Back to skill

Security audit

OpenClaw Add Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill’s goal is understandable, but it asks an agent to edit live OpenClaw configuration with a Telegram token and unvalidated user-supplied paths.

Review this skill before installing. It should validate agent IDs, avoid shell-style interpolation, protect Telegram bot tokens as credentials, back up and validate openclaw.json before changes, and ask for explicit confirmation before modifying live configuration or creating workspace directories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

Unvalidated Agent ID Enables Shell Injection and Path Traversal

Content
View full analysis
", "name": "", "workspace": "/home/xgao/clawd-workspace/" } ``` ```bash mkdir -p /home/xgao/clawd-workspace/ ``` ### Technical Analysis The Skill instructs the agent to collect an attacker-controlled `agent_id` and insert it directly into both a filesystem path and a shell command. It does not require validation, canonicalization, or shell-safe argument handling. If the agent performs literal textual substitution, shell metacharacters in the supplied identifier may terminate or alter the intended `mkdir` command and cause additional commands to run. An identifier containing path separators or traversal components such as `../` may also resolve outside `/home/xgao/clawd-workspace`, resulting in unauthorized directory creation or an unintended workspace path being written into the OpenClaw configuration. The vulnerability is especially significant because an AI agent may treat the documented command as an executable template. The exploitability of shell injection depends on the agent substituting the value into a shell command without safe argument separation, while the path-traversal risk also applies to direct filesystem operations that do not verify the resolved path. ### Attack Path 1. An attacker asks the Skill to create a Telegram agent. 2. The attacker supplies an `agent_id` containing shell control characters, path separators, or traversal sequences. 3. The agent inserts that value into `/home/xgao/clawd-workspace/` as instructed. 4. If the shell template is executed literally, the injected shell syntax alters the command and executes an attacker-selected command with the agent process's privileges. 5. Alternatively, traversal components cause the resolved directory ...[truncated 832 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs collection and storage of a Telegram bot token directly into a configuration file without warning about secret handling, masking, access controls, or safe storage. Bot tokens are credentials; exposing them in plaintext configs, logs, chat transcripts, or diffs can allow full takeover of the bot account and unauthorized messaging activity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description lists triggers such as "add agent" and "new agent" without narrowing context, exclusions, or activation constraints. These phrases are generic enough to overlap with ordinary conversation and could cause unintended invocation outside OpenClaw Telegram bot setup tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill directs modification of a live configuration file and creation of workspace directories under fixed filesystem paths, but provides no warning about operational impact, backup/rollback, validation, or permission boundaries. Mistakes here can break service availability, overwrite configuration, or create unintended directories, especially if agent identifiers are malformed or if changes are applied without review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction hardcodes the prompt 是否需要独立的memory?, which imposes a specific language regardless of user preference. This is a natural-language policy issue because no opt-in, fallback, or justification for a Chinese-only prompt is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.