Back to skill

Security audit

skill-creator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local skill-authoring helper with no evidence of hidden data theft, persistence, or destructive behavior.

Install this if you want help authoring or validating OpenClaw skills. Use normal caution before running the included helper scripts or any repository tests, especially in repositories you do not trust, and review what would be packaged before creating a .skill archive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description focuses on modifying or auditing AgentSkills and SKILL.md files, including validation and restructuring. The supplied code's primary function is different: it packages an existing skill directory into a .skill archive after validation. While validation is mentioned in the description, the main behavior here is archival/distribution creation, which is a distinct capability not represented in the declared purpose. The file writing and zip packaging are central behaviors, not incidental implementation details, so this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description focuses on modifying or validating AgentSkills and SKILL.md files themselves. The actual code chunk does not implement editing, tidying, restructuring, or direct auditing of skill definitions; instead, it is a test harness for packaging behavior. Its primary purpose is to verify secure archive creation and packaging invariants, including symlink exclusion, path containment, and deterministic archive entry order. Those are materially different capabilities from the declared purpose, so this is a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
apply live `SKILL.md` files with shell commands or helper scripts.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
apply live `SKILL.md` files with shell commands or helper scripts.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
apply live `SKILL.md` files with shell commands or helper scripts.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_package_skill.py (reported line 68)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_package_skill.py (reported line 93)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_package_skill.py (reported line 110)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to match many generic editing or auditing requests involving skills, which can cause the skill to be invoked in contexts the user did not intend. In an agent environment, overbroad activation increases the chance that file-modifying guidance or validation steps are applied to the wrong target, expanding the attack surface for prompt-trigger abuse or unintended changes.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The instruction to 'run any script tests touched' encourages execution of repository scripts without requiring trust checks, path restrictions, or review of what the script does first. In a hostile or mixed-trust repository, that can lead to arbitrary code execution through test hooks, validation scripts, or modified helper files, making the skill context more dangerous because it explicitly handles local project content and workflows.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
5. Keep brittle command syntax, auth caveats, safety rules, and validation.
6. Replace tables with bullets unless a table is clearly needed.
7. Relax prose; fragments ok.
8. Validate frontmatter and run any script tests touched.

## Validation

Static analysis

No suspicious patterns detected.