Back to skill

Security audit

Skill Discovery

Security checks for vulnerabilities and agentic risk

Overview

This is a real skill-discovery tool, but it can install and remove global skills and retain local logs/backups in ways users should review before installing.

Review this skill before installing. Use only dry-run/recommendation mode unless you explicitly intend it to modify your global OpenClaw skills, prefer pinned and reviewed installer tooling, avoid putting secrets in discovery prompts, and do not set TRASH_DIR to any directory containing data you cannot afford to lose.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
auto-discover.js:489
Finding

Default CLI workflow globally installs unreviewed remote skills

Content
View full analysis
!a.startsWith('--')).join(' '); if (!query) { console.error('错误: 请提供查询内容'); process.exit(1); } (async () => { try { const result = await discoverAndInstall(query, { dryRun }); ``` ```javascript // auto-discover.js:489-491 const installResult = isClawhub ? await clawhubAdd(best.skill.fullName) : await skillsAdd(best.skill.fullName, { global: true, yes: true }); ``` ### Technical Analysis The CLI derives `dryRun` solely from the presence of `--dry-run`. Therefore, an ordinary invocation without this option passes `{ dryRun: false }` to the discovery workflow. When a result is selected, the installation path uses `global: true` and `yes: true`. This installs the selected third-party skill globally and suppresses interactive confirmation. The selected package originates from skills.sh or ClawHub and is not subjected to a local source-code audit before installation. This behavior contradicts the documented safe default of recommendation-only operation. The library API defaults to dry-run, but the command-line entry point overrides that default with `false`. ### Attack Path 1. An attacker publishes or compromises a skill whose metadata matches a commonly searched query. 2. A user invokes `skill-discovery "query"` without the optional `--dry-run` flag. 3. The project searches external registries and selects the highest-scoring result. 4. The CLI passes `dryRun: false` to the installation workflow. 5. The selected skill is installed globally with non-interactive confirmation enabled. 6. Code or instructions contained in the installed skill become available ...[truncated 477 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
auto-discover.js:209
Finding

Documented source and quality validation is not enforced

Content
View full analysis
{ let score = 0; score += Math.min(skill.installs / MAGIC.MIN_INSTALLS_SCALE, 4) * MAGIC.INSTALLS_SCORE_FACTOR; const isTrusted = CONFIG.trustedOwners.includes(skill.owner); score += isTrusted ? MAGIC.TRUSTED_SCORE : MAGIC.UNTRUSTED_SCORE; return { skill, score }; }); scored.sort((a, b) => b.score - a.score); return scored[0]; } ``` ```javascript // auto-discover.js:433-438 function filterAndSelect(results) { const best = selectBest(results); console.log(`⭐ 最佳: ${best.skill.fullName} (评分: ${Math.round(best.score)})`); return { success: true, best }; } ``` ### Technical Analysis The trusted-owner list is used only as a ranking bonus. An untrusted owner receives `MAGIC.UNTRUSTED_SCORE`, which is a positive score, rather than being rejected or requiring explicit approval. No minimum installation threshold is enforced. The installation count only contributes to ranking, so a result with zero or very few installations remains eligible. `filterAndSelect()` directly returns the top-ranked entry without validating provenance, signatures, immutable versions, content, or a minimum reputation threshold. Consequently, the stated quality-validation model is not a security boundary. If an untrusted result is the only result or ranks above other candidates, it can proceed to recommendation or installation. ### Attack Path 1. An attacker publishes a skill with a name and description optimized for a target query. 2. The external registry returns that skill in the search results. 3. The attacker-controlled result is assigned a positive score even when its owner is absent from the trusted-owner list. 4. No ...[truncated 711 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
openclaw-hook.js:110
Finding

Environment-controlled trash path enables recursive deletion outside the intended directory

Content
View full analysis
SEVEN_DAYS_MS) { await fs.rm(entryPath, { recursive: true }); cleaned++; } } ``` ### Technical Analysis `TRASH_DIR` is accepted directly from the process environment. The path is not canonicalized, restricted to the OpenClaw directory, checked against filesystem roots, or validated for symlink traversal. `cleanTrash()` enumerates the configured directory and recursively removes every child whose modification time exceeds seven days. Because this function is publicly exported, any caller that can influence the environment or invoke the API can cause deletion under an arbitrary writable directory. The deletion applies to all matching child entries, not only backup entries created by `safeRemove()`. ### Attack Path 1. An attacker, wrapper script, compromised service configuration, or unsafe deployment controls the `TRASH_DIR` environment variable. 2. `TRASH_DIR` is set to a sensitive writable directory containing old files or subd ...[truncated 724 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
openclaw-hook.js:162
Finding

