Back to skill

Security audit

AOI Sandbox Shield (Lite)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a local snapshot and config-validation helper, but its snapshot command persistently copies potentially sensitive OpenClaw config and agent-state files without clear permission controls or retention guidance.

Review this before installing if your OpenClaw config or workspace memory may contain secrets or private instructions. The skill does not appear to send data off-host or install persistence mechanisms, but running the snapshot command will make additional local copies of sensitive files and keep them until manually removed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.js:53
Finding

Sensitive configuration and agent-state snapshots lack explicit restrictive permissions

Content
View full analysis

Vulnerability Details

File Location: skill.js, lines 53-87
Vulnerability Type: Insecure storage of sensitive local data
Risk Level: Medium

Vulnerable Code

js
function snapshot({ reason }) {
  const workspace = path.join(os.homedir(), '.openclaw', 'workspace');
  const snapRoot = path.join(workspace, '.sandbox_snapshots_lite');
  fs.mkdirSync(snapRoot, { recursive: true });

  const snapId = new Date().toISOString().replace(/[:.]/g, '-');
  const dir = path.join(snapRoot, snapId);
  fs.mkdirSync(dir);

  const targets = [
    path.join(os.homedir(), '.openclaw', 'openclaw.json'),
    path.join(workspace, 'AGENTS.md'),
    path.join(workspace, 'SOUL.md'),
    path.join(workspace, 'CURRENT_STATE.md'),
    path.join(workspace, 'MEMORY.md'),
  ];

  const manifest = {
    __sdna__,
    kind: 'snapshot',
    snapId,
    reason: reason || '',
    createdAt: nowKST(),
    files: [],
  };

  for (const p of targets) {
    const info = readFileIfExists(p);
    manifest.files.push(info);
    if (info.ok) {
      const base = path.basename(p);
      fs.copyFileSync(p, path.join(dir, base));
    }
  }
}

Technical Analysis

The snapshot operation duplicates security-sensitive configuration and agent-state files, including openclaw.json, MEMORY.md, SOUL.md, and AGENTS.md. These files may contain credentials, private state, operational details, user-derived memory, or instructions governing agent behavior.

The snapshot root and timestamped directory are created without explicit permission modes. Their effective permissions therefore depend on the process umask and existing parent-directory controls. Copied files are also not explicitly normalized to owner-only permissions. If the source files have permissive modes, or the surrounding workspace is accessible to other accounts, the snapshots may remain accessible beyond the intended user.

This issue does ...[truncated 1361 chars]

Remediation
View remediation

Remediation Suggestions

  • Create the snapshot root and each snapshot directory with explicit owner-only permissions:
    js
    fs.mkdirSync(snapRoot, { recursive: true, mode: 0o700 });
    fs.chmodSync(snapRoot, 0o700);
    fs.mkdirSync(dir, { mode: 0o700 });
    
  • Write copied files using an explicit 0o600 mode rather than relying on inherited source permissions:
    js
    const data = fs.readFileSync(p);
    fs.writeFileSync(path.join(dir, path.basename(p)), data, {
      mode: 0o600,
      flag: 'wx',
    });
    
  • Write manifest.json with mode 0o600.
  • Reject symbolic-link targets or verify resolved paths before reading to prevent unexpected files from being included if a target is replaced with a symlink.
  • Add retention controls so stale snapshots containing sensitive information can be automatically removed.
  • Document that snapshots may contain credentials, private memory, and agent instructions.
  • Consider allowing users to select or exclude snapshot targets, particularly configuration files that may contain authentication material.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation says the skill does not apply configs, while the code reportedly performs configuration application or update actions. That discrepancy can cause operators to run the skill expecting read-only validation/snapshot behavior, but instead trigger state-changing configuration updates that may weaken security, break systems, or silently alter protected settings.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims it does not modify cron, but the analysis reports cron modification behavior in code. This contradiction is dangerous because cron changes create persistence and scheduled execution, which can be abused for unauthorized tasks and are especially risky when hidden behind documentation that says no such behavior exists.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly claims the skill does not send messages externally, yet the static analysis indicates there is outbound HTTP request behavior in the implementation. That mismatch is security-relevant because it can mislead users and reviewers into approving a skill that may exfiltrate data, fetch remote instructions, or create hidden network dependencies under a false 'public-safe' description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The snapshot command copies several user workspace and configuration files into a new snapshot directory under the user's home workspace without any warning, confirmation, scope restriction, or sensitivity checks. While it does not exfiltrate data off-host, it silently duplicates potentially sensitive files such as configuration and memory/state documents, increasing the risk of unintended retention, later disclosure, or misuse by other tools or users with access to the workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The nowKST function forces all createdAt timestamps to Korea Standard Time by adding UTC+9 and appending +09:00. This imposes a specific locale/timezone behavior without offering user opt-in or documenting why this locale is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.