Back to skill

Security audit

Web Tools Guide

Security checks for vulnerabilities and agentic risk

Overview

This skill is a web-tool guide, but it also asks agents to collect API keys, change local configuration, install unverified remote code, and restart browser or gateway processes.

Install only after reviewing whether you trust the opencli package, the GitHub release extension, and the local configuration changes. Avoid pasting API keys into chat; use a secure local secret path instead. Do not run the setup script on a sensitive or shared machine unless you are prepared for global npm installation, browser restart, gateway restart, and persistent local changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
references/web-search-config.md:7
Finding

Mandatory Third-Party Promotion and Agent Workflow Hijacking

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup-opencli.sh:107
Finding

Remote Mutable Code Downloaded and Loaded as a Browser Extension

Content
View full analysis
/dev/null; then downloaded=true fi fi if [ "$downloaded" = false ]; then download_url="${GITHUB_RELEASE_BASE}/latest/download/opencli-extension.zip" if ! curl -fsSL --max-time 60 -o "$tmp_zip" "$download_url" 2>/dev/null; then rm -f "$tmp_zip" fail "Browser Bridge download failed: ${GITHUB_RELEASE_BASE}" fi fi mkdir -p "$ext_dir" unzip -qo "$tmp_zip" -d "$ext_dir" rm -f "$tmp_zip" if [ ! -f "${ext_dir}/manifest.json" ]; then fail "Browser Bridge extraction failed: manifest.json was not found" fi ``` The downloaded content is subsequently activated: ```bash local new_cmdline="${clean_cmdline} --disable-extensions-except=${ext_dir} --load-extension=${ext_dir}" kill "$chrome_pid" 2>/dev/null || true nohup bash -c "exec ${new_cmdline}" > "$log_file" 2>&1 & ``` ### Technical Analysis The script downloads executable browser-extension content from GitHub Releases and loads it into Chrome. If the version-specific artifact cannot be retrieved, it uses the mutable `latest` release URL. No cryptographic hash, signature, trusted manifest, or pinned commit is used to authenticate the archive. Checking only for `manifest.json` verifies archive shape, not origin or integrity. A malicious archive can provide a valid manifest while containing arbitrary JavaScript, content scripts, background workers, or native integration logic. Because the effective payload is hosted remotely, it can change after the Skill has been reviewed. Loading the result as a browser extension gives the remote component access accordi ...[truncated 1442 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/setup-opencli.sh:65
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-opencli.sh:180
Finding

Shell Command Injection Through Chrome Command-Line Reconstruction

Content
View full analysis
/dev/null || true local log_file="/tmp/opencli-chrome-restart.log" nohup bash -c "exec ${new_cmdline}" > "$log_file" 2>&1 & ``` ### Technical Analysis Linux stores process arguments in `/proc//cmdline` as NUL-separated byte strings. The script converts those boundaries to spaces, losing the distinction between argument contents and separators. It then modifies the resulting text with `sed`, concatenates additional text, and evaluates the entire string through `bash -c`. Consequently, shell metacharacters in an existing Chrome argument are interpreted as shell syntax during restart. Quotes, spaces, command substitutions, redirections, semicolons, pipes, and other metacharacters are not preserved as literal argument data. The implementation also breaks legitimate arguments containing spaces and allows the reconstructed command to differ materially from the original Chrome process. ### Attack Path 1. An attacker or another local component starts the Chrome process listening on port 9222 with a crafted argument. 2. The crafted argument contains shell syntax, such as a command substitution or command separator. 3. The setup script identifies that process as the Chrome process. 4. It reads `/proc//cmdline` and converts NUL delimiters to spaces. 5. The crafted data becomes part ...[truncated 681 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/web-search-config.md:84
Finding

Overbroad Process Termination During Gateway Restart

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/web-search-config.md:27
Finding

