Back to skill

Security audit

clawgo-clone

Security checks for vulnerabilities and agentic risk

Overview

This skill openly performs ClawGo workspace restore, but it can replace persistent agent instruction files from an unauthenticated remote zip with weak staging and validation controls.

Install only if you trust the ClawGo service and the specific key provider. Before applying a restore, inspect the zip contents and diffs, avoid keys from untrusted people, and understand that restored files can change how future OpenClaw sessions behave. Prefer a version that uses private temporary directories, validates zip members before extraction, verifies signed manifests or hashes, and asks for per-file approval before replacing workspace instruction files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:20
Finding

Remote replacement of agent instructions, identity, and behavioral guardrails

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Untrusted ZIP archive is extracted before member-path and resource validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:27
Finding

Predictable shared temporary paths permit staging tampering and backup exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest includes the trigger phrase "restore my workspace notes," which is broad natural language that could match ordinary requests unrelated to this specific ClawGo key-based sync workflow. Although other examples are specific, this phrase lacks a clear constraint tying invocation to the ClawGo service or 12-character key requirement.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill sends user-supplied data to an external service and then later downloads remote content intended to overwrite local workspace files, which can materially change agent behavior. In this context, the external transmission is security-relevant because the downloaded Markdown populates trusted workspace files like SOUL.md and AGENTS.md, creating a supply-chain style risk if the remote service or key content is malicious.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Step 1 — Check key readiness

bash
curl -s https://clawgo.me/api/clones/{key}/availability
  • available: true and status: ready → continue

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description understates the skill's actual behavior by claiming it only backs up and restores core OpenClaw configuration files, while the broader skill description indicates downloading a remote zip and copying its contents into the local workspace. This mismatch can mislead users and reviewers about the scope of file access and modification, weakening informed consent and increasing the chance of unintended data overwrite or supply-chain style abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.