Back to skill

Security audit

Loop Engine — Governed Loops for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed governance integration, but its provider-backed examples send workflow evidence to external LLMs without applying the sanitizer the documentation says to use.

Review provider-backed examples before installing or adapting this skill. Prefer local governance mode unless you need LLM analysis, and when using providers, apply guardEvidence, use explicit evidence allowlists, tokenize or remove PII/PCI and infrastructure secrets, and require human review for real financial or operational decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
example-ai-replenishment-claude.ts:111
Finding

Unsanitized inventory evidence is transmitted to Anthropic

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
example-infrastructure-change-openai.ts:126
Finding

Unsanitized infrastructure metadata is transmitted to OpenAI

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
example-fraud-review-grok.ts:147
Finding

Unsanitized transaction and cardholder evidence is transmitted to xAI Grok

Content
View full analysis
= 0.6. Dismiss if score < 0.6 with high confidence.', evidence: { // NOTE: deviceFingerprint and cardholderName are synthetic in this example // Replace with anonymized or tokenized values in production ...transaction, cardholderAvgMonthlySpend: 1580, cardholderAvg30DayTransaction: 1420, previousTransactionsToday: 2, merchantRiskScore: 0.12, ipCountry: 'US', deviceFingerprint: 'known-device-7f3a', velocityAlerts: 1, isNewMerchant: false, cardholderTravelHistory: ['US', 'CA', 'MX'], }, }) ``` ### Technical Analysis The example sends the complete transaction object and behavioral attributes directly to the xAI Grok adapter. No `guardEvidence()` call enforces the controls documented in `SKILL.md:191-202`. The current example uses synthetic data and includes a warning, but production substitution could expose cardholder names, partial card data, transaction identifiers, spending behavior, device identifi ...[truncated 1603 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation asserts that all evidence objects must be guarded before forwarding to external LLM adapters and describes guardEvidence as enforcing PII blocking, prompt-injection stripping, and length limits. However, in this file that protection is only demonstrated as caller guidance and example usage, not as a guaranteed, enforced control in the integration itself. If consumers assume sanitization is automatic and pass raw evidence into provider-backed flows, sensitive data or adversarial prompt content could be transmitted externally.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · example-ai-replenishment-claude.ts (reported line 6)May include surrounding context.

ts
* 
 * Anthropic Claude analyzes inventory data and recommends a reorder.
 * A confidence-threshold guard blocks low-confidence recommendations.
 * A human-only guard ensures the final approval can't be auto-approved.
 * 
 * Requires: ANTHROPIC_API_KEY environment variable
 *

Static analysis

No suspicious patterns detected.