Back to skill

Security audit

create-ticket

Security checks for vulnerabilities and agentic risk

Overview

The skill is for creating private Discord support tickets, but it reports success before verifying that the private channel and permissions were actually created.

Review this before installing in a real Discord support flow. It should only be used where a trusted OpenClaw Discord adapter verifies channel creation and permission overwrites before any user is told the channel is private or asked to share sensitive support details.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
index.js:28
Finding

Unverified Private Channel Creation Success Response

Content
View full analysis

Vulnerability Details

File Location: index.js:28-36
Vulnerability Type: Unverified security-sensitive operation and spoofed success response
Risk Level: Medium

Vulnerable Code

js
return JSON.stringify({
  action: 'CREATE_PRIVATE_CHANNEL',
  payload: {
    name: channelName,
    allowUser: userId,
    topic: `Issue: ${issue} | Created by AI Support`
  },
  message: `Successfully created private channel #${channelName} for user ${username}.`
})

Technical Analysis

The handler does not directly call the Discord API, await channel creation, inspect an adapter response, or verify the resulting channel permissions. Instead, it returns a JSON instruction and simultaneously asserts that the private channel was successfully created.

This creates a discrepancy between the operation actually performed and the status communicated to the user. If the expected OpenClaw Discord adapter is unavailable, rejects the action, fails during permission assignment, or interprets the payload differently, the success message may still be relayed to the user.

The issue is security-sensitive because SKILL.md identifies the resulting channel as a location where users may provide transaction records, screenshots, and other sensitive information. A user may therefore rely on an unverified privacy guarantee.

Attack Path

  1. A user or agent invokes the handler with a username, userId, and issue description.
  2. The handler constructs a CREATE_PRIVATE_CHANNEL action but does not execute or verify it.
  3. The downstream adapter is absent, fails to create the channel, or fails to apply the intended access restrictions.
  4. The unconditional Successfully created private channel message is presented to the user.
  5. Believing that a verified private channel exists, the user may disclose transaction records, screenshots, account details, or other sensitive support information in an improperly protected c ...[truncated 571 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use an explicit, authenticated Discord API or trusted adapter method to create the channel.
  2. Await the channel-creation result before returning any success status.
  3. Verify that the created channel exists and that its permission overwrites deny general access while granting access only to the intended user and authorized support personnel.
  4. Return a structured pending or failure state if the adapter does not provide verifiable confirmation.
  5. Generate the user-facing success message only after channel creation and permission verification have both succeeded.
  6. Include the verified channel identifier in the result so downstream components can reference the actual resource rather than relying only on a generated name.
  7. Log adapter failures without exposing sensitive issue details or user data.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructions are written entirely in Chinese and do not indicate that language choice is optional or user-selected. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file uses Chinese for the skill description and operational comments, which imposes a specific language on users or maintainers without any opt-in or stated regional justification. This matches the language/locale policy category because no alternative language choice or locale scope is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.