Back to skill

Security audit

easy-openclaw

Security checks for vulnerabilities and agentic risk

Overview

This is a real OpenClaw configuration wizard, but it asks for broad authority to change configuration, install third-party code, handle channel secrets, and weaken command approvals in ways users should review first.

Install only if you are comfortable with a configuration wizard that can edit OpenClaw files, restart the gateway, install other skills, and handle bot credentials. Review every command before execution, avoid pasting long-lived tokens into chat, keep backups protected, disable or narrow the broad exec allowlist, and skip remote repository installs or source-code patches unless you have verified the exact source and rollback path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:76
Finding

Mandatory Creator Branding Hijacks Agent Output

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/layer3-skills.md:13
Finding

Mutable Remote Installation Instructions Are Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/layer1-base.md:281
Finding

Command Approval Policy Auto-Allows Powerful Interpreters and Package Managers

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
references/layer2-channels.md:136
Finding

Skill Replaces Installed Feishu Plugin Source Code Without Version or Integrity Checks

Content
View full analysis
(); function getCacheKey(cfg?: FeishuConfig): string { if (!cfg?.appId) return "no-creds"; return `${cfg.appId}:${cfg.domain ?? "feishu"}`; } export async function probeFeishu(cfg?: FeishuConfig): Promise { const creds = resolveFeishuCredentials(cfg); if (!creds) { return { ok: false, error: "missing credentials (appId, appSecret)", }; } const cacheKey = getCacheKey(cfg); const cached = probeCache.get(cacheKey); if (cached && Date.now() - cached.timestamp < PROBE_CACHE_TTL_MS) { return cached.result; } try { const client = createFeishuClient(cfg!); const response = await (client as any).request({ method: "GET", url: "/open-apis/bot/v3/info", data: {}, }); if (response.code !== 0) { const result = { ok: false, appId: creds.appId, error: `API error: ${response.msg || `code ${response.code}`}`, }; probeCache.set(cacheKey, { result, timestamp: Date.now() }); return result; } const bot = response.bot || response.data?.bot; const result = { ok: true, appId: creds.appId, botName: bot?.bot_name, botOpenId: bot?.open_id, }; probeCache.set(cacheKey, { result, timestamp: Date.now() }); return result; } catch (err) { const result = { ok: false, appId: creds.appId, error: err instanceof Error ? err.message : String(err), }; probeCache.set(cacheKey ...[truncated 2126 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/layer4-onboarding.md:12
Finding

Channel Credentials Are Collected Through the Conversational Interface

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/layer1-base.md:136
Finding

Complete Target URLs Are Relayed to Third-Party Extraction Services

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (29)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
- `references/layer2-channels.md`:第 2 轮渠道增强

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
- `references/layer2-channels.md`:第 2 轮渠道增强

Docker Socket Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

whoami id for c in sudo docker apt-get curl jq python3; do command -v "$c" >/dev/null 2>&1 && echo "$c=ok" || echo "$c=missing"; done test -S /var/run/docker.sock && ls -l /var/run/docker.sock || echo "docker_sock=missing"

text

输出口径:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says users can retrieve necessary Discord/Telegram/Feishu information and 'send it back' for automatic writing and validation, but it does not warn that these details may include sensitive integration secrets such as bot tokens, app credentials, or webhook data. In a conversational skill, encouraging users to paste credentials without privacy and handling guidance increases the risk of secret exposure, insecure storage, or accidental logging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to install the skill, answer prompts, and then 'confirm write and restart Gateway' without a prominent warning at the point of use that the skill will modify configuration and restart a service. In an agent skill context, that omission is dangerous because users may treat the flow as low-risk guidance rather than authorizing system-changing actions that can alter availability, connectivity, or security posture.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

bash
whoami
id
for c in sudo docker apt-get curl jq python3; do command -v "$c" >/dev/null 2>&1 && echo "$c=ok" || echo "$c=missing"; done
test -S /var/run/docker.sock && ls -l /var/run/docker.sock || echo "docker_sock=missing"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to read a Discord token from configuration as part of automatic server ID discovery, but this file provides no user-facing disclosure or consent boundary for accessing stored secrets. Even if the token is used only for API calls, silently retrieving credentials increases the chance of unnecessary secret access, accidental leakage into logs, prompts, or downstream tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document explicitly says the skill can directly execute installations when the user names a skill and presents a one-click skip/install flow, but it does not pair that with a clear warning that these actions may modify local files, install software, or change agent behavior. In a configuration wizard skill, users may treat recommendations as safe defaults and authorize changes without understanding the system impact, increasing the risk of unintended configuration drift or unsafe package installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The workflow includes backup/restore and a later execution phase, which implies file writes and configuration mutation, but the overview does not clearly warn users that these steps may alter or overwrite OpenClaw configuration and related workspace state. In an initialization/optimization assistant, this omission can cause users to approve changes without understanding rollback limits, persistence effects, or the scope of modified paths.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/execution.md (reported line 47)May include surrounding context.

