T01 · Skill Instruction Hijacking
- Location
SKILL.md:76- Finding
Mandatory Creator Branding Hijacks Agent Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real OpenClaw configuration wizard, but it asks for broad authority to change configuration, install third-party code, handle channel secrets, and weaken command approvals in ways users should review first.
Install only if you are comfortable with a configuration wizard that can edit OpenClaw files, restart the gateway, install other skills, and handle bot credentials. Review every command before execution, avoid pasting long-lived tokens into chat, keep backups protected, disable or narrow the broad exec allowlist, and skip remote repository installs or source-code patches unless you have verified the exact source and rollback path.
SKILL.md:76Mandatory Creator Branding Hijacks Agent Output
references/layer3-skills.md:13Mutable Remote Installation Instructions Are Executed Without Integrity Verification
references/layer1-base.md:281Command Approval Policy Auto-Allows Powerful Interpreters and Package Managers
references/layer2-channels.md:136Skill Replaces Installed Feishu Plugin Source Code Without Version or Integrity Checks
references/layer4-onboarding.md:12Channel Credentials Are Collected Through the Conversational Interface
references/layer1-base.md:136Complete Target URLs Are Relayed to Third-Party Extraction Services
Referenced artifact was not completely inspected
- `references/layer2-channels.md`:第 2 轮渠道增强
Referenced artifact was not completely inspected
- `references/layer2-channels.md`:第 2 轮渠道增强
Potential security issue detected. Manual review is recommended.
whoami id for c in sudo docker apt-get curl jq python3; do command -v "$c" >/dev/null 2>&1 && echo "$c=ok" || echo "$c=missing"; done test -S /var/run/docker.sock && ls -l /var/run/docker.sock || echo "docker_sock=missing"
输出口径:
The README says users can retrieve necessary Discord/Telegram/Feishu information and 'send it back' for automatic writing and validation, but it does not warn that these details may include sensitive integration secrets such as bot tokens, app credentials, or webhook data. In a conversational skill, encouraging users to paste credentials without privacy and handling guidance increases the risk of secret exposure, insecure storage, or accidental logging.
The README instructs users to install the skill, answer prompts, and then 'confirm write and restart Gateway' without a prominent warning at the point of use that the skill will modify configuration and restart a service. In an agent skill context, that omission is dangerous because users may treat the flow as low-risk guidance rather than authorizing system-changing actions that can alter availability, connectivity, or security posture.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
whoami
id
for c in sudo docker apt-get curl jq python3; do command -v "$c" >/dev/null 2>&1 && echo "$c=ok" || echo "$c=missing"; done
test -S /var/run/docker.sock && ls -l /var/run/docker.sock || echo "docker_sock=missing"
The skill instructs the agent to read a Discord token from configuration as part of automatic server ID discovery, but this file provides no user-facing disclosure or consent boundary for accessing stored secrets. Even if the token is used only for API calls, silently retrieving credentials increases the chance of unnecessary secret access, accidental leakage into logs, prompts, or downstream tools.
The document explicitly says the skill can directly execute installations when the user names a skill and presents a one-click skip/install flow, but it does not pair that with a clear warning that these actions may modify local files, install software, or change agent behavior. In a configuration wizard skill, users may treat recommendations as safe defaults and authorize changes without understanding the system impact, increasing the risk of unintended configuration drift or unsafe package installation.
The workflow includes backup/restore and a later execution phase, which implies file writes and configuration mutation, but the overview does not clearly warn users that these steps may alter or overwrite OpenClaw configuration and related workspace state. In an initialization/optimization assistant, this omission can cause users to approve changes without understanding rollback limits, persistence effects, or the scope of modified paths.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"
The skill defines an overly broad post-run trigger list that changes future handling for common messages like 'hi', 'test', and '现在如何了'. This can unexpectedly suppress normal execution paths or security-relevant follow-up actions after the workflow ends, creating an ambiguous state machine that an attacker or accidental user input could exploit to prevent remediation or silently alter behavior.
The entire skill specification is written as fixed Chinese-language instructions and output requirements, with no indication that the user may choose another language. This creates a natural-language locale policy concern because it implicitly constrains the interaction language without documented opt-in or justification.