Full user prompts are persistently logged with incomplete sensitive-data redaction

Content
View full analysis
CONFIG.maxLogEntries) { logs = logs.slice(-CONFIG.maxLogEntries); } await fs.mkdir(path.dirname(CONFIG.logPath), { recursive: true }); await fs.writeFile(CONFIG.logPath, JSON.stringify(logs, null, 2)); } catch (e) { console.error('日志记录失败:', e.message); } } ``` ```javascript // openclaw-hook.js:162-165 await logDiscovery(result.installed ? 'install' : 'discover', { input: userInput, ...result }); ``` ```javascript // auto-discover.js:323-337 const SANITIZE_REDACT_KEY_PATTERNS = [ /\btoken\b/i, /\bsecret\b/i, /\bpassword\b/i, /\bapi[_-]?key\b/i, /\bcredential\b/i, /\bauthorization\b/i ]; const SANITIZE_REDACT_VALUE_PATTERNS = [ /\bBearer\s+[\w.-]+/i, /\bsk-[\w.-]+/, /ghp_[\w]+/, /===+\s*[A-Za-z]+\s*===+/ ]; ``` ### Technical Analysis The hook places the complete `userInput` string into the discovery log. Because it is stored under the generic `input` key, key-based redaction does not remove it. Value-based redaction recognizes only a limited set of token formats. It does not reliably detect arbitrary passwords, private keys, connection strings, session cookies, credentials embedded in URLs, personal information, source code secrets, or tokens issued by many providers. The log is persisted as plaintext JSON. `fs.writeFile()` does not explicitly enforce a restrictive file mode in this implementation. The ...[truncated 1033 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心流程是“发现并推荐”,且明确说明“由用户确认后安装”。但代码中的主流程 autoDiscover 在筛选出最佳 skill 后会直接进入 resolveInstall;当 dryRun 为 false 时,调用 skillsAdd(..., { global: true, yes: true }) 或 clawhubAdd(...) 执行真实安装,其中 yes:true 表明自动确认而非等待用户确认。这属于重要行为差异,不是单纯实现细节。此外,代码还会查询已安装的全局 skill 列表以判断是否已安装。搜索、匹配、质量偏好选择等部分与声明基本一致,但安装环节的自动执行与“用户确认后安装”明显不符,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose describes runtime functionality for discovering and recommending skills, but the code provided is purely a development tooling configuration file for ESLint. It sets parser/language options, globals, and linting rules for source and test files, and includes eslint-config-prettier. This is unrelated to the described product behavior and does not exercise any relevant capabilities, permissions, or triggers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的核心是“基于用户意图发现并推荐 skill,并由用户确认后安装”。代码的 onUserInput 部分基本符合这一点:它对输入进行自动发现、在 dryRun 模式下返回安装建议、已安装时提示、失败时返回候选或回退信息,也没有在该路径下直接自动安装。 但该代码块还包含多项未在描述中体现的实质能力:1)safeRemove 可全局卸载 skill;2)卸载前会把目标目录复制到 trash 作为备份;3)cleanTrash 会扫描并删除超过期限的备份;4)logDiscovery 会把 discovery/install/remove 事件写入本地日志文件。 这些能力超出了“发现并推荐 skill、确认后安装”的声明范围,属于明显的未声明功能,尤其是卸载与文件持久化操作,因此应判定为描述与实际行为存在不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明强调的是一个基于用户意图进行发现、质量验证、推荐最佳匹配,并在用户确认后安装的推荐型能力。但实际代码主要是底层 CLI 包装器,负责执行 npx skills/clawhub 的 list/find/add/remove/check/update 命令,以及解析输出与重试。代码中没有体现‘分析用户意图’、‘验证质量’、‘推荐最佳匹配’这类核心逻辑;相反,它提供了多种运维/管理能力,尤其是删除、检查更新、批量更新、列出已安装项等,这些都属于未声明的实质能力。另外,安装函数支持直接传入 yes 以跳过确认,不能证明“必须由用户确认后安装”。因此描述与代码行为存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向最终用户的 skill 发现与推荐能力:分析用户输入、搜索匹配项、验证质量、推荐最佳结果,并在用户确认后安装。实际代码则是一个测试脚本,不实现这些业务流程。它主要调用 wrapper 的 list/find/parse 功能进行演示和验证:读取已安装的全局 skills、搜索硬编码关键词“react”、以及解析示例输出文本。代码中没有用户意图分析、质量验证、推荐排序决策、确认交互或安装逻辑。因此其主要目的与声明明显不符,且还执行了未声明的已安装 skill 枚举能力。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file explicitly implements automatic discovery and installation, while the skill metadata says recommendations should be confirmed by the user before installation. That mismatch means the code can move from intent inference directly to package installation, violating least surprise and enabling unintended execution of third-party skill code.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

resolveInstall proceeds to clawhubAdd(...) or skillsAdd(..., { yes: true }) without any interactive or prior confirmation check. Because skill installation can execute or introduce external code, bypassing user approval materially increases the risk of unauthorized package installation and downstream code execution.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · openclaw-hook.js (reported line 251)May include surrounding context.

