Back to skill

Security audit

create-agent

Security checks for vulnerabilities and agentic risk

Overview

The skill’s agent-creation purpose is coherent, but it needs Review because it installs mutable remote skills, handles messaging credentials unsafely, and enables persistent memory/evolution behavior.

Install only if you are comfortable with an agent workspace that keeps long-term memory and learning logs, can bind to messaging providers, and may install additional skills. Use least-privilege bot credentials, avoid pasting secrets into chat, prefer secure secret storage, pin and verify any `npx` or remote skill installs, and review the generated workspace before enabling heartbeat or evolution features.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:240
Finding

Unpinned Third-Party Packages and Skills Are Downloaded and Executed

Content
View full analysis
Remediation
View remediation
add skill ... ``` 2. Pin each remote skill to an immutable release or commit hash rather than a mutable repository head. 3. Record and verify cryptographic hashes or signed provenance for every downloaded skill. 4. Use a committed lockfile and an approved internal registry or package mirror. 5. Download dependencies into a staging directory and inspect their scripts before execution. 6. Disable package lifecycle scripts during retrieval where supported, then explicitly execute only reviewed entry points. 7. Run installation in a sandbox with restricted filesystem and network access. 8. Grant installed skills only the minimum required workspace and tool permissions. 9. Treat the optional cross-agent sharing component as a separate trust decision and require explicit informed approval before installation. 10. Document the exact reviewed versions and establish a controlled dependency-update process. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
references/channel-params.md:39
Finding

Messaging Credentials Are Collected in Chat and Passed Through Command-Line Arguments

Content
View full analysis
--token ``` ```bash openclaw channels add --channel discord --account --token ``` Slack credentials are also supplied on the command line: ```bash openclaw channels add --channel slack --account \ --bot-token --app-token ``` Feishu credentials include multiple secrets: ```bash openclaw channels add --channel feishu --account \ --app-id \ --app-secret \ --verification-token \ --encrypt-key ``` Microsoft Teams exposes the bot password: ```bash openclaw channels add --channel msteams --account \ --bot-id \ --bot-password ``` Matrix exposes its access token: ```bash openclaw channels add --channel matrix --account \ --homeserver \ --access-token \ --user-id ``` LINE and Zalo similarly expose long-lived credentials: ```bash openclaw channels add --channel line --account \ --channel-token \ --channel-secret ``` ```bash openclaw channels add --channel zalo --account \ --app-id \ --secret-key \ --refresh-token ``` ### Technical Analysis The workflow asks users to provide bot tokens, ...[truncated 2666 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

代码的核心行为是“生成 workspace 模板文件”,这只覆盖了声明中的一部分。虽然生成了 SOUL.md、AGENTS.md、IDENTITY.md、USER.md、MEMORY.md、HEARTBEAT.md 等文件,并写入与 review/evolution 相关的静态说明和配置,但这些只是模板内容,不等于实际执行注册或进化。声明强调的是完整创建并注册 agent、内置自我进化、以及输出后续清单,而代码没有任何 openclaw agents add、openclaw message、node index.js --review 的执行逻辑,也没有问卷式收集步骤或后续清单生成。因此描述显著高于实际能力,存在明显描述-行为不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction that any request involving agent creation, initialization, or registration should trigger this skill is overly broad and can cause the skill to activate on ambiguous user prompts. In context, activation leads to file generation, registration commands, channel binding setup, and installation of additional components, so accidental triggering could initiate high-impact operational changes without sufficiently narrow intent confirmation.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/channel-params.md (reported line 271)May include surrounding context.

用户需提供的参数:

text
Homeserver URL(如 https://matrix.org):___________
Access Token:___________
User ID(如 @bot:matrix.org):___________
Account ID(账号别名,默认 default):___________(可留空)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/channel-params.md (reported line 297)May include surrounding context.

用户需提供的参数:

text
Homeserver URL(如 https://matrix.org):___________
Access Token:___________
User ID(如 @bot:matrix.org):___________
Account ID(账号别名,默认 default):___________(可留空)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/channel-params.md (reported line 350)May include surrounding context.

用户需提供的参数:

text
Homeserver URL(如 https://matrix.org):___________
Access Token:___________
User ID(如 @bot:matrix.org):___________
Account ID(账号别名,默认 default):___________(可留空)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate-workspace.sh (reported line 347)May include surrounding context.

sh
<!-- 条目将自动追加在此处 -->
"

# ─── 生成 .env ────────────────────────────────────────────────────────────────

write_file "$WORKSPACE/.env" "# capability-evolver 配置
EVOLVE_STRATEGY=balanced

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate-workspace.sh (reported line 349)May include surrounding context.

sh
# ─── 生成 .env ────────────────────────────────────────────────────────────────

write_file "$WORKSPACE/.env" "# capability-evolver 配置
EVOLVE_STRATEGY=balanced
EVOLVE_REVIEW_MODE=true

