Back to skill

Security audit

Openclaw

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent strategy-game skill, but it relies on mutable external code and broad chat triggers that can cause unintended execution or state changes.

Install only in an isolated environment, pin and verify the histrategy packages you intend to run, and avoid exposing unrelated API keys or files. Expect local game saves under ~/.histrategy/rooms, and be aware that broad triggers or group-chat delete commands may affect a campaign unintentionally.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/entry.py:16
Finding

External Import Path Allows Local Module Hijacking

Content
View full analysis
/src/histrategy_agent` to override an otherwise legitimate installed dependency. The imported package is not included in the audited project and no ownership, integrity, signature, or permission checks are performed before loading it. Python executes module-level code during import, so a spoofed module can execute before normal message processing begins. Exploitation requires the attacker to be able to place files in the calculated adjacent `src` directory. This may be possible where multiple packages, users, deployment jobs, or extraction processes share a writable parent directory. ### Attack Path 1. The attacker obtains write access to the adjacent `/src` directory. 2. The attacker creates a spoofed package such as: `src/histrategy_agent/format_engine.py`. 3. The Skill starts and inserts that directory at index zero of `sys.path`. 4. Python resolves `histrategy_agent` from the attacker-controlled directory. 5. Malicious module-level code executes with the privileges of the Agent process. 6. The malicious package can then intercept incoming messages, manipulate responses, ins ...[truncated 654 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Unpinned Dependencies and Mutable Source Installation Create Supply-Chain Risk

Content
View full analysis
=0.3.2 ``` ```markdown ## Installation ```bash pip install histrategy-sdk ``` - `histrategy-sdk` — Game SDK (`Room`, `MultiplayerRoom`, `DirectEngine`) - `histrategy-engine` — Auto-installed as dependency - `histrategy-agent` — Optional: IM bot integration (`TurnProcessor`, IM adapters) ### From GitHub ```bash git clone https://github.com/emergencescience/histrategy cd histrategy pip install -e histrategy-sdk/ ``` ``` ### Technical Analysis The dependency constraint permits every `histrategy-sdk` release at or above version `0.3.2`, while the installation command retrieves the latest version available at installation time. No lock file, exact version, package hash, or signature verification is provided. The alternative GitHub procedure clones a mutable default branch rather than a reviewed commit and then performs an editable installation. Package installation can execute build-backend and setup logic, making the effective executable code dependent on external content that can change after this Skill is audited. The entry point also imports `histrategy_agent` directly, although the documentation describes that component as optional and does not pin it as a runtime dependency. Consequently, important runtime behavior is supplied by unaudited external code. There is no evidence in the audited files that the named PyPI or GitHub projects are intentionally malicious or typosquatted. The vulnerability is the absence of reproducible, integrity-verified dependency resolution. ### Attack Path 1. An upstream package account, repository, release process, transitive dependency, or default branch is compromised. 2. ...[truncated 1096 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code clearly implements a chat-based strategy game and aligns with the general declared purpose of a natural-language historical strategy game over IM. It supports session management, faction selection, status/load/help/delete commands, and turn processing. However, in this supplied chunk, only the Three Kingdoms scenario is exposed: faction choices are all Three Kingdoms-era Chinese warlords, onboarding/help/status are framed around that setting, and there is no Rome Triumvirate scenario logic. Additionally, the declared triggers include Rome-related triggers, but no Rome-specific command handling appears in the code. This is a material description-to-behavior mismatch, though the core gaming purpose otherwise matches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "rome" is overly generic and can cause accidental activation during unrelated conversation about Rome, Roman history, travel, or current events. In an agent environment, unintended invocation can lead to confusing behavior, unnecessary API usage, and unexpected writes to local persistent game state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger "triumvirate" is ambiguous and likely to appear in normal educational or historical discussion, creating a risk of unintentional skill activation. Because this skill persists room state on disk and may invoke external LLM providers, accidental triggering has side effects beyond simple text generation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill intentionally implements session persistence by storing game state on disk and restoring it after context resets. While this is core functionality, persisted state can become a security concern in multi-user systems, shared workstations, or agent environments where local files may be inspected, tampered with, or retained longer than users expect.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

python
from histrategy_sdk import Room

# Create an English Three Kingdoms game as Cao Cao
room = Room.create("my-campaign", faction="cao", lang="en")

# Get the intro scene

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delete command immediately removes the game session for the chat with no confirmation, warning, or undo path. In an IM/group-chat game, any participant who can issue the trigger may be able to erase shared progress accidentally or maliciously, causing integrity and availability loss for the session.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
81% confidence
Finding

The trigger "三国" is short and common in Chinese-language historical or entertainment conversations, so it may activate the skill unintentionally. In context, accidental activation is somewhat mitigated because the skill is a game, but local persistence and possible LLM/API invocation still create side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill discloses file-based persistence, but it does not clearly warn users that state is automatically written to local disk under a home-directory path. This can surprise users in shared or managed environments and may expose gameplay content, names, or prompts to other local users or backup systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The docstring presents fixed trigger words in Chinese and romanized/English forms for invoking the skill, and the rest of the file continues with hard-coded Chinese and English user-facing text. Because there is no opt-in or explicit statement that this is a Chinese-language or region-specific skill, this can be read as a locale/language constraint without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.