Back to skill

Security audit

Setup claw.tech

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent setup purpose, but it asks users to run mutable remote installers, install a binary system-wide, and activate a remotely fetched skill without integrity verification.

Review this skill carefully before installing. Prefer pinned releases, verified checksums or signatures, user-local installation paths, and a reviewed pinned copy of openclaw-in-a-box. Treat the tapes database as sensitive because it can contain prompts and responses, and avoid placing ingest keys in shell history or shared environment logs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:20
Finding

Unverified Remote Installer Is Executed Directly by a Shell

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:36
Finding

Mutable Release Binary Is Extracted and Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:78
Finding

Mutable Remote Skill Instructions Are Downloaded and Subsequently Invoked

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This is a classic external script fetching issue: code is retrieved from a remote URL and immediately executed locally. If the hosting service, DNS, CDN, or publishing account is compromised, the installer becomes an instant remote code execution vector against anyone following the skill.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Step 1: Install tapes

bash
command -v tapes && tapes --version || curl -fsSL https://download.tapes.dev/install | bash

If the curl install fails, try: brew install papercomputeco/tap/tapes

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The explicit pipe into bash removes any review opportunity and chains untrusted network input straight into command execution. In a setup skill, users are especially likely to copy-paste such commands, which makes this pattern a high-probability arbitrary code execution hazard.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Step 1: Install tapes

bash
command -v tapes && tapes --version || curl -fsSL https://download.tapes.dev/install | bash

If the curl install fails, try: brew install papercomputeco/tap/tapes

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly installs telemetry that records every AI request and response into local storage, creating a substantial data-capture surface for prompts, outputs, and potentially secrets or proprietary content. Even though the later description says clawtel only uploads aggregate token metrics, the local collection itself increases privacy and compliance risk if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to fetch a network-delivered installer and pipe it directly to bash, which executes unauthenticated remote code immediately. This is dangerous because any compromise of the distribution endpoint, TLS-terminating infrastructure, or release pipeline would result in arbitrary code execution on the host during setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill tells users to export a sensitive ingest key directly in the shell without warning about shell history, process exposure, or secure secret storage. This can leak the key through terminal logs, history files, screenshots, shared shell sessions, or inherited environment variables.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill persists a remotely fetched SKILL.md into the local skills directory, creating a durable trust boundary crossing: future agent behavior may be influenced by unverified content retrieved from the network. In the context of agent skills, persistent installation is more dangerous because it can survive the setup session and affect later invocations or orchestration flows.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Step 4: Fetch openclaw-in-a-box skill

bash
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
  -o skills/openclaw-in-a-box/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

bash
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
  -o skills/openclaw-in-a-box/SKILL.md

Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
  -o skills/openclaw-in-a-box/SKILL.md

Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

bash
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
  -o skills/openclaw-in-a-box/SKILL.md

Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

bash
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
  -o skills/openclaw-in-a-box/SKILL.md

Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.

Static analysis

No suspicious patterns detected.