Back to skill

Security audit

openclaw-code-review-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate code-review skill, but it should be reviewed carefully because it feeds untrusted PR and repository content to spawned agents and can use authenticated GitHub commands, including posting comments.

Before installing, make sure you are comfortable letting the skill use your logged-in GitHub CLI to read PR metadata, diffs, repository CLAUDE.md files, and git history. Review generated findings locally before using --comment or asking it to publish, especially on private repositories or untrusted PRs where PR text or code comments could try to influence the reviewing agents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:48
Finding

Untrusted Pull Request and Repository Content Can Hijack Review Agents

Content
View full analysis
/dev/null # 子目录(与变更文件同目录的) # 用变更文件路径推断需要的 CLAUDE.md ``` **C. 获取变更文件列表** ```bash gh pr diff ``` ``` It then places pull request metadata, repository instructions, and changed files into privileged sub-agent contexts: ```markdown 使用 `sessions_spawn` 工具并行启动 3 个独立审查 Agent: #### Agent 1:CLAUDE.md 合规检查(Sonnet) **Prompt:** ``` 你是代码审查专家,负责检查此 PR 是否违反了项目 CLAUDE.md 中的规范。 背景: - PR 标题: - PR 描述:<description> - 项目规范在 CLAUDE.md 中列出 任务: 1. 阅读 PR 变更的文件内容和 CLAUDE.md 规范 2. 检查变更是否违反了 CLAUDE.md 中的任何明确规则 3. 只标记**明确违反**的规则(你能引用 CLAUDE.md 中的具体文字) ``` ``` The same untrusted metadata is also interpolated into the bug and history-analysis prompts: ```markdown 背景: - PR 标题:<title> - PR 描述:<description> 任务: 只检查 Diff 本身,不要引入 Diff 之外的上下文。 ``` ```markdown 背景: - PR 标题:<title> - PR 描述:<description> - 变更的文件:<files> 任务: 1. 对变更的关键文件运行 `git blame` 和 `git log` ``` ### Technical Analysis Pull request titles, descriptions, changed files, diffs, and repository-controlled `CLAUDE.md` files are untrusted inputs. A pull request author or repository contributor can place natural-language instructions in any of these sources. The Skill directly incorporates that content into prompts passed to spawned review agents. It does not establish a trust boundary stating that repository content is evidence to analyze rather than instructions to execute. This is particularly significant for `CLAUDE.md`, because the workflow expressly tells an agent to treat its contents as project rules. An attacker can therefore insert prompt-injection text that attempts to: - Overr ...[truncated 2328 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes a --comment mode that publishes review output directly to GitHub PR comments, but it does not clearly warn that this sends content to an external service and may disclose sensitive analysis, internal code details, or security findings. In a code-review skill, review output can easily contain proprietary information or vulnerability details, so the lack of an explicit disclosure warning increases the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README presents activation via phrases like "帮我 review 这个 PR" and "帮我 review 以下 Diff", but does not clearly constrain whether the skill should activate only on explicit /code-review commands or on general conversational requests. Because these are common help-style phrases, they can cause unintended invocation ambiguity in chat contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad natural-language trigger phrases can cause the skill to activate on ordinary conversation that merely mentions code review. In an agent environment, accidental activation increases the chance of running repository or GitHub CLI commands without the user intending to invoke this higher-privilege workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill says to ask before acting when information is insufficient, yet it instructs the agent to automatically query the user's open PRs. That can trigger unintended access to repository metadata and enumerate user activity without an explicit request for that specific PR, which is a scope-expansion/privacy issue in an agent setting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest and intro say the skill reviews 'Pull Request or code Diff', which implies both inputs are first-class supported review targets. However, the documented collection workflow is centered on gh pr view, gh api, and gh pr diff, and step 2 requires PR details, repository CLAUDE.md lookup, and changed-file retrieval via GitHub CLI. That behavior is broader and more GitHub/PR-dependent than the stated generic 'diff review' capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command table includes an everyday-language trigger ('帮我 review 这个 diff') without strict boundaries, which can be matched in routine discussion. That makes unintended invocation more likely and can lead to unnecessary code/data processing or external tool use before the user has explicitly consented to the full review workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Most user-facing instructions, examples, and prompts in the README are presented only in Chinese, which effectively imposes a language requirement on users without opt-in or justification. The policy allows locale constraints when explicitly documented and justified, but that is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents the --comment option as posting the review to the pull request, but it does not include any caution that the generated review content will be sent to GitHub and become visible according to the repository's access settings. Because markdown files should warn about behaviors affecting user data or system integrity, this remote publication behavior merits a user-facing warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.