Back to skill

Security audit

OMNI Semantic Signal Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides a local command-running proxy, but its shell-like authority is broad and not clearly bounded by approvals or safety controls.

Review before installing. Treat this as granting an agent a shell-like local command tool whose output may be archived locally. Only use it in a trusted, sandboxed workspace with an audited OMNI binary, and avoid routing secrets, production credentials, or destructive operations through it unless your OpenClaw host separately enforces approvals and command restrictions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented primarily as a local semantic filtering and cost-saving utility, but its documented tools enable arbitrary terminal command execution and retrieval of archived logs via an external binary. This mismatch can mislead operators into trusting or auto-enabling a skill with much greater authority than its description suggests, increasing the risk of unintended code execution and sensitive data exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill advertises local semantic context filtering, but actually registers a tool that executes terminal commands via an external binary. That mismatch is dangerous because it conceals a high-risk capability behind an innocuous description, increasing the chance that users or orchestrators grant it trust and permissions they would not otherwise allow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The omni_cmd tool accepts an arbitrary string command and passes it to the OMNI binary for execution, enabling broad terminal access unrelated to semantic filtering. Even though execFile avoids shell injection in Node itself, the tool still exposes arbitrary command execution functionality that can be abused to run destructive commands, access secrets, modify files, or pivot to other systems depending on host privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs agents to use omni_cmd exactly like a shell or bash tool, which normalizes arbitrary command execution without any safety warning, scope limitation, or approval guidance. In an agent skill context, this increases the chance that an LLM-driven agent will execute destructive, sensitive, or attacker-influenced commands, especially because the plugin is presented as a secure proxy that may reduce operator caution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises tools that execute terminal commands and manipulate process environment, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and makes it easier for an agent or integrator to grant broader execution capability than users would infer from the metadata.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guidance says to use the command-execution tool for 'all your standard development tasks,' which is an overly broad trigger for a powerful terminal proxy. Broad invocation guidance increases the chance the agent routes unrelated or sensitive tasks through this skill unnecessarily, expanding exposure to command execution and archived output handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module documentation presents the plugin as a local distillation or semantic engine, while the code's primary exposed capability is terminal execution. This deceptive framing increases operational risk by disguising dangerous behavior as an optimization feature, making unsafe deployment or approval more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool executes user-supplied terminal commands without any user-facing warning, confirmation, or policy check. In an agent setting, this can lead to silent execution of harmful actions triggered by prompt injection, model error, or misuse, especially because the capability is embedded in a skill presented as benign semantic processing.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:34