Back to skill

Security audit

Auto-Diagnostic (Tianyi)

Security checks across malware telemetry and agentic risk

Overview

This troubleshooting skill is purpose-aligned, but it needs review because it can read and change OpenClaw token configuration, restart or stop services, and expose tokens without consistently requiring user approval.

Install only if you want an agent to troubleshoot and potentially repair OpenClaw itself. Use read-only diagnosis by default, require explicit approval for every config change, gateway restart, extension install, dependency install, or process stop, and make sure gateway tokens are masked rather than printed in chat or logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The security/privacy section claims the skill only performs read-only log access and implies limited impact, but earlier sections explicitly instruct editing configuration files, restarting services, installing extensions, and killing processes. This mismatch can mislead users or higher-level agents into authorizing a skill under false assumptions, increasing the chance of unsafe automated changes.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are very broad, such as generic phrases like 'connection failed', 'cannot use', 'error', or consecutive failures in a skill chain. This can cause the diagnostic skill to activate in unrelated contexts and perform powerful troubleshooting actions on the wrong target or without sufficient user intent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The main workflow includes modifying configuration files, restarting the gateway, installing browser extensions, and potentially stopping processes, but it does not place a clear consent gate before those actions. In an agentic environment, this creates a meaningful risk of unauthorized or premature state changes that may disrupt services, overwrite settings, or alter authentication configuration.

Ssd 3

Medium
Confidence
98% confidence
Finding
The example output explicitly tells the agent to reveal a concrete authentication token to the user response. Exposing secrets in chat output, logs, screenshots, or transcripts can leak credentials and enable unauthorized access to the gateway or related components.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal