Back to skill

Security audit

oc-doctor

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local OpenClaw diagnostic skill with some caution-worthy install and cleanup guidance, but no evidence of hidden exfiltration, persistence, or deceptive behavior.

Before installing, prefer a pinned or reviewed install method instead of the unpinned npx -g -y command. When running the skill, review the diagnostic report carefully because it can read local OpenClaw configs, sessions, logs, cron data, and workspace Markdown, and approved fixes may change config/session files or delete cache/temp data. Do not approve batch fixes unless the exact changes and deletion targets are shown and secrets remain redacted.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:43
Finding

Unpinned npm Installer Executes Mutable Third-Party Code Without Confirmation

Content
View full analysis
Remediation
View remediation
add bryant24hao/oc-doctor -g ``` 2. Publish and document the expected package name, version, registry, source repository, and integrity digest. 3. Verify the downloaded package against a trusted checksum or lockfile before execution. 4. Avoid suppressing confirmation for security-sensitive installation steps where practical. 5. Consider providing a non-executing installation method, such as downloading a versioned release archive and verifying its checksum before copying the skill files. 6. Apply the corrected command consistently in both README files and both user-story documents. ]]>

other

Note
Location
assets/demo.svg:3
Finding

Bundled SVG Loads an External Google Fonts Resource

Content
View full analysis
@import url('https://fonts.googleapis.com/css2?family=JetBrains+Mono:wght@400;700&display=swap'); text { font-family: 'JetBrains Mono', 'SF Mono', 'Menlo', 'Consolas', monospace; } ``` ### Technical Analysis The bundled SVG imports a stylesheet from Google Fonts. A renderer that permits external SVG resources may issue a network request when the image is displayed. This behavior makes the asset non-self-contained and conflicts with the project’s broad statements that it makes no network requests. The diagnostic shell script itself contains no network operation; the issue is limited to rendering the documentation asset in a client that resolves external SVG resources. Whether a request occurs depends on the rendering environment. Some repository hosts sanitize SVGs or block remote resources, while browsers, documentation generators, and local image viewers may resolve them. ### Attack Path 1. A user or documentation service opens a page that renders `assets/demo.svg`. 2. The SVG renderer processes the CSS `@import` directive. 3. If external resources are allowed, the renderer connects to `fonts.googleapis.com`. 4. The external service receives request metadata associated with the user or rendering service. No code-execution path was identified from this import alone. ### Impact Assessment The external request may disclose the renderer’s IP address, user agent, request timing, and potentially referrer-related metadata to Google. It can also cause rendering failures or delays in offline and restricted environments. This finding does not grant local privileges, provide access to OpenClaw configuration, or expose file contents directly. Its scope is limited to network metadata and the reliability of documentation rendering. ]]>
Remediation
View remediation
text { font-family: 'SF Mono', 'Menlo', 'Consolas', monospace; } ``` 2. If JetBrains Mono is required, bundle a reviewed font asset locally and reference it without making a remote request. 3. Sanitize or test the SVG in all supported documentation renderers to ensure external resources are not fetched. 4. If the remote import is intentionally retained, narrow the privacy documentation to clarify that the diagnostic runtime is offline while documentation assets may load external resources. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description substantially overstates the scope and functionality. The provided code is a single shell script focused on collecting system-instruction health data: scanning markdown files under local OpenClaw workspaces, estimating tokens, identifying empty templates, detecting certain tool-description references, checking for BOOTSTRAP.md, and resolving a model context window from configuration files. It is read-only and emits raw JSON metrics. There is nothing implementing the claimed comprehensive 11-section doctor, nor checks for cron, gateway, security misconfigurations, session bloat, or model drift, and no generation of CRITICAL/WARNING/INFO findings or one-click remediation. While one small part of the declared description mentions system instruction token budget, the actual code only covers that narrow subset, making the overall description materially inaccurate.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

The skill searches under ~/.claude/skills and ~/.agents/skills to locate and execute a helper script, which reaches into agent configuration and installation directories outside the declared OpenClaw data paths. That expands the data-access surface and can reveal local agent layout or execute an unexpected script if those directories contain a manipulated matching path.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

bash
# Find the skill directory (works whether installed via skills.sh, clawhub, or manually)
SKILL_DIR="$(find ~/.claude/skills ~/.agents/skills -maxdepth 3 -name 'sysinstruction-check.sh' -path '*/oc-doctor/*' 2>/dev/null | head -1 | xargs dirname)"
bash "$SKILL_DIR/sysinstruction-check.sh"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/demo.svg (reported line 12)May include surrounding context.

text
<stop offset="100%" stop-color="#2c2c2e"/>
    </linearGradient>
  </defs>
  <!-- Window -->
  <rect width="800" height="620" rx="10" fill="#1c1c1e"/>
  <!-- Title bar -->
  <rect width="800" height="36" rx="10" fill="url(#titlebar)"/>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though the command is scoped to ~/.openclaw/browser/*, it is still a destructive shell command presented as a fix without caution, validation, or backup guidance. In the context of a troubleshooting skill that offers one-click fixes, normalizing raw rm -rf usage can lead to accidental data loss if paths are expanded unexpectedly, copied incorrectly, or executed in automation.

