Back to skill

Security audit

OpenClaw Dashboard Theme Changer

Security checks for vulnerabilities and agentic risk

Overview

This skill changes the dashboard color as advertised, but it edits installed OpenClaw CSS and JavaScript bundles in place without backups or confirmation.

Install only if you are comfortable with a skill that directly rewrites OpenClaw's installed dashboard assets. Before using it, make a backup or be prepared to reinstall/update OpenClaw to recover, and run it only for explicit dashboard theme changes with a reviewed color value.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
change-theme.sh:133
Finding

Heuristic Global Replacement Can Corrupt Unrelated JavaScript Colors

Content
View full analysis
=2 occurrences as the main accent) # The "danger" color (#ef4444 equivalent) should NOT be changed # Find colors that are likely the old accent (appear >= 2 times, not in standard palette) STANDARD_COLORS="007bff|00e5cc|050810|6366f1|f59e0b|dfb82b|22c55e|3b82f6|14b8a6|eab308" # Get the current accent color from CSS (we just set it, but check what was there) # We replace any color that is clearly an accent (not standard palette, appears >=2) OLD_ACCENT=$(echo "$JSCOLORS" | grep -vE "^\\s*[0-9]+\\s#($STANDARD_COLORS)$" | awk '{print $2}' | head -3) if [[ -n "$OLD_ACCENT" ]]; then echo " Replacing old accent color(s) in JS: $OLD_ACCENT" for old in $OLD_ACCENT; do # Skip if it looks like it could be the new color (idempotent check) if [[ "$old" != "$COLOR" ]]; then sed -i "s/${old}/${COLOR}/g" "$JS" echo " Replaced $old -> $COLOR" fi done else echo " No old accent color found to replace (may already be set)" fi ``` ### Technical Analysis The script infers the previous accent color by ranking every six-digit hexadecimal color in the JavaScript bundle, excluding a small hard-coded list, and selecting up to three remaining values. It then globally replaces ...[truncated 2710 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
change-theme.sh:177
Finding

Malformed Verification Check Falsely Reports Successful Removal of Old Accent Colors

Content
View full analysis
/dev/null; then echo " ⚠️ Old red accent values still found in CSS" else echo " ✅ No old red accent values in CSS" fi ``` ### Technical Analysis The verification expression is malformed in two independent ways: 1. The pattern expects `--accent:--`, while a valid CSS declaration would use a value such as `--accent:#ef4444`. 2. The pattern begins with `--` but is passed to `grep` without the `--` end-of-options delimiter or an explicit `-e`. Depending on the implementation, `grep` can interpret the pattern as an invalid long option. Standard error is redirected to `/dev/null`. Any `grep` error therefore produces a nonzero status that is handled by the `else` branch, which prints a success message. The check can consequently report that no old accent values remain even when the command failed or the values are still present. This is a fail-open verification weakness. It does not itself alter privileges or execute attacker-controlled commands, but it conceals incomplete or incorrect asset changes and compounds the risks of the preceding in-place modifications. ### Attack Path 1. A user runs the theme-changing script. 2. One or more old red accent values remain in the CSS because a declaration does not match the replacement expressions or because the update is otherwise incomplete. 3. The verification command executes with the malformed pattern. 4. `grep` either fails due to option parsing or searches for a CSS sequence that does not occur. 5. Error output is discarded. 6. The script enters the `else` branch and prints a successful verification message. 7. The user is ...[truncated 593 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README says the skill dynamically locates CSS/JS assets and updates bundles, but it does not prominently warn that this edits files inside the installed OpenClaw application rather than user-only configuration. That missing warning reduces informed consent and can lead users to run a skill that mutates application code/assets, affecting integrity and complicating upgrades or troubleshooting.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

OpenClaw loads skills automatically from:

text
~/.openclaw/workspace/skills/dashboard-theme/SKILL.md

Or via ClawHub:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 128)May include surrounding context.

OpenClaw loads skills automatically from:

text
~/.openclaw/workspace/skills/dashboard-theme/SKILL.md

Or via ClawHub:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises a very broad natural-language trigger in Chinese ('换成黄色'), which can overlap with ordinary conversation and increase the chance of accidental activation. In the context of a skill that modifies installed application assets, unintended execution can cause unauthorized local file changes even if the underlying function is not overtly malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are broad, natural-language expressions like changing dashboard color, which could cause the skill to activate unintentionally during ordinary conversation. Because the skill performs filesystem modifications to application assets, accidental invocation can lead to unauthorized or surprising changes to the installed dashboard theme.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs execution of a script that searches for and rewrites CSS and JS files in the OpenClaw installation, but the user-facing description does not prominently disclose that installed application files will be edited on disk. This creates risk of unsafe modification, persistence across sessions, and damage to application integrity if invoked unexpectedly or used on the wrong path/version.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script directly edits installed OpenClaw CSS and JS bundles in place using multiple sed -i replacements, with no backup, dry-run mode, or confirmation prompt. This can irreversibly corrupt application assets or introduce broad unintended changes if the regexes match the wrong content, and the risk is elevated because the JS replacement heuristics modify multiple discovered colors in a minified bundle.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language instructions, trigger conditions, and examples are presented solely in Chinese, which can amount to an implicit language policy constraint if the skill expects those phrases for invocation. There is no indication that other languages are supported or that Chinese-only use is a documented, justified requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.