Back to skill

Security audit

Config Diagnose

Security checks for vulnerabilities and agentic risk

Overview

This diagnostic skill is mostly purpose-aligned, but it can expose local secrets and system details and contains an unsafe shell command pattern.

Review this skill before installing. Only run it in an environment where you are comfortable exposing diagnostic output, and avoid sharing its logs because they may include API key prefixes, process details, file paths under /root, installed skill names, and OpenClaw memory metadata. The IMAP server check should be fixed before use because a crafted EMAIL_IMAP_SERVER value could execute unintended shell commands.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/diagnose.sh:64
Finding

Shell Command Injection Through the IMAP Server Environment Variable

Content
View full analysis
&1 | grep -q succeeded" 2>/dev/null; then echo -e "${GREEN}✓ 可连接${NC}" else echo -e "${YELLOW}⚠ 无法测试连接${NC}" fi fi ``` ### Technical Analysis The `EMAIL_IMAP_SERVER` environment variable is interpolated directly into a command string passed to `bash -c`. Because `bash -c` reparses the resulting string as shell syntax, an attacker-controlled value can contain command separators, command substitutions, redirections, or other shell metacharacters. The initial nonempty-variable check does not validate the value. Quoting the entire command argument to `bash -c` also does not protect the embedded value after interpolation. For example, a value containing `; attacker_command; #` could terminate the intended `nc` command and execute an additional command. The injected command would run with the same operating-system privileges as the diagnostic script. ### Attack Path 1. An attacker obtains control over, or convinces a user to set, the `EMAIL_IMAP_SERVER` environment variable. 2. The attacker places shell syntax and an arbitrary command in the variable. 3. The user or Agent invokes `diagnose.sh email`. 4. The script interpolates the malicious value into the `bash -c` command string. 5. Bash parses and executes the injected command. 6. If the Skill runs as `root`, the injected command receives root-level access to the host. ### Impact Assessment Successful exploitation provides arbitrary local command execution with the privileges of the Skill process. In the documented deployment paths, the Skill accesses `/root/.openclaw`, suggesting that it may operate in a highly privileged context. P ...[truncated 341 chars]
Remediation
View remediation
/dev/null 2>&1; then echo -e "${GREEN}✓ Reachable${NC}" fi else echo "Invalid IMAP server value" >&2 return 1 fi ``` Apply the following controls: 1. Validate the value against an allowlist suitable for DNS hostnames and supported IP-address formats. 2. Never construct shell source code from environment variables. 3. Use `--` where supported to prevent option injection. 4. Run diagnostics under a dedicated, unprivileged account. 5. Add regression tests using values containing `;`, `$()`, backticks, newlines, redirections, and leading hyphens. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/diagnose.sh:86
Finding

API Key and Token Prefixes Disclosed in Diagnostic Output

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/diagnose.sh:138
Finding

Overbroad File Enumeration Under the Root User Directory

Content
View full analysis
/dev/null | head -10) if [ -n "$results" ]; then echo -e "${GREEN}找到文件:${NC}" echo "$results" else echo -e "${RED}未找到文件${NC}" echo -e "\n${YELLOW}建议:${NC}" echo "1. 检查文件名拼写" echo "2. 确认文件是否需要先创建/安装" echo "3. 尝试更广泛的搜索: find / -name '$filename' 2>/dev/null" fi } ``` ### Technical Analysis The file diagnostic searches the entirety of `/root` for a caller-supplied filename pattern. This exceeds the minimum access scope necessary to diagnose files associated with the Skill or OpenClaw workspace. The resulting paths are returned to the caller. Even though file contents are not read, filenames and directory structures can expose the locations of credentials, private keys, backups, configuration files, repositories, operational data, and other sensitive assets. The suggested fallback command further encourages searching the entire filesystem. The filename is quoted within the `find` pattern, so the reviewed statement does not itself establish shell command injection. The confirmed issue is excessive search scope and privileged metadata disclosure. ### Attack Path 1. An untrusted user asks the Agent to search for a sensitive or broad filename pattern. 2. The Agent invokes `diagnose.sh file` with that pattern. 3. The script recursively searches all accessible paths under `/root`. 4. Up to ten matching privileged paths are printed. 5. The caller uses the disclosed paths f ...[truncated 540 chars]
Remediation
View remediation
/dev/null | head -10) ``` Apply these additional controls: 1. Default to the current Skill or workspace directory rather than `/root`. 2. Require explicit, informed confirmation before searching outside approved roots. 3. Maintain an allowlist of searchable directories. 4. Exclude sensitive directories such as `.ssh`, secret stores, credential caches, and backup locations. 5. Return minimal results and avoid exposing unnecessary absolute paths. 6. Remove the recommendation to run `find /`. 7. Run the Skill as an unprivileged service account with filesystem permissions limited to diagnostic needs. ]]>

