Back to skill

Security audit

OpenClaw Guardian

Security checks for vulnerabilities and agentic risk

Overview

This security plugin is not clearly malicious, but it needs review because it may expose recent conversation text to a model provider and its advertised protections appear incomplete or possibly not loadable.

Review this before installing as a security control. Verify the plugin actually loads, treat it as incomplete rather than a reliable safety boundary, check whether your model provider may receive sensitive conversation text, and require fixes for session scoping, redaction, documented path coverage, and blacklist bypass tests.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/llm-voter.ts:157
Finding

Cross-session conversation data is disclosed to the configured LLM provider

Content
View full analysis
f.endsWith(".jsonl")) .map((f: string) => ({ name: f, mtime: statSync(join(sessDir, f)).mtimeMs })) .sort((a, b) => b.mtime - a.mtime); if (files.length === 0) return "(no session context available)"; const latest = join(sessDir, files[0].name); const raw = readFileSync(latest, "utf-8"); const lines = raw.split("\n").slice(-50).join("\n"); const userMessages: string[] = []; for (const line of lines.split("\n")) { if (!line.trim()) continue; try { const entry = JSON.parse(line); const msg = entry.message ?? entry; if (msg.role === "user") { const text = typeof msg.content === "string" ? msg.content : Array.isArray(msg.content) ? msg.content .filter((b: any) => b.type === "text") .map((b: any) => b.text) .join(" ") : ""; if (text.trim()) userMessages.push(text.trim().slice(0, 500)); } } catch { /* skip malformed lines */ } } return userMessages.slice(-3).join("\n---\n") || "(no user messages found)"; } catch { return "(failed to read session context)"; } } ``` ```ts function buildPrompt(toolName: string, params: Record, context: string): string { const detail = toolName === "exec" ? `Command: ${params.command ?? "(empty)"}` : `File path: ${params.file_path ?? params.path ?? "(empty)"}`; return ...[truncated 2771 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/blacklist.ts:252
Finding

Shell blacklist can be bypassed using safe prefixes, command substitution, or interpreter quoting

Content
View full analysis
re.test(seg))) continue; const m = matchRules(seg, CRITICAL_EXEC, "critical") ?? matchRules(seg, WARNING_EXEC, "warning"); if (m) return m; } return null; ``` ### Technical Analysis The implementation approximates shell parsing with regular expressio ...[truncated 2382 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/blacklist.ts:180
Finding

Documented protection for SSH keys, environment files, dotfiles, and systemd units is absent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/index.ts:23
Finding

Broken module paths can prevent the security hook from loading

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding indicates the skill description promises a defensive enforcement layer while the observed behavior includes unmentioned transcript access and lacks evidence of the advertised blocking mechanisms. Hidden or undocumented data access combined with missing enforcement is risky because users may expose sensitive session content to a component they believe is only doing local rule checks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding indicates the skill description promises a defensive enforcement layer while the observed behavior includes unmentioned transcript access and lacks evidence of the advertised blocking mechanisms. Hidden or undocumented data access combined with missing enforcement is risky because users may expose sensitive session content to a component they believe is only doing local rule checks.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
| Level | LLM Votes | Latency | Examples |
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
| Level | LLM Votes | Latency | Examples |
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/blacklist.ts (reported line 203)May include surrounding context.

ts
| Level | LLM Votes | Latency | Examples |
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
| Level | LLM Votes | Latency | Examples |
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/llm-voter.ts (reported line 131)May include surrounding context.

ts
| Level | LLM Votes | Latency | Examples |
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
|-------|-----------|---------|---------|
| No match | 0 | ~0ms | Reading files, git, normal ops |
| Warning | 1 | ~1-2s | `rm -rf /tmp/cache`, `chmod 777`, `sudo apt` |
| Critical | 3 (unanimous) | ~2-4s | `rm -rf ~/`, `mkfs`, `dd of=/dev/`, `shutdown` |

### What Gets Checked

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
### Critical (exec)
- `rm -rf` on system paths (excludes `/tmp/` and workspace)
- `mkfs`, `dd` to block devices, redirects to `/dev/sd*`
- Writes to `/etc/passwd`, `/etc/shadow`, `/etc/sudoers`
- `shutdown`, `reboot`, disable SSH
- Bypass: `eval`, absolute-path rm, interpreter-based (`python -c`, `node -e`)
- Pipe attacks: `curl | sh`, `wget | bash`, `base64 -d | sh`

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
### Critical (exec)
- `rm -rf` on system paths (excludes `/tmp/` and workspace)
- `mkfs`, `dd` to block devices, redirects to `/dev/sd*`
- Writes to `/etc/passwd`, `/etc/shadow`, `/etc/sudoers`
- `shutdown`, `reboot`, disable SSH
- Bypass: `eval`, absolute-path rm, interpreter-based (`python -c`, `node -e`)
- Pipe attacks: `curl | sh`, `wget | bash`, `base64 -d | sh`

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- Writes to `/etc/passwd`, `/etc/shadow`, `/etc/sudoers`
- `shutdown`, `reboot`, disable SSH
- Bypass: `eval`, absolute-path rm, interpreter-based (`python -c`, `node -e`)
- Pipe attacks: `curl | sh`, `wget | bash`, `base64 -d | sh`
- Chain attacks: download + `chmod +x` + execute

### Warning (exec)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- Writes to `/etc/passwd`, `/etc/shadow`, `/etc/sudoers`
- `shutdown`, `reboot`, disable SSH
- Bypass: `eval`, absolute-path rm, interpreter-based (`python -c`, `node -e`)
- Pipe attacks: `curl | sh`, `wget | bash`, `base64 -d | sh`
- Chain attacks: download + `chmod +x` + execute

### Warning (exec)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
- `shutdown`, `reboot`, disable SSH
- Bypass: `eval`, absolute-path rm, interpreter-based (`python -c`, `node -e`)
- Pipe attacks: `curl | sh`, `wget | bash`, `base64 -d | sh`
- Chain attacks: download + `chmod +x` + execute

### Warning (exec)
- `rm -rf` on safe paths, `sudo`, `chmod 777`, `chown root`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

How It Works

text
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/README.md (reported line 18)May include surrounding context.

How It Works

text
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/llm-voter.ts (reported line 107)May include surrounding context.

ts
## How It Works

```
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/llm-voter.ts (reported line 111)May include surrounding context.

ts
## How It Works

```
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/llm-voter.ts (reported line 127)May include surrounding context.

ts
## How It Works

```
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/llm-voter.ts (reported line 131)May include surrounding context.

ts
## How It Works

```
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/llm-voter.ts (reported line 134)May include surrounding context.

ts
## How It Works

```
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/llm-voter.ts (reported line 135)May include surrounding context.

ts
## How It Works

```
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/README.md (reported line 18)May include surrounding context.

How It Works

text
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/README.md (reported line 18)May include surrounding context.

How It Works

text
AI Agent wants to run a tool (e.g., exec "rm -rf /tmp/data")
                    ↓
        ┌───────────────────────┐
        │   Risk Assessor       │  ← Keyword rules, 0ms, no model call

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/blacklist.ts:104

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/blacklist.ts:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/llm-voter.ts:146