Back to skill

Security audit

Context Guardian

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently monitors local context usage and stores a small local state file, with no evidence of hidden collection, network transfer, or deceptive behavior.

Install only if you want heartbeat/manual context monitoring and are comfortable with it storing recent usage percentages locally in the OpenClaw workspace. Avoid running the reset rm command unless you intentionally want to erase this skill's alert history; a future version should use safer state-file handling and a clearer reset flow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check.sh:20
Finding

Predictable State-File Write Can Follow Symbolic Links

Content
View full analysis
100 then .[-100:] else . end)') echo "$new_state" > "$STATE_FILE" } ``` ### Technical Analysis The script writes state to a fixed, predictable path using ordinary shell redirection. It does not verify that the destination is a regular file, reject symbolic links, validate ownership of the workspace and memory directory, or perform the update through a securely created temporary file. Shell redirection follows symbolic links and truncates the resolved target before writing. A local actor who can create or replace `memory/context-guardian-state.json` could therefore make it point to another file writable by the account running the Skill. When `save_state` executes, the target file would be replaced with generated JSON state. The direct write is also non-atomic. Interruption or concurrent heartbeat invocations could leave a truncated or partially written state file. ### Attack Path 1. The attacker obtains write access ...[truncated 1216 chars]
Remediation
View remediation
&2 exit 1 fi tmp_file=$(mktemp "$STATE_DIR/.context-guardian-state.XXXXXX") chmod 600 "$tmp_file" printf '%s\n' "$new_state" > "$tmp_file" mv -f -- "$tmp_file" "$STATE_FILE" ``` The implementation should additionally verify directory ownership and use locking where multiple heartbeat invocations are possible. ]]>
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The markdown contains a direct rm command for users to execute, which is a destructive shell action. Although the path is specific and appears limited to this skill's own state file, documentation that encourages copy-pasting deletion commands can still be abused or cause mistakes, especially if paths are edited, expanded incorrectly, or the environment differs from what the author assumed.

Content

Scanner excerpt · examples/manual-check.md (reported line 63)May include surrounding context.

To reset the state and allow alerts to trigger again:

bash
rm ~/.openclaw/workspace/memory/context-guardian-state.json

This is useful if you want to test alerts or if the state gets corrupted.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly instructs users to delete a state file to reset behavior, but it does not warn that this removes alert history and prior state. While the target is a narrow application state file rather than arbitrary user data, destructive commands in docs can still lead to unintended loss of operational state or normalized unsafe habits around running shell deletion commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.