Back to skill

Security audit

ClawLock

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed security scanner and hardening tool, but it relies on mutable remote installs and self-updates while also touching sensitive agent configuration.

Review this before installing because it asks the agent to run a third-party CLI with broad local security-inspection authority, can modify agent configuration during hardening, and may update itself from PyPI/GitHub. Prefer pinned package versions, avoid `@latest`, run optional red-team tests only against systems you control, and clear or disable local scan history if device fingerprinting is not acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL_EN.md:40
Finding

Unpinned Third-Party Packages Can Execute Mutable Remote Code

Content
View full analysis

Vulnerability Details

File Location: SKILL_EN.md:40, SKILL_EN.md:131, SKILL_EN.md:275; mirrored commands appear in SKILL.md:38, SKILL.md:129, and SKILL.md:272
Vulnerability Type: Unpinned package installation and direct execution of the latest registry release
Risk Level: High

Vulnerable Code Snippets

SKILL_EN.md:40:

bash
pip install clawlock

SKILL_EN.md:131:

bash
pip install -U clawlock

SKILL_EN.md:275:

bash
npm install -g promptfoo
npx promptfoo@latest

Technical Analysis

The Skill directs the Agent to install or execute third-party packages without pinning an audited version or verifying an integrity hash. In particular, npx promptfoo@latest resolves and executes whichever release the package registry currently identifies as the latest version.

The actual clawlock and promptfoo implementations are not included in this project, so their installation scripts, dependency trees, and runtime behavior cannot be verified from the audited files. Although there is no evidence that the current upstream packages are malicious, these commands create a mutable supply-chain execution path: the code executed during a future Skill run may differ from the code that existed when the Skill was reviewed.

Python and Node.js packages can execute code during installation or when their command-line entry points are invoked. Consequently, compromise of a publisher account, registry infrastructure, package dependency, or future release could turn these instructions into arbitrary local code execution.

Attack Path

  1. An attacker compromises an upstream publisher account, package registry, or transitive dependency, or causes a malicious future release to become the selected version.
  2. A user asks the Skill to perform a scan, update, or red-team operation.
  3. The Skill instructs the Agent to run pip install clawlock, pip install -U clawlock, or `npx p ...[truncated 1101 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every executable package to a specifically reviewed version, such as clawlock==2.5.0 and promptfoo@<reviewed-version>; do not use @latest.
  2. Use lock files and require cryptographic integrity verification. For Python, install from a reviewed requirements file with exact versions and hashes using pip install --require-hashes -r requirements.txt.
  3. For Node.js, commit a reviewed lock file and use npm ci; avoid direct npx execution of packages that have not already been installed and verified.
  4. Verify package provenance, publisher identity, release signatures, and expected checksums before installation or update.
  5. Require explicit user approval immediately before any package installation or upgrade, showing the exact package name, resolved version, source registry, and expected integrity value.
  6. Run optional red-team dependencies in an isolated environment with restricted filesystem access, sanitized environment variables, and limited network access.
  7. Do not automatically replace the local Skill file from a mutable branch. Retrieve a versioned release artifact or immutable commit and verify its digest before replacement.
  8. Document the reviewed versions in both SKILL_EN.md and SKILL.md so the two language variants enforce the same dependency policy.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
clawlock precheck ./SKILL.md # 新 skill 导入预检

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
#### 4.2 本地静态分析(63 模式)

🔴 严重(确认恶意):凭证外传(curl/wget) · 反弹Shell(bash/nc/Python/mkfifo) · 挖矿 · 批量删除 · chmod 777 · 提示词注入(覆盖/劫持/越狱/中文) · 混淆载荷(base64→shell) · 零宽字符 · Shell 命令嵌套混淆(`sh -c`/`bash -c`/`cmd /c` 多层包装绕过检测)

🟠 高危:Unicode 转义混淆 · 硬编码凭证 · AI API 密钥 · 危险环境变量export · Cron持久化 · DNS外传 · 用户输入直接进eval · 递归删除系统目录

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL_EN.md (reported line 224)May include surrounding context.

md
#### 4.2 本地静态分析(63 模式)

🔴 严重(确认恶意):凭证外传(curl/wget) · 反弹Shell(bash/nc/Python/mkfifo) · 挖矿 · 批量删除 · chmod 777 · 提示词注入(覆盖/劫持/越狱/中文) · 混淆载荷(base64→shell) · 零宽字符 · Shell 命令嵌套混淆(`sh -c`/`bash -c`/`cmd /c` 多层包装绕过检测)

🟠 高危:Unicode 转义混淆 · 硬编码凭证 · AI API 密钥 · 危险环境变量export · Cron持久化 · DNS外传 · 用户输入直接进eval · 递归删除系统目录

