Back to skill

Security audit

clawsec-suite

Security checks for vulnerabilities and agentic risk

Overview

This security suite is mostly purpose-aligned, but some auxiliary workflows can trust mutable or unsigned remote data that could steer security decisions or installs.

Review before installing. Prefer the manual verified install path or a pinned clawhub version, keep CLAWSEC_ALLOW_UNSIGNED_FEED disabled, avoid custom feed/catalog URLs unless you control and verify them, and only enable the persistent hook or cron if you want ongoing security automation in your OpenClaw main session.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
HEARTBEAT.md:102
Finding

Unsigned advisory feed content can inject operational guidance into the heartbeat workflow

Content
View full analysis
/dev/null 2>&1; then echo "ERROR: Advisory feed has invalid format." exit 1 fi ``` Remote fields are subsequently emitted as operational guidance: ```bash if [ -s "$NEW_IDS_FILE" ]; then echo "New advisories:" while IFS= read -r id; do [ -z "$id" ] && continue jq -r --arg id "$id" '.advisories[] | select(.id == $id) | "- [\(.severity | ascii_upcase)] \(.id): \(.title)"' "$FEED_TMP" jq -r --arg id "$id" '.advisories[] | select(.id == $id) | " Exploitability: \(.exploitability_score // "unknown" | ascii_upcase)"' "$FEED_TMP" jq -r --arg id "$id" '.advisories[] | select(.id == $id) | " Action: \(.action // "Review advisory details")"' "$FEED_TMP" done < "$NEW_IDS_FILE" else echo "FEED_OK - no new advisories" fi echo "Affected installed skills (if any):" found_affected=0 removal_recommended=0 for skill_path in "$INSTALL_ROOT"/*; do [ -d "$skill_path" ] || continue skill_name="$(basename "$skill_path")" skill_hits="$(jq -r --arg skill_prefix "${skill_name}@" ' [.advisories[] | select(any(.affected[]?; startswith( ...[truncated 2519 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/guarded_skill_install.mjs:216
Finding

