Back to skill

Security audit

OpenClaw Minecraft

Security checks for vulnerabilities and agentic risk

Overview

This Minecraft bot skill is purpose-related but needs review because it sets up persistent automation, replaces a workspace-level cron prompt, and reuses bearer tokens with a hardcoded external controller.

Review before installing. Use only with a controller you operate and trust, replace the hardcoded ngrok URL, avoid open registration, store credentials outside shared workspace files where possible, use short-lived scoped tokens, and do not overwrite an existing CRON_PROMPT.md without a backup and explicit operator approval. Add a clear way to disable or remove the cron job.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:52
Finding

Persistent Autonomous Execution Through a Recurring Cron Job

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 52-56
Vulnerability Type: T06: System Persistence
Risk Level: High

Vulnerable Code:

markdown
## Cron Integration
This project uses Gateway cron (not heartbeat) for autonomous loops.

After installing this skill, ensure:
- Overwrite the workspace root `CRON_PROMPT.md` with `skills/openclaw-minecraft/CRON_PROMPT.md` (always, regardless of existing file).
- A cron job runs every 30 seconds and instructs the agent to follow `CRON_PROMPT.md`.

Technical Analysis

The skill directs the installer to create a scheduled task that invokes the agent every 30 seconds. This task persists beyond the run in which the skill was installed and repeatedly causes authenticated network requests and autonomous Minecraft actions.

The instructions provide no execution lifetime, automatic expiration, resource limit, teardown procedure, or requirement for explicit operator confirmation. Consequently, installing the skill can establish an indefinite cross-session automation mechanism.

The scheduled task follows CRON_PROMPT.md, which requires the agent to load credentials, query the external controller, plan an action bundle, submit the bundle, and record decisions on each eligible cycle.

Attack Path

  1. A user or agent installs the skill and follows its installation instructions.
  2. The installation process creates a cron job that runs every 30 seconds.
  3. Each scheduled invocation directs the agent to follow the workspace CRON_PROMPT.md.
  4. The cron prompt loads the stored bearer token and bot identifier.
  5. The agent sends authenticated state and action requests to the configured external controller.
  6. This behavior continues across sessions until the cron job is manually identified and removed.

Impact Assessment

The mechanism obtains persistent ability to trigger agent activity within the cron job's execution context. It can repeated ...[truncated 470 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not install or enable a cron job automatically as part of skill installation.
  • Require explicit, informed operator approval before creating any scheduled task.
  • Display the exact schedule, command or prompt target, credentials accessed, and expected actions before approval.
  • Assign a bounded lifetime or maximum invocation count to the task.
  • Use a substantially lower frequency unless a 30-second interval is operationally necessary.
  • Scope the task to a dedicated workspace and least-privileged controller token.
  • Provide documented commands to inspect, disable, and permanently remove the scheduled task.
  • Add an emergency stop flag that is checked before credentials are loaded or network requests are made.
  • Record creation and removal events in an operator-visible audit log.

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:55
Finding

Unconditional Replacement of Workspace-Level Automation Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 55; resulting instructions in CRON_PROMPT.md, lines 26-52
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code:

markdown
- Overwrite the workspace root `CRON_PROMPT.md` with `skills/openclaw-minecraft/CRON_PROMPT.md` (always, regardless of existing file).

The replacement prompt then mandates the following behavior:

markdown
0. Auth + bot context (every tick):
   - Load `memory/mc-auth.json` and read `accessToken`.
   - Use `Authorization: Bearer <accessToken>` for **all** API requests.
   - Load `memory/mc-bot.json` and read `botId`.
   - Use that `botId` in all `/v1/bots/{botId}/...` URLs (never leave it blank).
   - Base URL: `https://56eb-125-246-120-211.ngrok-free.app/v1`.
   - If token or botId is missing, stop and report the exact reason.
   - Cron environment note: do NOT use `jq` or `python` (not available).
   - If JSON parsing is needed, use `node -e` instead.
1. Observe: `GET /v1/bots/{botId}/state`.
   - `nearby` is an object: `{ "entities": [...], "blocks": [...] }` (not an array).
2. Busy check: ONLY treat as busy if `metadata.currentTaskId` is a non-empty string OR `metadata.queueLength` > 0.
   - If busy, wait 2 seconds and end this cycle.
   - If `currentTaskId` is `null`/empty and `queueLength` is 0, you MUST continue to steps 3-6 in order. Do not stop early.
3. Plan: decide an action bundle (5 to 10 steps) based on `nearby`, `health`, `hunger`, and persona `priorityRules`.
   - If the previous bundle failed, choose a safer fallback bundle.
   - If you cannot find enough actions, use safe fillers (`move_relative`, `move`, `jump`, `chat`) to reach 5 steps.
4. Build a batch action list:
   - First action is a chat announce using persona `chatTemplate`, e.g., `[plan][carpenter] {plan}`.
   - Then append each action step in order.
   - `mode: "until"` is only
...[truncated 2785 chars]
Remediation
View remediation

Remediation Suggestions

  • Never overwrite a shared workspace instruction file unconditionally.
  • Install skill-specific instructions under a namespaced path, such as skills/openclaw-minecraft/CRON_PROMPT.md, and configure only a dedicated job to use that file.
  • Detect whether the destination already exists and stop safely if it does.
  • Present the operator with a diff and require explicit approval before modifying shared instructions.
  • Preserve an authenticated backup and provide an atomic rollback procedure.
  • Merge only narrowly scoped configuration where possible instead of replacing the whole file.
  • Keep user and administrator safety constraints authoritative and immutable to the skill.
  • Verify file ownership and expected content before every modification to prevent accidental or malicious replacement.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Reusable Bearer Token Stored in a Predictable Plaintext Workspace File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 17; CRON_PROMPT.md, lines 26-27
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code:

markdown
Recommended: store the response in `memory/mc-auth.json` and reuse the `accessToken` for future calls.
markdown
0. Auth + bot context (every tick):
   - Load `memory/mc-auth.json` and read `accessToken`.
   - Use `Authorization: Bearer <accessToken>` for **all** API requests.

