Back to skill

Security audit

Goal Task

Security checks for vulnerabilities and agentic risk

Overview

This scheduling helper has a coherent purpose, but its script can run unintended local code from crafted task text and can leave persistent cron jobs using a local gateway token.

Install only if you are comfortable with a shell script reading your OpenClaw gateway token and creating, updating, and deleting persistent remote cron jobs. Do not pass untrusted task text to goal_task until the JSON/Python construction is fixed, and check for stale goal-task cron jobs after use.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/goal-task.sh:65
Finding

Python Code Injection Through Unsafely Interpolated Task Data

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
scripts/goal-task.sh:65
Finding

Recurring Cron Job Can Persist Indefinitely When Agent-Driven Cleanup Fails

Content
View full analysis
&1 | grep -v "Config warnings\|🦞\|channel plugin\|setup surfaces\|runtime loads" > /dev/null ``` The English text in the second excerpt is a translation of the source cleanup instruction; the scheduling and cleanup behavior is unchanged. ### Technical Analysis The implementation describes a goal-driven task but creates an `every` schedule, which is recurring rather than one-shot. The script itself does not enforce deletion after the first successful trigger. Instead, it appends a natural-language request telling the receiving agent to call `delete_goal_task`. Natural-language compliance is not a reliable lifecycle control. Deletion can fail if: - The agent does not follow the instruction. - The task message conflicts with or distracts from the cleanup request. - The agent execution times out or terminates unexpectedly. - The update request fails after the cron has already been created. - The generated ...[truncated 1469 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/goal-task.sh:77
Finding

Gateway Authentication Token Is Exposed Through Process Arguments

Content
View full analysis
&1) ``` It is exposed again during updates: ```bash openclaw gateway call cron.update \ --token "$token" \ --json \ --params "$update_params" 2>&1 | grep -v "Config warnings\|🦞\|channel plugin\|setup surfaces\|runtime loads" > /dev/null ``` It is also exposed during removal: ```bash result=$(openclaw gateway call cron.remove \ --token "$token" \ --json \ --params "{\"jobId\":\"$job_id\"}" 2>&1) ``` ### Technical Analysis The script reads the gateway token from `~/.openclaw/openclaw.json` and then passes it using the `--token` command-line option. Command-line arguments may be observable through process inspection facilities, monitoring agents, diagnostic tooling, audit logs, crash reports, or shell tracing. The exact visibility depends on operating-system configuration and process-isolation controls. Nevertheless, command-line arguments are not an appropriate transport for reusable secrets when a safer authentication mechanism is available. The exposure occurs for each gateway operation, increasing the opportunity for observation. ### Attack Path 1. The Skill reads the reusable gateway token from the OpenClaw configuration. 2. The script starts an `openclaw gateway call` process with the token embedded in its argument vector. 3. A local process observer, monitoring service, diagnostic collector, or sufficiently privileged local user captures the command line while the process is running. 4. The observer extracts the plaintext token. 5. The captured token is used to invo ...[truncated 668 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is written as an instruction/presentation entirely in Chinese and frames the skill behavior in that locale without any indication that users may choose another language. Under the policy, language-specific behavior should not be forced unless there is explicit opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly states that the script will automatically read a gateway token from ~/.openclaw/openclaw.json, but it does not warn the user that sensitive credentials will be accessed and used. This can normalize implicit credential use, reduce informed consent, and increase the chance that a skill executes with broader privileges than the operator expects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The metadata is internally contradictory: it declares that no credentials are required, but then states that a gateway token is read from a local credentials file at runtime. This can mislead users, reviewers, and automation into granting or exposing access they did not expect, and it obscures the skill's true trust and credential requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Saying 'No credentials required' while simultaneously disclosing runtime token access is a security-significant misrepresentation. In this skill context, the skill creates cron tasks and interacts with a gateway, so hidden credential use increases the risk of unauthorized scheduling actions or misuse of an existing local token under false assumptions of harmlessness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script reads a gateway authentication token directly from the user's local config file and then uses it to create, update, and delete remote cron jobs. While token access is functionally related to the feature, silently harvesting credentials from a private config path expands the skill's privilege boundary and creates unnecessary secret exposure if the script is modified, logged, or reused in other contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script accesses a gateway token and performs remote state-changing actions against the cron service without any user-facing disclosure, confirmation, or consent step. This is dangerous because users invoking a seemingly simple scheduling helper may not realize it can read local secrets and mutate persistent remote jobs on their behalf.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language comments and user-facing guidance are written in Chinese, and later runtime messages also assume that locale without any opt-in or alternative. This can violate language policy when a skill forces a specific language rather than offering user choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.