Back to skill

Security audit

快速信息查询

Security checks for vulnerabilities and agentic risk

Overview

This system-info skill is mostly purpose-aligned, but it can expose sensitive OpenClaw configuration and host details too easily.

Install only if you are comfortable with a status helper that may print local IPs, process details, Docker ports, OpenClaw channel/plugin metadata, agent names, and parts of OpenClaw configuration. Avoid using the OpenClaw or broad default modules around untrusted chats or logs unless the config redaction is changed to an allowlist.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
sysinfo.sh:14
Finding

Incomplete Denylist-Based Redaction May Expose OpenClaw Credentials

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
sysinfo.sh:143
Finding

Broad Host and Application Reconnaissance Exposes Sensitive Operational Metadata

Content
View full analysis
/dev/null || ifconfig | grep -E "^[a-z]|inet " echo "" echo "=== 连接数 ===" ss -s 2>/dev/null | head -10 ;; ``` ```bash load) echo "=== 系统负载 ===" uptime echo "" echo "=== Top 10 进程 (CPU) ===" ps aux --sort=-%cpu | head -11 echo "" echo "=== Top 10 进程 (内存) ===" ps aux --sort=-%mem | head -11 ;; proc) echo "=== 进程统计 ===" echo "总进程数: $(ps aux | wc -l)" echo "运行中: $(ps aux | awk '$8=="R"{c++}END{print c+0}')" echo "睡眠中: $(ps aux | awk '$8=="S"{c++}END{print c+0}')" echo "" echo "=== 关键服务状态 ===" for svc in sshd docker nginx openclaw-gateway; do status=$(systemctl is-active $svc 2>/dev/null || echo "unknown") echo "$svc: $status" done ;; ``` ```bash docker) echo "=== Docker 容器 ===" docker ps -a --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}" 2>/dev/null || echo "Docker 未安装或无权限" echo "" echo "=== Docker 资源 ===" docker stats --no-stream --format "table {{.Name}}\t{{.CPUPerc}}\t{{.MemUsage}}" 2>/dev/null || echo "无运行中容器" ;; openclaw) echo "=== OpenClaw 配置 ===" OC_BIN="$(command -v openclaw 2>/dev/null || echo 'openclaw')" OC_HOME="${OPENCLAW_HOME:-$HOME/.openclaw}" echo "版本: $($OC_BIN --version 2>/dev/null || echo '未知')" echo "" sanitize_and_print_config \ api_key token secret password key \ auth_token access_token refresh_token \ connection_string private_key client_secret webhook_secret echo "" echo "=== 服务状态 ===" systemctl --user is-active openclaw-gateway 2>/dev/null || echo " gateway: 未知" echo " 监听: $(ss -tlnp 2>/dev/null | grep -oP ':\K18789(?=\s)' | head -1 || echo '未知')" echo "" echo "=== Session 概览 = ...[truncated 2991 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill is presented as a quick system information helper, but its documented behavior includes broad local environment enumeration: detailed process state, network interfaces and IPs, Docker container metadata, directory listings, and OpenClaw configuration contents. Even with claimed redaction, exposing configuration structure and operational metadata can leak sensitive internal information and materially increase reconnaissance value for an attacker or an over-privileged user request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include generic terms such as '状态', '概览', and '怎么样', which are common in ordinary conversation and can cause the skill to activate unintentionally. In this skill's context, accidental invocation is more dangerous because the skill performs host and application enumeration, potentially disclosing system and configuration details when the user did not clearly request them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The env/all paths disclose host-level details such as hostname, OS version, kernel, current user, shell, local IP addresses, uptime, and installed tool versions without any confirmation, minimization, or disclosure boundary. In an agent skill context, this materially increases fingerprinting and privacy risk because the data can be relayed to a remote user or model and used for targeted follow-on attacks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The openclaw module reads ~/.openclaw/openclaw.json and enumerates channels, plugins, agents, and session-related filesystem entries, which exposes internal configuration structure and operational metadata even though some secret values are redacted. This is dangerous because non-secret metadata can still reveal deployed integrations, enabled services, agent names, and local layout, all of which aid reconnaissance and may leak private organizational or account information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language invocation guidance is entirely specified in Chinese, and no alternative language or opt-in behavior is documented. This can constitute a language/locale policy issue when users are not given a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language strings that describe the skill's purpose and usage are presented in Chinese only, which effectively forces a specific language on users without opt-in. The file does not indicate that the skill is intentionally region-specific or provide an alternative language path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.