Technical Analysis

The skill recommends storing a reusable JWT access token in a predictable workspace file and directs every cron invocation to read that token. It does not specify restrictive file permissions, encryption at rest, use of a platform secret manager, expiry validation, redaction controls, or protection from inclusion in logs and backups.

Bearer tokens authorize their holder without requiring proof of possession of another secret. Any process, tool, skill, backup mechanism, or user that can read memory/mc-auth.json may therefore be able to replay the token against the controller until it expires or is revoked.

The risk is amplified by the fixed path, repeated access, and cross-session storage. The report does not establish that the token has operating-system privileges or access beyond controller-owned bots; the demonstrated authority is limited to the controller permissions encoded in the token.

Attack Path

  1. The agent obtains an access token through open registration or operator provisioning.
  2. Following the recommendation, it writes the token to memory/mc-auth.json.
  3. The file remains in the workspace for reuse by scheduled invocations.
  4. Another workspace component, tool, skill, user, log collector, or backup process with read access obtains the file contents.
  5. The token is replayed in an Authorization: Bearer header to the configured controller.
  6. The unauthorized holder ...[truncated 658 chars]
Remediation
View remediation

Remediation Suggestions

  • Store controller credentials in an operating-system or platform-managed secret store rather than a normal workspace file.
  • Inject the token into the scheduled task only when needed and avoid persisting it in project memory.
  • If file storage is unavoidable, create the file with owner-only permissions and keep it outside shared, synchronized, or version-controlled directories.
  • Use short-lived, narrowly scoped access tokens with explicit bot and operation restrictions.
  • Validate token expiry before use and implement automatic rotation and immediate revocation.
  • Prevent authorization headers and token-bearing responses from being written to logs, telemetry, chat output, or backups.
  • Add .gitignore and backup-exclusion rules as defense in depth, while not treating those controls as substitutes for a secret manager.
  • Audit access to the secret and alert on anomalous controller requests or token reuse.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill describes obtaining a JWT via a registration flow involving a master issuer secret and then sharing the returned access token with the agent. This creates a credential-handling path where sensitive tokens may be exposed to the agent or stored insecurely, expanding the blast radius if the agent workspace, memory files, or logs are compromised.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
To obtain a JWT, an operator should call `POST /v1/auth/register` with the master issuer secret and share the returned `accessToken` with the agent. Refresh tokens can be rotated via `POST /v1/auth/refresh`.

If you don't want to share the master secret, the controller can expose `POST /v1/auth/proxy/register` with allowlist + rate-limit. In that mode, the agent requests an access token using a `proxyKey`.

If open registration is enabled (`POST /v1/auth/open/register`), the agent can request an access token without a proxy key. This is less secure and should only be used when you accept open access.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill permits token issuance through a proxy key or fully open registration without a proxy key, explicitly acknowledging reduced security. In the context of a controller that can create and command bots, weak or open enrollment materially lowers the barrier to unauthorized access and token abuse.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
If you don't want to share the master secret, the controller can expose `POST /v1/auth/proxy/register` with allowlist + rate-limit. In that mode, the agent requests an access token using a `proxyKey`.

If open registration is enabled (`POST /v1/auth/open/register`), the agent can request an access token without a proxy key. This is less secure and should only be used when you accept open access.

## Safety Rules
- Never send LLM API keys to the controller.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt instructs the agent to read a bearer access token from local memory and attach it to all outbound API requests. Even if this is intended for normal bot control, it creates credential-handling risk because the skill operationalizes secret retrieval and network use without any scoping, rotation, redaction, or explicit user consent safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions require use of a bearer token for network requests but provide no user-facing warning or handling guidance about secret transmission. In this context, the skill also hardcodes a remote ngrok endpoint, which increases risk because credentials are being sent to an externally hosted service without transparency or visible trust controls.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill directs the agent to transmit data to an external ngrok-hosted endpoint to self-register and obtain a token. Even though the example only sends an agent name, this establishes outbound communication to an unaudited third-party service and can expose metadata or enable later privileged actions through the issued token.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

Register First (Open Registration)

If open registration is enabled, the agent can self-issue a token:

bash
curl -sS -X POST "https://56eb-125-246-120-211.ngrok-free.app/v1/auth/open/register" \
  -H "Content-Type: application/json" \
  -d '{"agentName":"andy"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs operators to overwrite the workspace root CRON_PROMPT.md unconditionally, which modifies a high-impact control file at the workspace level without any integrity or user-data warning. Because cron-driven prompts can influence future autonomous agent behavior, this can replace existing safeguards or tasking and create persistence across runs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The prompt directs persistent logging of autonomy decisions with timestamps to a local memory file. While not inherently malicious, persistent logs can accumulate behavioral history, world state, or operator-linked activity that may later be exposed to other skills, users, or processes without clear retention controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs the agent to persist decisions with timestamps to local memory without warning the user that this activity history is being recorded. This is a transparency and privacy issue because users may not expect durable recording of autonomous behavior, especially in shared memory accessible beyond a single run.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.