Back to skill

Security audit

Lark Multi Agent Factory

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it needs review because it handles Lark app secrets and writes persistent agent configuration in ways that are under-scoped.

Review before installing. Use a protected config file instead of inline --config for real Lark secrets, check permissions on ~/.openclaw/openclaw.json, inspect generated IDENTITY.md and SOUL.md before using new agents, and confirm that automatic agentToAgent.allow changes match your intended trust boundary.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/setup_agents.py:224
Finding

Persistent Instruction Injection Through Unsanitized Agent Profile Fields

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:44
Finding

Lark Application Secrets Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/setup_agents.py (reported line 225)May include surrounding context.

python
save_config(cfg)
    print(f"✅ agent '{agent_id}' 已从配置中移除")
    print(f"   ⚠️  工作区目录未删除,请手动确认是否清除:")
    print(f"   rm -rf {OPENCLAW_DIR}/workspace-{agent_id}")
    print(f"   rm -rf {OPENCLAW_DIR}/agents/{agent_id}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/setup_agents.py (reported line 226)May include surrounding context.

python
print(f"✅ agent '{agent_id}' 已从配置中移除")
    print(f"   ⚠️  工作区目录未删除,请手动确认是否清除:")
    print(f"   rm -rf {OPENCLAW_DIR}/workspace-{agent_id}")
    print(f"   rm -rf {OPENCLAW_DIR}/agents/{agent_id}")


# ─── 创建单个 agent ───────────────────────────────────────────────────────────

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell execution and file-modifying behavior but does not declare any tool scope or allowed-tools boundary. That creates an unsafe trust gap: an invoking agent may gain or assume broad shell/file capabilities without explicit least-privilege constraints, increasing the risk of unintended filesystem changes or command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to place Feishu App Secret values directly in command-line arguments and inline JSON. Secrets passed this way can be exposed via shell history, terminal scrollback, process listings, audit logs, and agent transcripts, which is especially risky because these credentials control external service accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring and all user-facing usage/help documentation in this file are written exclusively in Chinese, which imposes a specific language on users without offering a choice or documenting a justified locale restriction. The stated policy flags language or locale constraints when they are forced without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented primarily as a batch agent configuration tool, but it also performs destructive deletion and service restarts. That scope expansion is security-relevant because users or orchestrators may invoke it expecting only additive configuration changes, yet it can remove agents and disrupt availability.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_agents.py (reported line 88)May include surrounding context.

python
def check_plugin_installed() -> bool:
    """检查 @larksuite/openclaw-lark 是否已安装"""
    try:
        result = subprocess.run(
            ["openclaw", "plugins", "list", "--json"],
            capture_output=True, text=True, timeout=10
        )

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

When creating an agent, the code silently adds the new agent ID to tools.agentToAgent.allow, modifying global inter-agent communication permissions beyond simple Lark account setup. This broadens the agent's ability to interact with other agents and may enable lateral movement or privilege expansion if the new agent is misconfigured or compromised.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_agents.py (reported line 460)May include surrounding context.

python
cmd_remove(args.remove, dry_run=args.dry_run)
        if args.restart and not args.dry_run:
            print("\n🔄 重启 gateway...")
            subprocess.run(["openclaw", "gateway", "restart"], check=False)
        return

    if args.set_channel:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_agents.py (reported line 472)May include surrounding context.

python
cmd_remove(args.remove, dry_run=args.dry_run)
        if args.restart and not args.dry_run:
            print("\n🔄 重启 gateway...")
            subprocess.run(["openclaw", "gateway", "restart"], check=False)
        return

    if args.set_channel:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/setup_agents.py (reported line 535)May include surrounding context.

python
cmd_remove(args.remove, dry_run=args.dry_run)
        if args.restart and not args.dry_run:
            print("\n🔄 重启 gateway...")
            subprocess.run(["openclaw", "gateway", "restart"], check=False)
        return

    if args.set_channel:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file consistently presents activation phrases, workflow, and operational instructions only in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not done here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese and provides no indication that the skill supports other languages or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.