Back to skill

Security audit

Deep Research

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent research helper, but its ledger tool can delete directories outside its research folder if invoked with unsafe options.

Review before installing. The research workflow itself is disclosed and sensible, but run it in a restricted workspace and avoid using --force or path-like --name values until the ledger script validates that reset targets stay inside the intended research run directory. Do not store secrets or unnecessary private data in evidence logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/research_ledger.py:165
Finding

Output Directory Escape Enables Arbitrary Recursive Directory Deletion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs the agent to read local files, write run artifacts, and perform broad web research, but it does not declare any explicit tool scope or permissions boundary. That creates an overbroad operational surface where a host agent may grant more file and network access than necessary, increasing the risk of unintended data exposure, unsafe file access, or over-privileged execution during research runs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is extremely broad and overlaps with many general-purpose research, verification, due-diligence, and decision-support tasks, making it likely to be invoked in situations beyond its safest intended use. In combination with file, write, and network-capable behavior, ambiguous routing increases the chance that sensitive tasks are delegated to a skill that performs wide source ingestion and local artifact handling, expanding exposure to prompt-injection and data-leak risks.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-install.md (reported line 8)May include surrounding context.

Install locally

bash
mkdir -p ~/.openclaw/skills
unzip skill.zip -d ~/.openclaw/skills
ls ~/.openclaw/skills/deep-research/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/openclaw-install.md (reported line 10)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills
unzip skill.zip -d ~/.openclaw/skills
ls ~/.openclaw/skills/deep-research/SKILL.md

Install in a workspace

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/openclaw-install.md (reported line 18)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills
unzip skill.zip -d ~/.openclaw/skills
ls ~/.openclaw/skills/deep-research/SKILL.md

Install in a workspace

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

When --force is supplied, the script recursively deletes an existing non-empty run directory with shutil.rmtree(). Although the CLI help says 'reset an existing non-empty run directory,' there is no runtime confirmation prompt or explicit deletion warning at the point of execution, and this operation can irreversibly remove user data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.