Back to skill

Security audit

Publish

Security checks for vulnerabilities and agentic risk

Overview

This skill is a dialect dictionary, but it also includes credential use, cloud syncing, local state changes, and contaminated data that need careful review before installation.

Review before installing. At minimum, remove the /root/.openclaw/openclaw.json API-key fallback, set cloud_share.enabled to false by default, remove or isolate the hardcoded task-queue helper, purge prompt-like rows from the corpus, replace executable incremental SQL with parameterized imports, and add backups or confirmation before database rebuilds.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
auto_enrich.py:24
Finding

Global OpenClaw Credential Extraction and Transmission to MiniMax

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
sync_from_cloud.py:137
Finding

Untrusted Cloud Records Are Persisted in Agent Memory

Content
View full analysis
0: synced += 1 new_words.append((std_word, dial_word, category, contributor)) ``` ```python def write_log(synced, skipped, new_words, total_online, mode): """Write synchronization log""" os.makedirs(MEMORY_DIR, exist_ok=True) log_file = os.path.join(MEMORY_DIR, "sync_from_cloud.md") now = datetime.now().strftime('%Y-%m-%d %H:%M') with open(log_file, 'a', encoding='utf-8') as f: f.write("\n\n## " + now + " · " + ("Full" if mode == "full" else "Incremental") + " synchronization\n\n") f.write("- Online records: " + str(total_online) + "\n") f.write("- Records obtained: " + str(synced + skipped) + "\n") f.write("- Added: " + str(synced) + "\n") f.write("- Skipped: " + str(skipped) + "\n") if new_words: f.write("- Added words:\n") for std, dial, cat, contrib in new_words: f.write(" - " + std + " → " + dial + " (" + cat + ") @" + contrib + "\n") `` ...[truncated 1810 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
add_word.py:67
Finding

Persistent SQL Injection Through Incremental Vocabulary Entries

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
submit-fangyan-sync.sh:13
Finding

External Task Submission Uses Hardcoded Personal and Application Identities

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
data/config.yaml:5
Finding

Cloud Sharing Is Enabled by Default Contrary to the Documented Opt-In Model

Content
View full analysis
Remediation
View remediation

other

Warning
Location
init_db.py:43
Finding

Database Initialization Silently Deletes Existing Local Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (88)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
| data/dialect_data.sql | 方言数据 SQL(init_db.py 使用) |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file materially expands scope from a passive dialect lookup skill into an autonomous data-generation and remote-sync workflow. That increases risk because running the skill can cause unsupervised outbound API calls, database mutation, and cloud writes that users may not expect from the advertised functionality.

Content

No source excerpt is available for this finding.

Tainted flow: 'req' from open (line 192, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · auto_enrich.py (reported line 124)May include surrounding context.

python
method="POST"
    )

    with urllib.request.urlopen(req, timeout=30) as r:
        resp = json.loads(r.read())

    text = ""

Tainted flow: 'req' from open (line 192, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · auto_enrich.py (reported line 154)May include surrounding context.

python
data=data,
        headers={"Content-Type": "application/json"}
    )
    with urllib.request.urlopen(req) as r:
        resp = json.loads(r.read())
    return resp.get("tenant_access_token", "")

Tainted flow: 'req' from open (line 192, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · auto_enrich.py (reported line 199)May include surrounding context.

python
data=data,
        headers={"Content-Type": "application/json"}
    )
    with urllib.request.urlopen(req) as r:
        resp = json.loads(r.read())
    return resp.get("tenant_access_token", "")

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A row at this location contains prompt-like or chain-of-thought style control text embedded as data, which can act as semantic prompt injection if the skill retrieves and feeds corpus entries into an LLM. In a dialect lookup skill, users and the model expect lexical mappings, so hidden model-directed instructions are especially dangerous because they can override output behavior or suppress safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Natural-language assistant-control text embedded inside a lookup corpus is a classic prompt-injection pattern. If an agent concatenates retrieved rows into an LLM prompt, this content can instruct the model to ignore prior policy, reveal reasoning style, or change output format in ways the user did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This repeated control phrase reinforces that the corpus contains active model-steering instructions rather than passive dialect data. Repetition increases the chance that retrieval surfaces the payload and that an LLM overweights it relative to the system or task prompt.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These rows appear to be generation residue and formatting artifacts rather than genuine dialect mappings, which means the dataset is contaminated with model-control or transcript fragments. If surfaced during retrieval, they can poison prompts, degrade tool reliability, and potentially steer LLM responses away from intended behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The content around these lines appears to preserve hidden output-control instructions inside corpus rows, which can act as second-order prompt injection. In a translation/dialect skill, such payloads are likely to be retrieved in response to user text and then interpreted by the model as higher-priority behavioral guidance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script performs an external side effect unrelated to the declared skill purpose: it submits a cloud sync job to a task queue and can direct notifications to a user or group. In a dialect lookup skill, this hidden operational capability creates a covert execution and messaging path that could be abused for unauthorized job submission, data movement, or off-platform actions without user awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code can enqueue external tasks and target arbitrary recipients via receive-id and receive-id-type, which gives the skill a messaging/automation capability beyond simple query functionality. In this context, that mismatch is dangerous because a seemingly harmless language skill could be used as a delivery mechanism for unauthorized workflows, spam, social engineering, or concealed backend actions.

Content

No source excerpt is available for this finding.

Tainted flow: 'req' from open (line 82, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · sync_from_cloud.py (reported line 46)May include surrounding context.

python
"https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal",
        data=data, headers={"Content-Type": "application/json"}
    )
    with urllib.request.urlopen(req) as r:
        resp = json.loads(r.read())
    if resp.get('code') != 0:
        raise Exception("获取token失败: " + str(resp))

Tainted flow: 'req' from open (line 82, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · sync_from_cloud.py (reported line 88)May include surrounding context.

python
"https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal",
        data=data, headers={"Content-Type": "application/json"}
    )
    with urllib.request.urlopen(req) as r:
        resp = json.loads(r.read())
    if resp.get('code') != 0:
        raise Exception("获取token失败: " + str(resp))

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as a dialect lookup/query tool, but this file performs outbound writes to Feishu Bitable and also mutates local configuration by persisting bot_name. That hidden state change and remote synchronization exceed the stated capability and make the skill materially more dangerous because users would not reasonably expect their interactions to be written to cloud storage.

Content

No source excerpt is available for this finding.

Tainted flow: 'req' from open (line 134, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · sync_to_cloud.py (reported line 62)May include surrounding context.

python
'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
        data=data, headers={'Content-Type': 'application/json'}
    )
    with urllib.request.urlopen(req) as r:
        token = json.loads(r.read())['tenant_access_token']

    # 获取 bot 信息

Tainted flow: 'req' from open (line 134, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · sync_to_cloud.py (reported line 70)May include surrounding context.

python
'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
        data=data, headers={'Content-Type': 'application/json'}
    )
    with urllib.request.urlopen(req) as r:
        token = json.loads(r.read())['tenant_access_token']

    # 获取 bot 信息

Tainted flow: 'req' from open (line 134, file read) → urllib.request.urlopen (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · sync_to_cloud.py (reported line 98)May include surrounding context.

python
'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
        data=data, headers={'Content-Type': 'application/json'}
    )
    with urllib.request.urlopen(req) as r:
        token = json.loads(r.read())['tenant_access_token']

    # 获取 bot 信息

Static analysis

No suspicious patterns detected.