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description advertises creation, registration, and evolution capabilities but does not upfront warn that it may generate files, install skills, query configured channels, and run CLI commands that modify the user's environment. This increases the chance that users invoke the skill without understanding the side effects, which is especially risky in a security-sensitive setup workflow.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The skill is designed to create persistent agent workspaces, memory files, heartbeat logic, and follow-on self-evolution behavior, which establishes durable state across sessions. In context this persistence is not inherently malicious, but it becomes risky because it is broadly triggered and paired with logging/reuse of conversation content and automated installation/registration steps, magnifying accidental or unauthorized long-term data and configuration changes.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
workspace 文件(SOUL.md/AGENTS.md/IDENTITY.md/USER.md/MEMORY.md/HEARTBEAT.md)、
  执行 `openclaw agents add` CLI 注册、内置 capability-evolver 自我进化(--review 模式)、
  以及向用户输出完整的后续操作清单。
  触发词:创建 agent、新建 agent、帮我建一个 agent、create agent、new agent、add agent、
  setup agent、我想要一个新的 agent、初始化 agent。
  任何涉及 OpenClaw agent 创建、初始化、注册的请求都应触发此 skill。
tags: [openclaw, agent, setup, workspace, evolution]

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Several trigger phrases such as create agent, new agent, add agent, and setup agent are common conversational phrases and may match benign discussion rather than an actionable request. Because this skill's workflow culminates in persistent workspace creation, CLI registration, and optional channel/plugin installation, false activation can have real operational and privacy consequences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructions and user-facing questionnaire are written as if the interaction will occur in Chinese, with no indication that the user may choose another language. This can violate language or locale policy when a skill imposes a language preference without explicit opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs persistent collection of every session's conversation content into memory and learning logs for later processing by other skills. This creates a data retention and cross-component exposure risk: sensitive user content may be stored indefinitely, reused outside the original interaction context, and consumed by other automation layers, increasing the impact of leakage or misuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs use of npx playbooks add skill ... without pinning an exact package/version, which allows whatever version is currently resolved from the registry to run at install time. In a security-sensitive automation flow, this creates a supply-chain risk: a compromised upstream release, typosquatting, or unexpected breaking update could execute attacker-controlled code or alter the installed skill behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This is a second unpinned npx playbooks invocation in the same workflow, again causing execution of remote code resolved at runtime without a fixed version. Because the command is part of an agent bootstrap path, it expands the attack surface and makes the resulting environment non-reproducible and susceptible to supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The post-install guidance again tells users to run npx playbooks without version pinning, propagating the same supply-chain risk beyond the automated phase into manual follow-up steps. Repeated unpinned commands increase the likelihood that users will execute unreviewed code later under the assumption it is part of a trusted workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This additional unpinned npx playbooks command extends the same remote-code-execution-by-install pattern to optional ecosystem integration. Even though optional, users may treat it as recommended and execute code from an unpinned upstream source, which is dangerous in a skill explicitly handling persistent agent setup and evolution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document repeatedly instructs users to paste bot tokens, app secrets, passwords, and other credentials directly into questionnaires and shell commands, but never warns about leakage through terminal history, logs, screenshots, or chat transcripts. In an agent-creation skill context, this is more dangerous because the workflow likely centralizes collection of many third-party secrets, increasing the chance they are exposed or retained insecurely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/channel-params.md (reported line 111)May include surrounding context.

text

**获取 Token 方法:**
1. 访问 https://api.slack.com/apps → Create New App
2. 开启 Socket Mode,生成 App Token(xapp-)
3. OAuth & Permissions → Bot Token(xoxb-)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Allowing users to provide raw Google Service Account JSON content is risky because those files often contain private keys that grant broad API access and are highly sensitive. In this skill context, encouraging direct submission of JSON content to an automated workflow materially raises the chance of credential exfiltration, accidental logging, or long-term retention in transcripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template instructs the agent to automatically persist session information into dated memory files and distilled summaries without clearly warning users that their data will be retained. This creates a privacy and data-governance risk because sensitive user content may be stored long-term by default without informed consent, minimization rules, or retention controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template embeds a persistent self-evolution workflow with heartbeat-triggered review logic, learning promotion, and runtime-history analysis that goes beyond one-time agent creation. Even though it says changes require approval, it normalizes ongoing autonomous behavior and future capability modification, which expands attack surface and can lead to unsafe or unintended actions if later components mis-handle approvals or are subverted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user profile template directs the agent to fill in user preferences and observational notes over time, but it does not disclose that personal information and inferred traits may be recorded. This is dangerous because it encourages silent profiling and long-term storage of user-related data without consent, transparency, or limits on sensitivity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script writes natural-language policy into USER.md that sets communication language to Chinese by default: '中文(除非用户使用英文)'. That imposes a specific language preference without offering a neutral choice or requiring explicit user consent, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest focuses on creating and registering a new agent, but the AGENTS.md template instructs the agent to inspect bindings and communicate with other agents via CLI. That introduces multi-agent operational behavior into the generated workspace, which is broader than straightforward initialization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The communication preference line sets the language to Chinese by default, only switching if the user uses English. This imposes a locale/language policy without first offering the user a choice or documenting an explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.