T05 · Unauthorized Access and Privilege Escalation

Note
Location
scripts/full-diagnose.sh:128
Finding

Unnecessary Inspection of Agent Memory Metadata

Content
View full analysis
/dev/null | wc -l) echo "记忆文件: $memory_count 个" echo "" ``` ### Technical Analysis The full configuration diagnostic inspects persistent Agent memory locations and reports whether the main memory file exists, its size, and the number of memory files. These checks are not necessary for the stated environment-variable, service, network, and configuration diagnostics. The code does not read or modify memory contents, so no memory poisoning or direct content disclosure is established. Nevertheless, accessing and reporting memory metadata unnecessarily expands the Skill's authority and reveals persistent-state information to the caller. The same full diagnostic also inventories host, port, environment-variable, and installed-Skill state. Combined output can provide useful operational reconnaissance, although no external transmission mechanism was found. ### Attack Path 1. A caller causes the Agent to run `full-diagnose.sh`. 2. The script accesses paths associated with persistent Agent memory. 3. It determines whether memory exists, measures the primary memory file, and counts memory entries. 4. These details are printed to the diagnostic output. 5. If the output is available to an untrusted caller or retained in shared logs, that party learns metadata about the Agent's persistent state. ### Impact Assessment The direct impact is limited to metadata disclosure: exis ...[truncated 451 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata uses very broad trigger phrases such as “为什么不能 / 找不到配置 / 排查问题 / 诊断一下”, which can match many unrelated user requests and cause the diagnostic skill to activate unexpectedly. Because this skill is designed to inspect environment variables, files, services, and possibly network state, accidental invocation can expand access to sensitive local context without clear user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The one-line invocation model describes activation from vague problem statements like '为什么不能' and '不工作' without boundaries on what system areas may be examined. This ambiguity encourages automatic overreach from a generic complaint into broad diagnostics, increasing the chance of unnecessary inspection of sensitive configuration, filesystem paths, or service state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Searching under /root grants visibility into root-owned filesystem contents, which is significantly broader than simple file-location troubleshooting. A user-controlled filename can be used to enumerate sensitive files and directory structures in privileged areas, especially if the script runs with elevated permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description advertises diagnosis of configuration issues, environment variables, service state, and file search, but it does not warn that these operations may access sensitive data or system information. In a diagnostic skill, omission of privacy and safety disclosures increases the risk that users or orchestrators invoke it without understanding the scope of local inspection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill promotes a '完整诊断' command for full system diagnosis without any warning about potentially privacy-relevant enumeration or system-impacting checks. In context, a full diagnostic likely broadens inspection scope beyond the user's immediate issue, which raises the chance of unnecessary exposure of secrets, service topology, or sensitive files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The '智能触发' mode says the system should infer when diagnostics are needed from context and then auto-execute a mail diagnostic, but it provides no precise constraints, denylist, or consent gate. This creates a real risk of the skill autonomously performing checks based on weak signals, which can expose local configuration details or normalize unrequested system inspection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API diagnostics enumerate multiple credential environment variables and reveal the first 10 characters of any value found. Even partial secret disclosure increases exposure in logs, terminal history, screenshots, or shared troubleshooting sessions, and checking unrelated credentials broadens access beyond the minimum needed for diagnosis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Printing the first 10 characters of API keys is a direct sensitive-data disclosure. Partial credential leakage can still help attackers correlate secrets, identify providers/accounts, or combine leaked fragments with other exposures.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The service diagnostics inspect system-wide ports and running Node-related processes, which can expose operational details about unrelated applications on the host. In a shared or privileged environment, this leaks process metadata and network posture beyond narrow configuration troubleshooting.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill diagnostics enumerate installed skills and inspect a global workspace path, disclosing tool inventory and filesystem structure unrelated to the stated troubleshooting scope. Such environment discovery can aid reconnaissance and expose internal capability details to unauthorized users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Nearly all user-facing comments and terminal output are in Chinese, and the script does not provide any language selection, opt-in, or justification for restricting output to that locale. This can violate organizational language/locale policy when a skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Manifest 描述强调配置问题、环境变量、服务状态和文件搜索等本地诊断能力,但这里额外对 google.com 和 baidu.com 发起 ping 探测外网/国内网连通性。网络探测不是该技能目的中明确声明的能力,且会主动与外部主机交互。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script contains natural-language comments and user-facing messages in Chinese, including diagnostic output shown to the user later in the file. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire report template is written in Chinese, including headings and labels, which implies the skill will generate output in a fixed language. There is no indication in the template that the user can choose the language or that the Chinese-only format is justified by a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Nearly all comments and user-visible messages are in Chinese, and the script does not provide any language selection or explain that it is intentionally region-specific. This creates a natural-language locale policy concern because the skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The script inspects several sensitive credential-related environment variables, including API keys and an email password, and reports whether they are set. Although it does not print the secret values, the file contains no comment or user-facing warning explaining that credential presence will be checked, which is a safety-relevant action under the audit criteria for code files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.