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 396)May include surrounding context.

md
对每个剩余的 guidance-only 发现,依据 `location` 字段找到目标文件。常见目标:

- `~/.openclaw/config.*` · `~/.zeroclaw/config.*` · `~/.claude/settings.json`
- MCP server JSON(通常在 `~/.claude/mcp_servers.json` 或项目级 `.mcp.json`)
- Skill 脚本 / SKILL.md / SOUL.md

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL_EN.md (reported line 399)May include surrounding context.

md
对每个剩余的 guidance-only 发现,依据 `location` 字段找到目标文件。常见目标:

- `~/.openclaw/config.*` · `~/.zeroclaw/config.*` · `~/.claude/settings.json`
- MCP server JSON(通常在 `~/.claude/mcp_servers.json` 或项目级 `.mcp.json`)
- Skill 脚本 / SKILL.md / SOUL.md

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

md
### LLM 辅助加固的安全约束

- **必须备份:** 在写入前,把原文件复制到 `~/.clawlock/backups/<timestamp>/` 并在 `~/.clawlock/hardening_log.json` 追加一条记录(measure_id / files_changed / backup_path),使 `clawlock harden --rollback` 能按统一入口回滚
- **不得越权:** 禁止 `sudo` / `chmod -R 777` / 跨用户目录写入 / 系统级服务安装 / 关闭 SELinux 或 AppArmor
- **最小必要变更:** 不对不相关配置做顺带优化或美化;保留原注释、字段顺序、缩进风格
- **不伪造"已应用":** 若某项需用户手动操作(如禁用 Windows 服务、移除 cron 任务、卸载恶意 skill),只写"建议手动执行并给出命令",不得报告为已完成
- **凭证不入日志:** LLM 补齐的 token / secret 必须引用 env 变量或 secret 管理器占位符(如 `${GATEWAY_TOKEN}`),严禁将实际值写进 config 或对话

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL_EN.md (reported line 433)May include surrounding context.

md
### LLM 辅助加固的安全约束

- **必须备份:** 在写入前,把原文件复制到 `~/.clawlock/backups/<timestamp>/` 并在 `~/.clawlock/hardening_log.json` 追加一条记录(measure_id / files_changed / backup_path),使 `clawlock harden --rollback` 能按统一入口回滚
- **不得越权:** 禁止 `sudo` / `chmod -R 777` / 跨用户目录写入 / 系统级服务安装 / 关闭 SELinux 或 AppArmor
- **最小必要变更:** 不对不相关配置做顺带优化或美化;保留原注释、字段顺序、缩进风格
- **不伪造"已应用":** 若某项需用户手动操作(如禁用 Windows 服务、移除 cron 任务、卸载恶意 skill),只写"建议手动执行并给出命令",不得报告为已完成
- **凭证不入日志:** LLM 补齐的 token / secret 必须引用 env 变量或 secret 管理器占位符(如 `${GATEWAY_TOKEN}`),严禁将实际值写进 config 或对话

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL_EN.md (reported line 194)May include surrounding context.

md
**Interpretation rule:** Treat built-in audit findings as **configuration risk hints**, not as confirmed attacks. Use language like "there is a risk, recommend tightening".

**Output rules:** Show both passing and failing items. Passing example: `✅ | Gateway auth | Enabled, external access requires credentials.` Each item = one sentence: status + impact + recommendation. Do not mix in findings from Steps 2-8.

### Step 2 — Process Detection + Port Exposure

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL_EN.md (reported line 232)May include surrounding context.

md
**Interpretation rule:** Treat built-in audit findings as **configuration risk hints**, not as confirmed attacks. Use language like "there is a risk, recommend tightening".

**Output rules:** Show both passing and failing items. Passing example: `✅ | Gateway auth | Enabled, external access requires credentials.` Each item = one sentence: status + impact + recommendation. Do not mix in findings from Steps 2-8.

### Step 2 — Process Detection + Port Exposure

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims a 'static analysis' boundary while elsewhere instructing active behaviors such as self-updating via pip, replacing its own skill file, editing configs, rollback-capable hardening, and optional live red-team testing. That mismatch can mislead operators about the trust boundary and cause them to approve network access, file writes, or active probing they would not expect from a scanner.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The boundary text says the skill cannot execute real attacks or confirm exploitability, yet the skill also documents red-team testing against endpoints. This contradiction can cause unsafe use against production targets or make users underestimate that the skill may perform active security testing rather than passive review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is presented as a scanner/auditor, but it also instructs direct self-update behavior from PyPI and GitHub and replacement of local skill files. That expands it from analysis into code-fetching and local modification, which materially changes the trust boundary and can be abused if update sources, transport, or repository contents are compromised.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
#### 4.2 本地静态分析(63 模式)

