Back to skill

Security audit

AgentClear

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it gives the agent authority to send payloads to dynamically selected paid third-party services without clear per-call approval or spending controls.

Install only if you are comfortable letting the agent use an AgentClear API key for paid calls. Before use, require manual confirmation for each proxy request, review exactly what data will be sent, check the selected provider and price, and set account-level spending limits if available. Prefer installing from a pinned reviewed commit or verified release instead of the mutable main-branch commands in the README.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
README.md:15
Finding

Unpinned Remote Skill Installation Permits Supply-Chain Modification

Content
View full analysis
Remediation
View remediation
/SKILL.md ``` 2. Publish a SHA-256 digest for each reviewed release and require verification before installation: ```bash echo " skills/agentclear/SKILL.md" | sha256sum --check ``` 3. Prefer signed, versioned releases rather than the `main` branch. 4. Document signature verification using signed Git tags or release artifacts. 5. Require users to review changes before updating or restarting the gateway. 6. Add an update policy stating that Skill updates are never installed automatically from a mutable branch. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:43
Finding

Dynamic Third-Party Data Forwarding and Automatic Billing Lack Explicit Approval Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 17)May include surrounding context.

bash
# From your OpenClaw workspace
mkdir -p skills/agentclear
curl -o skills/agentclear/SKILL.md https://raw.githubusercontent.com/dwflickinger/agentclear-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

bash
# From your OpenClaw workspace
mkdir -p skills/agentclear
curl -o skills/agentclear/SKILL.md https://raw.githubusercontent.com/dwflickinger/agentclear-skill/main/SKILL.md

Or clone the repo:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

bash
# From your OpenClaw workspace
mkdir -p skills/agentclear
curl -o skills/agentclear/SKILL.md https://raw.githubusercontent.com/dwflickinger/agentclear-skill/main/SKILL.md

Or clone the repo:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly encourages routing agent requests through a third-party paid proxy and describes automatic billing, but it does not clearly warn that user data may be transmitted to external services or that calls can incur charges. In an agent setting, this can lead to unintentional exfiltration of sensitive prompts/files and surprise spending if operators do not understand the trust and billing boundary.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

Discover Services

Find APIs by describing what you need:

bash
curl -X POST https://agentclear.dev/api/discover \
  -H "Authorization: Bearer $AGENTCLEAR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"query": "parse invoices from PDF", "limit": 5}'

Static analysis

No suspicious patterns detected.