bash
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/execution.md (reported line 47)May include surrounding context.

bash
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill defines an overly broad post-run trigger list that changes future handling for common messages like 'hi', 'test', and '现在如何了'. This can unexpectedly suppress normal execution paths or security-relevant follow-up actions after the workflow ends, creating an ambiguous state machine that an attacker or accidental user input could exploit to prevent remediation or silently alter behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill specification is written as fixed Chinese-language instructions and output requirements, with no indication that the user may choose another language. This creates a natural-language locale policy concern because it implicitly constrains the interaction language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file title and all operational instructions are written exclusively in Chinese, indicating the skill content is effectively constrained to a specific language. The document does not state that language choice is optional or user-selected, which matches the policy concern for forced language/locale without opt-in.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The backup command produces a durable zip archive of the entire OpenClaw state under ~/openclaw-backups, a user-accessible and guessable directory. In the context of an agent configuration skill, this makes the issue more dangerous because the archived contents likely include long-lived session artifacts, agent memory, configs, and possibly secrets that persist beyond the original environment.

Content

Scanner excerpt · references/layer1-base.md (reported line 15)May include surrounding context.

bash
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The backup command produces a durable zip archive of the entire OpenClaw state under ~/openclaw-backups, a user-accessible and guessable directory. In the context of an agent configuration skill, this makes the issue more dangerous because the archived contents likely include long-lived session artifacts, agent memory, configs, and possibly secrets that persist beyond the original environment.

Content

Scanner excerpt · references/layer1-base.md (reported line 15)May include surrounding context.

bash
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/layer1-base.md (reported line 222)May include surrounding context.

md
- `coding` 权限通常已经足够,是当前这套 skill 的原生体验,强烈建议保持。
- 能读写配置、执行常规命令、完成大部分自动化修改。
- 若要启用审批,建议保持 `coding`,并在第 2 轮再叠加“exec 高危操作审批”。
- 重要:仅保留 `coding` 不代表“删除文件 / sudo 一定会触发审批”。OpenClaw 新版里,`tools.profile` 只决定工具集合,不直接等于 exec 审批策略。
- 若要验证审批,优先测试 `exec` 审批路径:确保 `exec-approvals.json` 已启用 `security=allowlist + ask=on-miss`,并执行一个“不在 allowlist 中”的命令来触发审批;不要把“rm 没弹审批”直接理解成 Telegram / Discord 审批联动失效。
- 默认不额外改动用户现有权限配置;若探测到已是 `coding`,可直接维持。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The title and the entire instructional content are written in Chinese, and the file does not indicate that language selection is optional or limited to a China-specific deployment context. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes this skill as an OpenClaw configuration optimization wizard focused on initialization, base recommendations, channel-specific enhancement, skills recommendations, and new channel onboarding. This section of the file directs users to configure cross-channel exec approval policy, command allowlists, and execution security modes, which materially extends beyond channel enhancement and into broader execution-control hardening.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest presents the skill as a configuration wizard for OpenClaw initialization and optimization, but this section tells the operator to edit a TypeScript source file under an extensions path and replace it with implementation code. Altering extension source code is a behavioral scope expansion beyond configuration guidance and changes program logic, not just configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file presents all operational instructions and user-facing trigger/installation guidance exclusively in Chinese. That can violate a language/locale policy when the skill does not offer the user a choice of language or document that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to deploy a nightly system-level Cron job and enforce security-rule changes as part of a configuration wizard, which goes beyond ordinary OpenClaw optimization and crosses into persistent host modification. In this context, that creates unnecessary authority expansion and persistence on the user's machine, increasing the blast radius if the guidance is wrong, overbroad, or abused.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The layer recommends installing domain-specific medical skills that are unrelated to the stated purpose of initializing or optimizing OpenClaw. While not inherently malicious, this broadens the system's capabilities into sensitive biomedical workflows and may introduce extra code, dependencies, and data-access paths without a purpose tied to the user's original configuration task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to send a Discord bot token to the AI and then has the AI write that secret into local configuration, but it does not clearly warn that the token is a high-value credential, should only be shared through a private channel, and will be stored locally. If exposed in chat history, logs, or summaries, an attacker could take over the bot, impersonate it, or abuse the connected Discord application.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Telegram flow asks the user to return the Bot Token and proceeds with configuration and pairing, but it omits an explicit warning that the token is a sensitive credential and should only be provided through a private channel. This increases the chance of credential leakage through conversation history or accidental posting, which could allow unauthorized control of the Telegram bot.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.