Back to skill

Security audit

Experiment Notes

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently provides local experiment logging, but its plaintext persistent notes can expose secrets if users or agents record raw commands or errors.

Install only if you are comfortable keeping local plaintext experiment history. Configure agents and users to avoid logging secrets, tokens, credentials, private customer data, full auth headers, or raw dumps, and periodically delete or protect ~/.openclaw/memory/experiments/ if the machine or backups are shared.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/expnote.py:62
Finding

Potentially Sensitive Experiment Data Stored in Plaintext Without Enforced Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill clearly describes persistent local storage under ~/.openclaw/memory/experiments/ and references a Python CLI that reads and writes files, but it does not declare any tool scope such as permissions or allowed-tools. That creates a transparency and policy gap: an agent or reviewer cannot easily constrain or audit the file access the skill requires, increasing the chance of unintended writes or broader-than-expected local data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises automatic logging of trial-and-error, commands, failures, and lessons learned, but provides no warning against recording secrets, tokens, credentials, personal data, or sensitive command output. In practice, experiment logs often contain raw CLI arguments, stack traces, URLs, headers, and environment-derived values, so persistent storage without caution can leak sensitive data into local memory files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installation section states that experiment records are stored persistently in ~/.openclaw/memory/experiments/ but omits any notice about privacy, retention, access control, or cleanup. Persistent local logs materially increase exposure because sensitive operational details can remain on disk indefinitely and be read later by other tools, users, backups, or processes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The agent guidance explicitly tells the agent to log every attempt, including executed commands and raw error output, regardless of success or failure. Commands and error output are high-risk fields for secret exposure because they frequently contain API keys, auth headers, internal hostnames, filesystem paths, customer data, or debug dumps; persisting them into local memory creates a durable exfiltration and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill persistently stores free-form experiment data under the user's home directory, including task descriptions, commands, errors, fixes, and lessons, without any notice, consent prompt, minimization, or retention controls. In an agent context, those fields can easily contain secrets, internal paths, tokens, proprietary prompts, or sensitive failure logs, so silent disk persistence increases the risk of privacy leakage and later compromise from local file access or backup/sync exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.