Back to skill

Security audit

安全技能插座

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a plain security-skill directory, but it tells agents to install and bulk-update other skills without enough review or safety controls.

Review this skill before installing. It does not contain executable code or an obvious malicious payload, but its documented workflows can add or update persistent agent skills from ClawHub. Only use the install and update commands for publishers and versions you trust, avoid bulk updates unless each change is reviewed, and confirm before running downstream scans or monitoring against sensitive systems.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:174
Finding

Unverified and Unpinned Third-Party Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 174-188
Vulnerability Type: Third-party supply-chain exposure
Risk Level: Medium

Vulnerable Code

bash
# Search for skills
clawhub search "关键词"

# Install a skill
clawhub install 技能名

# Update all skills
clawhub update --all

# List installed skills
clawhub list

Technical Analysis

The skill documentation directs the agent to install skills from ClawHub and bulk-update all installed skills. It does not require immutable version or digest pinning, publisher verification, package integrity validation, permission review, source inspection, or sandboxed testing before activation.

A marketplace skill is an external, mutable component that may contain instructions or executable resources. Consequently, the behavior reviewed at one point in time may differ from the behavior installed later. The clawhub update --all command further expands this risk by replacing multiple previously installed or reviewed components without requiring an individual security decision for each update.

The project does not itself contain a malicious payload, and exploitation depends on a malicious or compromised third-party skill. Nevertheless, its documented installation process creates an unsafe supply-chain path.

Attack Path

  1. An attacker publishes a malicious skill, compromises an existing skill or publisher account, or supplies a deceptively named skill through ClawHub.
  2. A user asks the hub to search for or install a skill matching the attacker's package.
  3. The agent follows the documented workflow and executes clawhub install without verifying an immutable version, digest, provenance, or requested permissions.
  4. Alternatively, clawhub update --all retrieves a malicious update for a previously trusted skill.
  5. The external skill is registered in the OpenClaw workspace and becomes available to influence later agent operations.
  6. Whe ...[truncated 811 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user confirmation before every third-party installation or update.
  2. Pin each approved skill to an immutable version and cryptographic digest rather than resolving a mutable package name.
  3. Verify package signatures, publisher identity, repository provenance, and integrity metadata before installation.
  4. Maintain an allowlist of reviewed publishers, package names, versions, and hashes.
  5. Download packages into a quarantine directory and audit their instruction files, scripts, dependencies, hooks, and requested permissions before activation.
  6. Replace clawhub update --all with individually reviewed and version-pinned updates.
  7. Run newly installed skills in a restricted sandbox with minimal filesystem, network, credential, command-execution, and tool permissions.
  8. Record installation provenance and retain a known-good version to support rollback.
  9. Re-audit every update, even when its package name or publisher has previously been approved.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file presents the skill description, usage guidance, trigger descriptions, and examples entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. This creates a language policy concern because the skill appears to impose a specific locale by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The hub explicitly supports searching for and installing external skills but does not warn about trust, provenance, permissions, or system-state changes. This is dangerous because it normalizes bringing unreviewed third-party code or prompts into the agent environment, which can introduce prompt injection, data exfiltration paths, malicious automation, or privileged local actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest repeatedly frames this skill as a unified platform for security capabilities, yet the integrated skills list includes AI performance diagnosis, machine health exploration, and general troubleshooting. Those functions are operationally outside the stated 'security skill' scope, creating a semantic mismatch between the hub's declared purpose and what it routes users toward.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad trigger keywords that overlap with normal conversation can cause unintended invocation of a skill, especially in an agent environment that auto-routes based on text. In this hub, unintended routing is more dangerous because the downstream skills include scanning, monitoring, and external search/install capabilities that may affect privacy, system state, or trust boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Overly vague routing keywords are unsafe in a hub that multiplexes many powerful skills because small wording differences can send requests to the wrong tool. Misrouting can result in unnecessary data exposure, noisy scans, or accidental use of external components when the user intended only a discussion or lookup.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Using generic trigger words like '扫描', '验证', '监控', and '审计' across multiple security skills creates ambiguous routing and increases the chance of invoking the wrong capability. In a security hub, accidental invocation is materially risky because some tools may access sensitive artifacts, perform active probing, or generate side effects on monitored systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The front-matter integrated list names one set of skills, while the later sections introduce additional ones such as ai-performance-analyzer, machine-health-explorer, claude-code-openclaw-troubleshoot, and agent-security-knowledge-query, and omit or vary others. For a hub whose core function is unified skill management and invocation, inconsistent declarations of managed capabilities create an intent-level mismatch about the actual scope of the platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill hub advertises capabilities such as threat monitoring, network protection monitoring, vulnerability scanning, and code scanning, but the markdown does not disclose that these actions may inspect project content, network-related data, or system activity. A user-facing description should warn about possible effects on privacy and system integrity when such capabilities are invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.