and related orchestration commands that will change the local workspace and installed skill set, but it does not clearly warn that these operations are state-changing. In a security-focused skill, that omission is more dangerous because users may assume the commands are purely diagnostic or safe-by-default, reducing informed consent before modifying trusted tooling and workspace state.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises commands that execute Python scripts and perform installation, updates, setup, and scans across a workspace, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: an agent or user may invoke shell-capable behavior without clear guardrails, increasing the risk of unintended command execution or overbroad workspace modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enumerates powerful Pro actions such as restore, rollback, quarantine, revoke, block, reject, rotate, enforce, contain, and remediate without any warning that these may alter system state, disable access, modify credentials, or disrupt workflows. In a security orchestration context, omission of these warnings is especially risky because users may assume all actions are safe diagnostics when some are effectively automated response or enforcement steps.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

The orchestrator executes Python scripts from skill directories discovered inside the workspace, and those scripts can be modified or replaced by anyone who can write to the workspace. Although subprocess.run is invoked without a shell, this still results in arbitrary code execution in the current interpreter against untrusted local content, which is especially risky because this file is a security orchestrator that implicitly trusts installed skills.

Content

Scanner excerpt · scripts/security.py (reported line 202)May include surrounding context.

python
cmd = [python, str(script)] + args + ws_args

    try:
        result = subprocess.run(
            cmd,
            capture_output=capture,
            text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The install command performs bulk installation of 11 external skills into the workspace immediately when invoked, without an explicit confirmation prompt, dry-run mode, or warning that it will modify the local environment. In a security tool context this is more dangerous because users may assume inspection-only behavior, while the command actually imports and stages executable components from an external ecosystem.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/security.py (reported line 279)May include surrounding context.

python
print(f"  [....] {name:<30} installing...", end="", flush=True)
        try:
            result = subprocess.run(
                [clawhub, "install", name, "--workdir", str(workspace)],
                capture_output=True,
                text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The update command bulk-modifies installed security skills via an external CLI without explicit consent, version review, or warning that local components will change. In this context, silent updates to security tooling can alter behavior, introduce regressions, or replace previously trusted code, making the lack of confirmation materially risky.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/security.py (reported line 573)May include surrounding context.

python
for name in sorted(found.keys()):
        print(f"  Updating {name}...", end="", flush=True)
        try:
            result = subprocess.run(
                [clawhub, "update", name, "--workdir", str(workspace)],
                capture_output=True,
                text=True,

Static analysis

No suspicious patterns detected.