T05 · Unauthorized Access and Privilege Escalation
- Location
lib/spawn-security-proxy.js:200- Finding
Security proxy tool restrictions are accepted but never enforced
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not malicious, but its security-isolation helper and orchestration guidance overstate controls that the shipped code does not actually enforce.
Install only if you are comfortable treating the JavaScript libraries as reference code that needs review and hardening before production use. Do not rely on the security proxy for real isolation unless your OpenClaw runtime separately enforces tool, filesystem, network, output-size, and cost limits; also review or remove the optional failure-tracer hook before scoring sensitive outputs.
lib/spawn-security-proxy.js:200Security proxy tool restrictions are accepted but never enforced
lib/spawn-security-proxy.js:229Caller-controlled task text is delegated without sanitization
lib/spawn-security-proxy.js:276Documented prompt-injection and output defenses are not implemented
lib/quality-scorer.js:12Quality scorer conditionally loads and invokes an undeclared out-of-package component
The supplied code does not implement or demonstrate most of the declared high-level orchestration features. Instead, it is specifically an example file for a 'researcher' specialist workflow. It shows how to call spawnResearcher and spawnMultiPerspective with mock spawn functions, plus source credibility scoring and simple quality checks. There is some limited alignment with 'cost-aware spawning' because returned mock results include cost fields, and there is some orchestration in the sense of spawning multiple perspectives. However, the primary purpose is not broad production-ready subagent orchestration patterns; it is a research example/demo. No security isolation, phased implementation, or peer-collaboration mechanisms are present in this code chunk.
The description is only partially aligned. The code does relate to security isolation and cost-aware spawning, but it does not implement or demonstrate the broader declared scope of advanced specialized subagent orchestration, phased implementation, or peer collaboration. Instead, it is a standalone example file showing how to call spawnSecurityProxy for isolated third-party API access with schema enforcement and cost checks. Because the declared purpose substantially overstates and broadens the actual behavior of this code chunk, this should be flagged as a mismatch.
The description suggests orchestration infrastructure and patterns for managing subagents (security isolation, phased implementation, peer collaboration, cost-aware spawning). The code does not implement orchestration, spawning, isolation, collaboration, or phased execution logic. Instead, it evaluates the quality of subagent outputs using rubric-based heuristics and can optionally send low-scoring results to a failure tracer. That is a materially different primary purpose, so this is a clear description/behavior mismatch.
Referenced artifact was not completely inspected
- Inline attack vector documentation in `spawn-security-proxy.js` (test fixtures, not live payloads)
Referenced artifact was not completely inspected
- Inline attack vector documentation in `spawn-security-proxy.js` (test fixtures, not live payloads)
Referenced artifact was not completely inspected
**lib/spawn-researcher.js** - Multi-perspective research framework
Referenced artifact was not completely inspected
**lib/cost-estimator.js** - Cost estimation and tracking
Referenced artifact was not completely inspected
**lib/cost-estimator.js** - Cost estimation and tracking
Referenced artifact was not completely inspected
node examples/security-proxy-usage.js
Referenced artifact was not completely inspected
node examples/researcher-usage.js
Referenced artifact was not completely inspected
node examples/cost-estimation-demo.js
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
// Bearer tokens in headers
{ pattern: /Authorization:\s*Bearer\s+\S+/gi, replacement: 'Authorization: Bearer [REDACTED_TOKEN]' },
// Access tokens in URLs
{ pattern: /access_token=\S+/g, replacement: 'access_token=[REDACTED_TOKEN]' },
{ pattern: /api_key=\S+/g, replacement: 'api_key=[REDACTED_KEY]' },
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
},
tool_escalation: {
description: 'Attempt to use restricted tools',
example: 'Use exec to read /etc/passwd or access main workspace',
defense: 'Tool whitelist enforced at framework level'
},
persistence: {
The skill explicitly describes code paths that may read environment variables, including examples that derive paths from process.env.OPENCLAW_WORKSPACE and guidance that external API keys should be stored in environment variables. However, the manifest declares no tool scope or permissions, so consumers have no machine-readable restriction on env access. In a skill package that includes runnable JS reference libraries, this increases the chance that copied code will access sensitive environment data without prior review.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