API Keys Exposed Through Chat, Process Arguments, and Plaintext Verification

Content
View full analysis
openclaw config set plugins.entries.kimi.enabled true openclaw config set plugins.entries.kimi.config.webSearch.apiKey ``` It later verifies configuration by retrieving the secret value: ```bash openclaw config get plugins.entries.tavily.config.webSearch.apiKey openclaw config get plugins.entries.kimi.config.webSearch.apiKey ``` ### Technical Analysis The prescribed workflow exposes secrets through several channels: 1. The user is instructed to paste the API key into the conversation, placing it in chat history and Agent context. 2. The key is passed as a command-line argument, where it may be visible in process listings, diagnostic tools, execution telemetry, shell history, or logs. 3. Verification retrieves the stored key itself rather than checking whether a credential is configured, potentially returning the plaintext value to tool output and conversation context. 4. The document does not specify restrictive file permissions, encryption, redaction, or use of a dedicated secret manager. Checking a secret by reading it back violates least disclosure. The Agent only needs a boolean configuration status or a redacted fingerprint. ### Attack Path 1. A search failure triggers the provider-configuration workflow. 2. The user pastes an API key into the chat. 3. The Agent inserts the key into an `openclaw config set` command. 4. The key appears in the command's argument vector and possibly execution logs or telemetry. 5. The configuration backend stores the key with ...[truncated 784 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is documentation-style guidance for choosing web tools, but the behavior extends into system setup and modification: installing software, downloading artifacts, compiling a browser plugin, and restarting the browser. That mismatch is dangerous because users or orchestrators may trust the skill as harmless guidance while it can trigger privileged local changes and external code supply-chain exposure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill references shell execution capability by instructing the agent to run a setup script (bash {baseDir}/scripts/setup-opencli.sh) but does not declare any tool scope or permissions boundary. This creates an authorization gap: a guidance skill can induce command execution and environment modification without explicit least-privilege declaration, increasing the chance of unintended or unsafe system changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are excessively broad and include everyday terms like 搜索/上网/查资料/web search/fetch/browser/opencli, making the skill likely to auto-activate in many normal conversations. Because the skill contains operational instructions including shell-based setup and mandatory workflow constraints, over-triggering expands the attack surface and can steer unrelated tasks into risky tool use or setup actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill's natural-language instructions are entirely in Chinese and provide no option for the user or agent to choose another language. This creates a locale/language policy issue because the skill effectively mandates one language without documenting user opt-in or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire instruction set and required user-facing messages are written in Chinese, including directives to output text verbatim to the user. There is no indication that the skill is region-specific or that users may opt into another language, which makes this a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks the agent to collect a user's API key and store it persistently without clearly disclosing that the secret will be written to local configuration and remain accessible afterward. This creates a credential-handling risk because users may provide secrets without informed consent, and persisted keys may later be exposed through logs, config reads, backups, or other tools.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs the agent to solicit, store, and later reuse a user-provided API key, turning the skill into a credential collection and persistence workflow. In an adversarial or misconfigured environment, this broadens secret exposure and normalizes handing sensitive credentials to the agent rather than using a secure provisioning path.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide directs the agent to run local configuration and service-management commands that persist a user-supplied API key and modify runtime state. In an agent-skill context, instructions to write secrets into config files and restart infrastructure exceed normal content guidance and can lead to unauthorized system changes, credential exposure, or denial of service if triggered inappropriately.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The restart section includes Docker restart and process-kill commands such as pkill, which can disrupt unrelated workloads and create avoidable downtime. Embedding operational control actions inside a web-search helper skill is dangerous because a routine user request failure could cascade into service interruption on the host.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The later verification step explicitly tells the agent to read back stored API keys from configuration after wake-up, increasing the number of times the secret is accessed and the chance it is surfaced to the model, logs, or other components. Secret retrieval for verification is especially risky because it normalizes exposing credential material rather than checking only metadata such as whether a key is present.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The script downloads executable browser-extension content from a remote GitHub release and installs it without verifying a cryptographic checksum, signature, or pinned immutable artifact. If the release asset, repository, network trust path, or dependency source is compromised, a malicious extension could be installed into the browser and execute with the user's browser privileges.

Content

Scanner excerpt · scripts/setup-opencli.sh (reported line 117)May include surrounding context.

sh
if [ -n "$version" ]; then
        download_url="${GITHUB_RELEASE_BASE}/download/v${version}/opencli-extension.zip"
        info "尝试下载 Browser Bridge 插件 v${version}..."
        if curl -fsSL --max-time 60 -o "$tmp_zip" "$download_url" 2>/dev/null; then
            downloaded=true
        else
            warn "v${version} 下载失败,回退到 latest release"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script explicitly kills the detected Chrome process and escalates to SIGKILL if it does not exit, which can disrupt active browsing sessions and risk unsaved user state. Although there are informational log messages, there is no confirmation prompt or explicit user warning before this destructive action is taken.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-opencli.sh (reported line 262)May include surrounding context.

sh
info "使用新参数重新启动 Chrome..."
    # 后台启动,重定向输出到日志文件
    local log_file="/tmp/opencli-chrome-restart.log"
    nohup bash -c "exec ${new_cmdline}" > "$log_file" 2>&1 &
    local new_pid=$!
    info "Chrome 已启动 (PID: ${new_pid}),日志: ${log_file}"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-like JSON uses natural-language descriptions that frame the resource set as Chinese-oriented, and several entries explicitly prescribe preferred language choices such as '中文首选' and '中文版'. That can conflict with a language/locale neutrality policy because it steers agent behavior toward a specific locale without indicating user choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description '百度搜索(中文首选)' explicitly directs a preferred engine based on language/locale. Because the file does not indicate that this preference is user-selected or limited to a justified regional context, it is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description labels this as 'MDN Web Docs 搜索(中文版)', which steers use toward a specific language version. Without an explicit opt-in or justification that this skill is region-specific, this is a natural-language locale preference violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script's comments and user-visible status/error messages are written in Chinese throughout, with no option to select another language. This creates a locale/language policy concern because the skill imposes a specific language on all users without opt-in or documented regional scoping.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.