js
result.candidates.slice(0, 3).forEach((c, i) => {
      prompt += `${i + 1}. ${c.fullName} (${c.installs} installs)\n`;
    });
    return prompt;
  }

  if (!result.success && result.fallback) {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains natural-language text saying that README and SKILL.md were made entirely Chinese. A mandatory single-language documentation policy can violate locale-choice expectations when no opt-in or region-specific justification is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes behavior that automatically discovers and installs skills, while the surrounding context says installation should occur after user confirmation. This mismatch can mislead users and host systems about when system-modifying actions occur, increasing the chance of unauthorized installation of code and reducing meaningful consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to execute npx skills without pinning a specific package version, which allows whatever version is current in the registry to run at install time. Because this skill's purpose is to discover and install other skills automatically, an unpinned package in the trust chain increases supply-chain risk and can lead to arbitrary code execution if the upstream package is compromised or changes unexpectedly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly advertises automatic installation based on user intent, contradicting a safer approval model and encouraging unattended installation of third-party skills. In this context, the contradiction is dangerous because the skill is designed to modify the environment by fetching and installing code, so users may trigger code installation with ordinary requests they did not understand as approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents automatic installation behavior without a strong warning that this will modify the system by downloading and installing code. For a discovery skill, failure to clearly disclose system-modifying behavior undermines informed consent and can cause users to invoke dangerous actions through normal conversation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This reference again relies on npx skills without a pinned version, so users may execute a different package version than the author tested. In a skill that performs search, validation, and installation of additional components, this broadens the supply-chain attack surface and makes compromise of the discovery tool especially dangerous.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and overlap with common conversational requests like 'help me' or 'I need...', which raises the likelihood of accidental activation. Because activation can lead to searching for and installing skills, ambiguous triggers materially increase the risk of unintended system modification from benign user input.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The development instructions direct contributors to use npx skills without version pinning, which exposes both maintainers and users to executing unreviewed upstream changes. Even in a README, such guidance can normalize insecure operational practices and enable registry or package compromise to affect local environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Listing npx skills as a dependency without version constraints indicates reliance on mutable remote code at runtime. Given this skill automates discovery and installation, the context makes the risk more severe because compromise of the dependency could directly influence what gets installed and executed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The manifest declares runtime requirements and documents use of environment variables such as OPENCLAW_DIR, but it does not declare any explicit tool scope or permissions. This creates a transparency and least-privilege gap: hosts or users may not realize the skill can access environment-derived configuration and local paths, increasing the chance of unintended data exposure or broader execution than expected.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill depends on external tooling via npx/CLI references without any pinned version, which means the resolved package or server behavior can change over time. If an upstream package is compromised or a breaking release is published, the skill could execute unintended code or produce unsafe results during discovery or installation workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad trigger phrases can cause accidental invocation of a skill that searches external registries and may eventually lead users toward installation actions. In this context, over-broad activation increases the chance of unsolicited external lookups, metadata leakage about user intent, and confusing recommendations in normal conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The English examples are generic enough that ordinary support requests could trigger the skill unintentionally. Because this skill interfaces with external registries and can progress toward installation workflows, accidental activation raises unnecessary privacy and supply-chain exposure compared with a narrowly scoped recommender.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The stated purpose is to analyze user intent, search registries, validate quality, recommend a matching skill, and install it after user confirmation. Line L77 introduces an additional uninstall-and-backup capability, which goes beyond discovery/recommendation and is not explained as part of the skill's core scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Retaining backups of uninstalled skills in .trash/ for 7 days creates a data-retention surface that may preserve sensitive code, configuration, or embedded secrets longer than users expect. In a discovery-oriented skill, this behavior is contextually riskier because backup persistence is not essential to the core recommendation function and expands local exposure if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Documenting reliance on npx skills without a pinned version introduces a supply-chain risk because execution semantics depend on whatever package version npx resolves at runtime. In a skill that can lead to installation actions, unpinned resolution materially increases the chance of malicious or unexpected code execution from upstream changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level documentation advertises fully automated execution, contradicting the manifest's user-confirmed installation model. Even though this is documentation, it is security-relevant because it normalizes and justifies unsafe automation, making future maintenance and operator use more likely to bypass consent controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.