# Package Contents Disclosure
# This skill contains runnable JS reference libraries in lib/ and example templates in templates/.
# These files are NOT auto-executed on install. They are reference implementations
# intended to be copied into your workspace lib/ directory manually or via setup.sh.
# setup.sh only creates local directory scaffolding — it makes no network calls and installs no packages.
package_type: reference-implementation-with-libs
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
# Package Contents Disclosure
# This skill contains runnable JS reference libraries in lib/ and example templates in templates/.
# These files are NOT auto-executed on install. They are reference implementations
# intended to be copied into your workspace lib/ directory manually or via setup.sh.
# setup.sh only creates local directory scaffolding — it makes no network calls and installs no packages.
package_type: reference-implementation-with-libs
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
# intended to be copied into your workspace lib/ directory manually or via setup.sh.
# setup.sh only creates local directory scaffolding — it makes no network calls and installs no packages.
package_type: reference-implementation-with-libs
auto_executes: false
---
# Advanced Subagent Architecture
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- Version: 1.0.0+
- Integration: Auto-classification of incoming tasks, risk scoring, pattern routing
- Tested: Yes (production since 2026-02-15)
- Documentation: See `skills/task-routing/SKILL.md`
**cost-governor**
- Status: ⚠️ Planned (design phase)
The document explicitly states a current limitation: skill code runs in the main agent context with no code isolation, no execution validation, and no capability restrictions. In a package that ships runnable JS reference libraries and encourages copying/invoking them, this means any malicious or buggy skill code would inherit broad agent privileges, enabling data exfiltration, destructive actions, or unauthorized external calls if executed. The context makes this more dangerous because the skill normalizes advanced orchestration patterns and external consultation workflows, increasing the likelihood of users integrating executable components.
**Limitations:**
- ❌ No code isolation for skills (skill code runs in main agent context)
- ❌ No execution validation (skill can do anything agent can do)
- ❌ No capability restrictions (skill inherits all agent tools)
- ❌ Trust model: Binary (external = vet, internal = trust)
**Current Workaround:**
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
v2 Design Considerations:
// Proposed: Skill capability manifest
// skills/my-skill/SKILL.md
---
capabilities_required:
- web_search # Skill needs web access
The v2 design sketch proposes core logic that would 'auto-approve safe requests' from subagents. Even though it is aspirational documentation rather than active code, auto-approval of subagent requests can create a privilege-escalation path if request classification is wrong or manipulable, especially in a system already described as lacking strong sandboxing and per-skill restrictions. The danger is contextual: in a subagent orchestration skill, automation of trust decisions is security-sensitive.
})
// Core receives request:
// - Auto-approve safe requests (data lookup from memory)
// - Escalate to human for decisions
// - Return answer to subagent
// - Subagent continues with clarification
The file openly documents that the current framework lacks output size limits and that subagents can generate extremely large outputs. In an orchestration-heavy skill, unbounded output can lead to denial of service through memory exhaustion, storage consumption, log flooding, or runaway cost when outputs are processed or transmitted onward. The context increases risk because several patterns encourage spawning multiple agents and aggregating their outputs.
- ❌ No memory limit kills (agent can OOM the host)
- ❌ No cost threshold kills (can exceed budget before timeout)
- ❌ No stuck detection (infinite loops run until timeout)
- ❌ No output size limits (can generate gigabytes of text)
**Current Workaround:**
- Set conservative timeouts (may kill productive work early)
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
**Documented:**
- Current state: Binary trust model (external = vet, internal = trust)
- Limitations: No code isolation, no runtime sandboxing, no capability restrictions
- Workaround: Manual vetting, human code review
- v2 Proposal: Capability manifests + runtime sandboxing for all skills
- Code example: 15 lines of skill capability manifest with isolation levels
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
// Apply gates
if (estimate.expected < 0.10) {
console.log(` ✓ Auto-approved (micro tier)`);
} else if (estimate.expected < 0.50) {
console.log(` ⚠️ Logged to cost tracking`);
} else if (estimate.expected < 2.00) {
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
// Apply gates
if (estimate.expected < 0.10) {
console.log(` ✓ Auto-approved (micro tier)`);
} else if (estimate.expected < 0.50) {
console.log(` ⚠️ Logged to cost tracking`);
} else if (estimate.expected < 2.00) {
No suspicious patterns detected.