The file title and all operational instructions are written exclusively in Chinese, indicating the skill content is effectively constrained to a specific language. The document does not state that language choice is optional or user-selected, which matches the policy concern for forced language/locale without opt-in.
The backup command produces a durable zip archive of the entire OpenClaw state under ~/openclaw-backups, a user-accessible and guessable directory. In the context of an agent configuration skill, this makes the issue more dangerous because the archived contents likely include long-lived session artifacts, agent memory, configs, and possibly secrets that persist beyond the original environment.
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"
The backup command produces a durable zip archive of the entire OpenClaw state under ~/openclaw-backups, a user-accessible and guessable directory. In the context of an agent configuration skill, this makes the issue more dangerous because the archived contents likely include long-lived session artifacts, agent memory, configs, and possibly secrets that persist beyond the original environment.
BACKUP_DIR="$HOME/openclaw-backups"
mkdir -p "$BACKUP_DIR" 2>/dev/null || BACKUP_DIR="$HOME/.openclaw/backups"
mkdir -p "$BACKUP_DIR"
cd ~ && zip -r "$BACKUP_DIR/backup-openclaw-all-$(date +%Y%m%d-%H%M%S).zip" .openclaw/ -x ".openclaw/backups/*"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- `coding` 权限通常已经足够,是当前这套 skill 的原生体验,强烈建议保持。
- 能读写配置、执行常规命令、完成大部分自动化修改。
- 若要启用审批,建议保持 `coding`,并在第 2 轮再叠加“exec 高危操作审批”。
- 重要:仅保留 `coding` 不代表“删除文件 / sudo 一定会触发审批”。OpenClaw 新版里,`tools.profile` 只决定工具集合,不直接等于 exec 审批策略。
- 若要验证审批,优先测试 `exec` 审批路径:确保 `exec-approvals.json` 已启用 `security=allowlist + ask=on-miss`,并执行一个“不在 allowlist 中”的命令来触发审批;不要把“rm 没弹审批”直接理解成 Telegram / Discord 审批联动失效。
- 默认不额外改动用户现有权限配置;若探测到已是 `coding`,可直接维持。
The title and the entire instructional content are written in Chinese, and the file does not indicate that language selection is optional or limited to a China-specific deployment context. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.
The manifest describes this skill as an OpenClaw configuration optimization wizard focused on initialization, base recommendations, channel-specific enhancement, skills recommendations, and new channel onboarding. This section of the file directs users to configure cross-channel exec approval policy, command allowlists, and execution security modes, which materially extends beyond channel enhancement and into broader execution-control hardening.
The manifest presents the skill as a configuration wizard for OpenClaw initialization and optimization, but this section tells the operator to edit a TypeScript source file under an extensions path and replace it with implementation code. Altering extension source code is a behavioral scope expansion beyond configuration guidance and changes program logic, not just configuration.
This file presents all operational instructions and user-facing trigger/installation guidance exclusively in Chinese. That can violate a language/locale policy when the skill does not offer the user a choice of language or document that the skill is intentionally region-specific.
The skill directs the agent to deploy a nightly system-level Cron job and enforce security-rule changes as part of a configuration wizard, which goes beyond ordinary OpenClaw optimization and crosses into persistent host modification. In this context, that creates unnecessary authority expansion and persistence on the user's machine, increasing the blast radius if the guidance is wrong, overbroad, or abused.
The layer recommends installing domain-specific medical skills that are unrelated to the stated purpose of initializing or optimizing OpenClaw. While not inherently malicious, this broadens the system's capabilities into sensitive biomedical workflows and may introduce extra code, dependencies, and data-access paths without a purpose tied to the user's original configuration task.
The skill instructs users to send a Discord bot token to the AI and then has the AI write that secret into local configuration, but it does not clearly warn that the token is a high-value credential, should only be shared through a private channel, and will be stored locally. If exposed in chat history, logs, or summaries, an attacker could take over the bot, impersonate it, or abuse the connected Discord application.
The Telegram flow asks the user to return the Bot Token and proceeds with configuration and pairing, but it omits an explicit warning that the token is a sensitive credential and should only be provided through a private channel. This increases the chance of credential leakage through conversation history or accidental posting, which could allow unauthorized control of the Telegram bot.
No suspicious patterns detected.