T09 · Insecure Skill Coding Practices
- Location
sysinfo.sh:14- Finding
Incomplete Denylist-Based Redaction May Expose OpenClaw Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This system-info skill is mostly purpose-aligned, but it can expose sensitive OpenClaw configuration and host details too easily.
Install only if you are comfortable with a status helper that may print local IPs, process details, Docker ports, OpenClaw channel/plugin metadata, agent names, and parts of OpenClaw configuration. Avoid using the OpenClaw or broad default modules around untrusted chats or logs unless the config redaction is changed to an allowlist.
sysinfo.sh:14Incomplete Denylist-Based Redaction May Expose OpenClaw Credentials
sysinfo.sh:143Broad Host and Application Reconnaissance Exposes Sensitive Operational Metadata
The skill is presented as a quick system information helper, but its documented behavior includes broad local environment enumeration: detailed process state, network interfaces and IPs, Docker container metadata, directory listings, and OpenClaw configuration contents. Even with claimed redaction, exposing configuration structure and operational metadata can leak sensitive internal information and materially increase reconnaissance value for an attacker or an over-privileged user request.
The trigger phrases include generic terms such as '状态', '概览', and '怎么样', which are common in ordinary conversation and can cause the skill to activate unintentionally. In this skill's context, accidental invocation is more dangerous because the skill performs host and application enumeration, potentially disclosing system and configuration details when the user did not clearly request them.
The env/all paths disclose host-level details such as hostname, OS version, kernel, current user, shell, local IP addresses, uptime, and installed tool versions without any confirmation, minimization, or disclosure boundary. In an agent skill context, this materially increases fingerprinting and privacy risk because the data can be relayed to a remote user or model and used for targeted follow-on attacks.
The openclaw module reads ~/.openclaw/openclaw.json and enumerates channels, plugins, agents, and session-related filesystem entries, which exposes internal configuration structure and operational metadata even though some secret values are redacted. This is dangerous because non-secret metadata can still reveal deployed integrations, enabled services, agent names, and local layout, all of which aid reconnaissance and may leak private organizational or account information.
The natural-language invocation guidance is entirely specified in Chinese, and no alternative language or opt-in behavior is documented. This can constitute a language/locale policy issue when users are not given a choice.
Natural-language strings that describe the skill's purpose and usage are presented in Chinese only, which effectively forces a specific language on users without opt-in. The file does not indicate that the skill is intentionally region-specific or provide an alternative language path.
No suspicious patterns detected.