🔴 严重(确认恶意):凭证外传(curl/wget) · 反弹Shell(bash/nc/Python/mkfifo) · 挖矿 · 批量删除 · chmod 777 · 提示词注入(覆盖/劫持/越狱/中文) · 混淆载荷(base64→shell) · 零宽字符 · Shell 命令嵌套混淆(`sh -c`/`bash -c`/`cmd /c` 多层包装绕过检测)

🟠 高危:Unicode 转义混淆 · 硬编码凭证 · AI API 密钥 · 危险环境变量export · Cron持久化 · DNS外传 · 用户输入直接进eval · 递归删除系统目录

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL_EN.md (reported line 224)May include surrounding context.

md
#### 4.2 本地静态分析(63 模式)

🔴 严重(确认恶意):凭证外传(curl/wget) · 反弹Shell(bash/nc/Python/mkfifo) · 挖矿 · 批量删除 · chmod 777 · 提示词注入(覆盖/劫持/越狱/中文) · 混淆载荷(base64→shell) · 零宽字符 · Shell 命令嵌套混淆(`sh -c`/`bash -c`/`cmd /c` 多层包装绕过检测)

🟠 高危:Unicode 转义混淆 · 硬编码凭证 · AI API 密钥 · 危险环境变量export · Cron持久化 · DNS外传 · 用户输入直接进eval · 递归删除系统目录

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
2. **编码混淆** — Unicode smuggling · base64 长字符串
3. **SHA-256 Drift** — 与 `~/.clawlock/drift_hashes.json` 基准对比

**安全守则:** 不读取、不枚举相册 / ~/Documents / ~/Downloads / 聊天记录 / 日志正文。不执行 sudo / TCC 绕过 / 沙箱逃逸。仅读配置元数据、权限状态、文件哈希。

### Step 6 — MCP 暴露面 + 隐式工具投毒(10 个风险信号)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL_EN.md (reported line 244)May include surrounding context.

md
2. **编码混淆** — Unicode smuggling · base64 长字符串
3. **SHA-256 Drift** — 与 `~/.clawlock/drift_hashes.json` 基准对比

**安全守则:** 不读取、不枚举相册 / ~/Documents / ~/Downloads / 聊天记录 / 日志正文。不执行 sudo / TCC 绕过 / 沙箱逃逸。仅读配置元数据、权限状态、文件哈希。

### Step 6 — MCP 暴露面 + 隐式工具投毒(10 个风险信号)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Feature 1 Step 8 explicitly describes LLM red-team testing against an --endpoint, which is an active security test against a target service. Later, the capability boundary states the skill cannot '执行真实攻击或确认漏洞可利用性', which contradicts the earlier red-team functionality at the intent/documentation level.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill explicitly instructs use of npx promptfoo/promptfoo@latest for red-team testing, which fetches and executes remote package code at runtime without a fixed trusted version. In a security tool, this weakens supply-chain integrity and can lead to execution of a compromised or unexpected upstream release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs persistent storage of scan history and a device fingerprint in ~/.clawlock/scan_history.json. Even if intended for trend analysis, retaining identifiable telemetry locally increases privacy risk and creates a sensitive artifact that could reveal usage patterns or aid host correlation if accessed by other software or attackers.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs automatic self-update from PyPI and replacement of the local skill file from GitHub before continuing security work. For a scanning skill, this expands its authority to network retrieval and self-modification, increasing supply-chain and trust-boundary risk if the upstream package, repository, or transport path is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL_EN.md (reported line 403)May include surrounding context.

md
- MCP server JSON (commonly at `~/.claude/mcp_servers.json` or project-level `.mcp.json`)
- Skill scripts / SKILL.md / SOUL.md

**Always Read before writing, never write blind.** If the file is absent or not writable, skip and explain why.

**Step 4 — Show "current → target + UX impact" and wait for confirmation**

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL_EN.md (reported line 454)May include surrounding context.

md
| H015 | Edit MCP server JSON: set `host` to `127.0.0.1`, enable auth, restrict CORS `origin` |
| H016 | Grep skill code for `import(user_input)` / `importlib.import_module(user_input)` / `require(user_input)` and guide tightening |
| H017 | Enable redaction in logging / prompt config, or mask sensitive fields |
| H018 | At the line numbers reported by `scan_skill`, rewrite unsafe phrasing (e.g., strip "bypass confirmation", "skip audit") into compliant equivalents |

Measures not in this table are **guidance only** — the LLM must not attempt automatic rewrites.

Static analysis

No suspicious patterns detected.