Back to skill

Security audit

Openclaw Llm Router

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed model-routing helper that reads local OpenClaw configuration to recommend models, with some privacy-relevant but purpose-aligned local checks.

Install only if you are comfortable with the router reading your OpenClaw config, checking whether common provider API keys are configured, and probing local Ollama. It appears to use that information for model recommendations, not to expose secrets or persist changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior claims broad routing and web-update capabilities, but the file mainly contains instructions and also includes undeclared localhost probing behavior. This mismatch is dangerous because users and reviewers may approve the skill for one purpose while overlooking privacy-relevant local/network access it actually encourages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises intelligent routing but does not prominently warn that the skill reads the user's local OpenClaw configuration and enumerates active providers, which is sensitive environmental metadata. Even if it only checks provider presence rather than raw secrets, users may unknowingly expose details about installed services, local setup, and account-linked capabilities to the skill's decision logic.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example trigger phrases are broad, natural-language commands that overlap with ordinary conversation, so the skill may activate when the user did not intend to invoke routing behavior. In a routing skill that can inspect local configuration and influence model selection, unclear invocation scope can cause unexpected disclosure of configured providers or unintended redirection of tasks to different models/services.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs reading local files, inspecting environment-derived API key presence, and probing localhost/Ollama, but it declares no explicit tool scope or permissions. That creates a transparency and least-privilege problem: a user may invoke the skill without realizing it can access local configuration and local network resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description advertises web-search-powered model library updates without warning the user that data may leave the local environment. Network actions can leak metadata about the user's setup, query intent, or timing, especially if triggered implicitly as part of an update workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The operative role/instruction section is written as a direct mandate in Chinese and does not indicate that the skill should adapt to the user's preferred language. This can constitute a language/locale policy violation because it imposes a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says it will read local OpenClaw configuration and inspect API-key-related fields, but it does not present a clear privacy warning or obtain informed user consent. Local config files often reveal enabled providers, defaults, custom endpoints, and other sensitive operational metadata beyond just keys.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to inspect provider API key presence in environment or config while the manifest declares no environment requirements. Even if only checking presence rather than printing secrets, this still touches sensitive credential context without clear disclosure, which can expose private setup details or normalize secret inspection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown reference forces a specific language/locale for all readers through its headings, descriptions, and annotations, but it does not provide an opt-in, alternative language, or explanation that the document is intended only for a Chinese-speaking or region-specific audience. Under the policy, a skill artifact that imposes a language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document title and all instructional content are presented in Chinese, which can amount to a language-policy violation when no user opt-in or alternative language is offered. The file does not indicate that the locale is region-specific or otherwise justified, so it appears to force a specific language by default.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/openclaw-config-format.md (reported line 59)May include surrounding context.

md
"models": {
    "providers": {
      "my-provider": {
        "baseUrl": "https://api.example.com/v1",
        "apiKey": "${MY_API_KEY}",
        "api": "openai-completions",
        "models": [

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and later console messages are written in Chinese, which imposes a specific language on users of the skill. The file does not offer an opt-in or fallback language, and no region-specific justification is documented.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The stated purpose is to read local config and classify available models, but active provider detection also reads environment variables such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the host environment. Accessing host secrets is a broader capability than config parsing and is not explicitly justified by the narrow 'reads your local config' description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest and module docstring describe reading local OpenClaw configuration and classifying models, but this function additionally makes an HTTP request to localhost to infer whether Ollama is running. Although localhost access is not remote exfiltration, it is still behavior beyond merely reading local config and changes the script from pure config inspection into active service probing.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · scripts/read_config.py (reported line 90)May include surrounding context.

python
break
    # 检测 Ollama
    try:
        urllib.request.urlopen("http://localhost:11434/api/tags", timeout=2)
        active.append("ollama")
    except:
        pass

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions and example prompts are presented only in Chinese, and the skill examples imply Chinese-language interaction by default. There is no stated language option, opt-in, or justification for a Chinese-only locale, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file explains that the router detects activated providers by reading multiple API-key environment variables, and later states it sends a request to a local Ollama endpoint. Under the markdown-specific warning rule, the description should disclose that the skill may inspect credential-related configuration and perform local network calls, because those behaviors can affect privacy and system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.