Back to skill

Security audit

OpenClaw Copilot CLI Wrapper

Security checks for vulnerabilities and agentic risk

Overview

This skill is a thin Copilot CLI helper, but it repeatedly recommends unrestricted agent access that can read, edit, run commands, and use network access without clear limits.

Install only if you are comfortable with Copilot receiving prompts and repository context and with examples that can grant broad local command, file, and network access. Prefer running it in a limited workspace or container, avoid `--allow-all` unless needed, review AGENTS.md first, and keep output/logging visible for file edits or shell tasks.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:24
Finding

Unrestricted Delegated Execution Through Copilot CLI

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–35 and 46–56
Vulnerability Type: Unrestricted tool, filesystem, and network permissions
Risk Level: High

Vulnerable Code

text
copilot -p \"Your prompt here\" --allow-all --silent
text
- `--allow-all`: Enables all tools/paths/URLs (use `--yolo` for short).
- `--silent`: Outputs only agent response.
- `--model claude-sonnet-4.6` or `gpt-5.2` etc. to choose model.

**In OpenClaw exec:**
text
exec:
  command: copilot -p 'Generate a Python script to...' --allow-all --silent
text
### Shell task
text
copilot -p 'List all .js files and summarize' --allow-all
text
### Code generation
text
copilot -p 'Create a simple Express server in Node.js' --allow-all --silent
text
### File edits
text
copilot -p 'Add error handling to main.js' --allow-all

Technical Analysis

The Skill recommends --allow-all as the standard invocation mode and identifies --yolo as its shorthand. According to the Skill itself, this option enables access to all tools, filesystem paths, and URLs. Such unrestricted authority is not necessary for ordinary code generation, source summarization, or narrowly scoped file edits and therefore violates least-privilege principles.

Copilot is a delegated agent capable of selecting and executing tools based on prompts and contextual instructions. If its input or automatically loaded repository instructions are attacker-controlled, unrestricted access can turn an otherwise textual prompt-injection condition into command execution, arbitrary file access or modification, and outbound network communication. The use of --silent can further reduce operator visibility into the delegated activity, although it is not independently the source of the privilege issue.

Attack Path

  1. A user invokes this Skill against a repository ...[truncated 1507 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove --allow-all and --yolo from default commands, recommendations, and examples.
  • Require explicit, per-action approval for shell execution, file modification, and network access.
  • Restrict filesystem permissions to the intended workspace and deny access to home-directory credentials, SSH material, cloud configuration, and unrelated repositories.
  • Apply URL or domain allowlists and disable outbound network access when it is unnecessary.
  • Separate read-only analysis from file-editing and shell-task workflows, granting each operation only the tools it needs.
  • Use --no-custom-instructions when operating on untrusted repositories, or review repository instruction files before allowing them to influence Copilot.
  • Avoid --silent for security-sensitive operations; retain visible command and approval logs.
  • Run the CLI in a sandbox or container under a low-privilege account with minimal mounted files and no unnecessary credentials.
  • Document the risks of prompt injection and require human review before executing generated commands or accepting security-sensitive file changes.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill directs the agent to use an external model/provider selection (gpt-5.3-codex) while also enabling --allow-all, creating a pathway for sensitive prompts, code, file contents, or environment-derived data to be sent to a third-party service. In an automation skill, this expands data exposure and execution risk beyond the local environment.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

Advanced models

text
copilot -p '...' --model gpt-5.3-codex --allow-all

Test

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly recommends running Copilot CLI with --allow-all, which grants broad tool, path, and URL access without any safety caveats or scope restriction. In the context of an agent skill that can perform shell tasks and file edits, this meaningfully increases the chance of destructive commands, sensitive file access, or unintended network interactions driven by model output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The examples normalize shell-task and file-editing operations without warning that they may execute impactful commands or alter repository contents. Because users may copy these examples directly, the omission reduces informed consent and makes unsafe execution more likely, especially when paired with permissive flags like --allow-all.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Code generation

text
copilot -p 'Create a simple Express server in Node.js' --allow-all --silent

File edits

Static analysis

No suspicious patterns detected.