Content

Scanner excerpt · docs/user-story.en.md (reported line 68)May include surrounding context.

md
- Fix: set reserveTokensFloor: 20000

### [WARNING] Browser cache 282 MB
- Fix: rm -rf ~/.openclaw/browser/*

### [INFO] System instructions using 2.6% of context
- BOOTSTRAP.md still present (588 tokens reclaimable)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though the command is scoped to ~/.openclaw/browser/*, it is still a destructive shell command presented as a fix without caution, validation, or backup guidance. In the context of a troubleshooting skill that offers one-click fixes, normalizing raw rm -rf usage can lead to accidental data loss if paths are expanded unexpectedly, copied incorrectly, or executed in automation.

Content

Scanner excerpt · docs/user-story.en.md (reported line 68)May include surrounding context.

md
- Fix: set reserveTokensFloor: 20000

### [WARNING] Browser cache 282 MB
- Fix: rm -rf ~/.openclaw/browser/*

### [INFO] System instructions using 2.6% of context
- BOOTSTRAP.md still present (588 tokens reclaimable)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The markdown recommends a raw rm -rf ~/.openclaw/browser/* deletion command as a fix. Even though the path is scoped, recursive forced deletion in a user-facing troubleshooting skill is risky because path expansion, symlink surprises, misconfigured home directories, or copy-paste mistakes can cause unintended data loss, especially when presented as a one-click remediation pattern.

Content

Scanner excerpt · docs/user-story.md (reported line 68)May include surrounding context.

md
- 修复:设置 reserveTokensFloor: 20000

### [WARNING] 浏览器缓存 282 MB
- 修复:rm -rf ~/.openclaw/browser/*

### [INFO] 系统指令占上下文 2.6%
- BOOTSTRAP.md 仍在(588 tokens 可回收)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The markdown recommends a raw rm -rf ~/.openclaw/browser/* deletion command as a fix. Even though the path is scoped, recursive forced deletion in a user-facing troubleshooting skill is risky because path expansion, symlink surprises, misconfigured home directories, or copy-paste mistakes can cause unintended data loss, especially when presented as a one-click remediation pattern.

Content

Scanner excerpt · docs/user-story.md (reported line 68)May include surrounding context.

md
- 修复:设置 reserveTokensFloor: 20000

### [WARNING] 浏览器缓存 282 MB
- 修复:rm -rf ~/.openclaw/browser/*

### [INFO] 系统指令占上下文 2.6%
- BOOTSTRAP.md 仍在(588 tokens 可回收)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation examples include broad phrases like "openclaw doctor" and "openclaw diagnose" that could be matched in normal conversation, causing the skill to trigger unintentionally. Because this skill can propose and perform interactive remediation on local configuration, logs, sessions, and workspace files, accidental activation increases the chance of unnecessary inspection of sensitive local state or unintended modification prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states the skill will 'automatically match your language,' which imposes locale/language behavior by default rather than offering a user choice. The policy for this audit flags language or locale constraints unless the skill explicitly provides opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest lists several specific trigger phrases, but then adds the broad natural-language condition "or troubleshooting OpenClaw." That phrase is ambiguous about what wording or context should activate the skill and could overlap with ordinary support conversations about OpenClaw rather than an explicit request to run this diagnostic skill.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Enumerating ~/.claude/skills and ~/.agents/skills exposes information about installed agent skills and local environment structure that is not necessary for a health check result. In adversarial or privacy-sensitive contexts, that metadata can leak tool inventory and make follow-on targeting easier, especially because the enumeration is immediately tied to selecting a script for execution.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

bash
# Find the skill directory (works whether installed via skills.sh, clawhub, or manually)
SKILL_DIR="$(find ~/.claude/skills ~/.agents/skills -maxdepth 3 -name 'sysinstruction-check.sh' -path '*/oc-doctor/*' 2>/dev/null | head -1 | xargs dirname)"
bash "$SKILL_DIR/sysinstruction-check.sh"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The user story promotes one-click batch fixes that modify configuration, clear caches, archive files, and replace files, but it does not warn that these actions change local state and may delete or overwrite data. Users may approve actions without understanding persistence, rollback, or data-loss implications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The documentation recommends installing the skill via npx skills add bryant24hao/oc-doctor -g -y without pinning a specific version or commit. That creates a supply-chain risk because users may fetch whatever package version is current at install time, including a compromised or unexpectedly changed release.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The story promotes one-click or bulk fixes that modify configuration, align sessions, archive/replace files, and delete cached data, but it does not clearly foreground the operational impact, rollback expectations, or need for confirmation per action. In a troubleshooting skill, this can lead users to approve destructive or broad system changes without understanding what will be altered.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The SVG imports a remote Google Fonts stylesheet, causing the asset to make an external network request when rendered. For a local diagnostic skill, this creates unnecessary third-party dependency, privacy leakage (viewer IP/user agent/request metadata), and weakens offline/self-contained behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The installation command uses -g -y, encouraging global, non-interactive installation without warning about trust or system-wide effects. This increases the chance users will install and execute code they have not reviewed, with broader impact on their environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Nearly the entire document is written in Chinese, which imposes a specific language presentation on the user. Although line 1 links to an English version, the file itself does not state in-body that users may choose their preferred language, so this is a mild locale-choice concern under the language policy rule.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
docs/user-story.en.md:68

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
docs/user-story.md:68