Guarded installation executes an unpinned mutable npx dependency

Content
View full analysis
``` ### Technical Analysis The guarded installer invokes `npx clawhub@latest`, which can download and execute the package version currently associated with the mutable `latest` registry tag. The effective installer code can therefore change after this Skill has been audited. The child process invocation safely uses an argument array rather than shell interpolation, and the Skill name is restricted to lowercase letters, digits, and hyphens. These controls reduce command-injection risk but do not address supply-chain compromise of the `clawhub` package itself. Because `npx` executes package code with the current user’s authority, a compromised maintainer account, malicious registry release, or hijacked dependency in a future `latest` version could execute arbitrary code. ### Attack Path 1. An attacker compromises the `clawhub` package, its maintainer account, publication workflow, or one of its runtime dependencies. 2. A malicious release is assigned to the `latest` distribution tag. 3. A user or Agent runs the guarded installer or follows the documented `npx clawhub@latest` command. 4. `npx` r ...[truncated 729 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/discover_skill_catalog.mjs:187
Finding

Unsigned and unrestricted remote catalog can steer users toward attacker-selected packages

Content
View full analysis
controller.abort(), timeoutMs); try { const response = await globalThis.fetch(indexUrl, { method: "GET", headers: { Accept: "application/json" }, signal: controller.signal, }); if (!response.ok) { throw new Error(`HTTP ${response.status} while fetching catalog`); } const payload = await response.json(); return normalizeRemoteSkills(payload); } finally { clearTimeout(timeout); } } ``` The unverified catalog is turned into installation guidance: ```js async function discoverCatalog() { const indexUrl = envVar("CLAWSEC_SKILLS_INDEX_URL") || DEFAULT_INDEX_URL; const timeoutMs = parseTimeoutMs(); const fallback = await loadFallbackCatalog(); try { const remote = await loadRemoteCatalog(indexUrl, timeoutMs); return { source: "remote", index_url: indexUrl, version: remote.version, updated: remote.updated, skills: mergeWithFallbackMetadata(remote.skills, fallback.skills), warning: null, }; } catch (error) { return { source: "fallback", index_url: indexUrl, version: fallback.version, updated: fallback.updated, skills: fallback.skills, warning: String(error), }; } } ``` Catalog entries are displayed as commands: ```js process.stdout.write(` install: npx clawhub@latest install ...[truncated 2537 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (101)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · advisories/feed.json (reported line 10550)May include surrounding context.

json
"id": "CVE-2026-41357",
      "severity": "low",
      "type": "unknown_cwe_214",
      "nvd_category_id": "CWE-214",
      "title": "OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbo...",
      "description": "OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can exploit this by leveraging non-default SSH environment forwarding configurations to leak sensitive environment variables from parent processes to SSH child processes.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"
      ],
      "platforms": [
        "openclaw"
      ],
      "action": "Review and update affected components. See NVD for remediation details.",
      "published": "2026-04-23T22:16:43.177",
      "references": [
        "https://github.com/openclaw/openclaw/commit/cfe14459531e0

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a controlled, approval-gated security tool, but the documented behavior includes persistent hooks, cron automation, filesystem state access, installed-skill discovery, and event-triggered execution without corresponding permission declarations. This transparency gap can cause operators to trust and deploy a skill whose effective behavior and persistence model are broader than advertised.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- Embedded signed advisory trust set: `advisories/feed.json`, `feed.json.sig`, `checksums.json`, `checksums.json.sig`, and `feed-signing-public.pem`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
- Guarded installer: `scripts/guarded_skill_install.mjs`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- Dynamic catalog discovery for installable skills: `scripts/discover_skill_catalog.mjs`

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · advisories/feed.json (reported line 4)May include surrounding context.

json
{
  "version": "0.0.3",
  "updated": "2026-07-12T06:52:13Z",
  "description": "Community-driven security advisory feed for ClawSec. Automatically updated with OpenClaw-related CVEs from NVD and community-reported security incidents.",
  "advisories": [
    {
      "id": "CVE-2026-15320",
      "severity": "medium",
      "type": "missing_authorization",
      "nvd_category_id": "CWE-862",
      "title": "A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function...",
      "description": "A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the fil

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · advisories/feed.json (reported line 472)May include surrounding context.

json
different gateway and node environments",
      "description": "Summary Node exec approvals could use different gateway and node environments. In affected versions, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. This advisory is scoped to the named feature and configuration. It does not change OpenClaw's trusted-operator model: authenticated Gateway operators, installed plugins, and intentional local execution surfaces remain trusted unless a separate policy, approval, allowlist, sandbox, or auth boundary is crossed. Impact When the affected feature is enabled and reachable, this could execute or persist actions beyond the caller's intended authorization. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. Patched Versions The first stable patched version is 2026.6.5. Mitigations Upgrade to OpenClaw 2026.6.5 or later. Before upgrading, restrict the affect

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 2686)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 2908)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 3344)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 3493)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 4307)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 7473)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 9084)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 9085)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 11303)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 11304)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 11984)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 11985)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · advisories/feed.json (reported line 24227)May include surrounding context.

json
"type": "unknown_cwe_184",
      "nvd_category_id": "CWE-184",
      "title": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environmen...",
      "description": "OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to workspace .env files, tool environment overrides, or skill environment blocks can pass malicious Node.js control variables to influence child processes or coverage output paths.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:openclaw:openclaw:2026.5.26:beta1:*:*:*:node.js:*:*",

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 5853)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 10838)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 11591)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 12868)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · advisories/feed.json (reported line 16370)May include surrounding context.

json
"type": "server_side_request_forgery",
      "nvd_category_id": "CWE-918",
      "title": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profil...",
      "description": "OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.",
      "affected": [
        "cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*",
        "openclaw@*"

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
advisories/feed.json:23963