Back to skill

Security audit

Security Check

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed security checker, but it can let an agent automatically proceed with installing or executing external code based on heuristic signals.

Install only if you are comfortable with a skill influencing package installs and repository/script downloads. Treat its Safe label as informational, and require manual confirmation before any install, clone, or curl-piped script, especially for mutable versions, unknown maintainers, or commands that execute downloaded code.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 Β· Insecure Skill Coding Practices

Error
Location
SKILL.md:85
Finding

Heuristic Risk Scoring Permits Automatic Installation of Untrusted Code

Content
View full analysis
| bash` strings at `SKILL.md:23` and `README.md:147` are detection examples rather than commands targeting a real remote payload. They are not independently classified as remote payload retrieval and execution. ### Attack Path 1. An attacker publishes a new malicious package, compromises an estab ...[truncated 1665 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

Including curl <url> | bash as a monitored command pattern normalizes an extremely dangerous execution flow: fetching remote content and piping it directly into a shell. In the context of a skill that may label commands as safe and auto-proceed, this can materially increase the risk of remote code execution from untrusted or compromised sources.

Content

Scanner excerpt Β· README.md (reported line 147)May include surrounding context.

md
- `git clone <url>`
- `pip install <package>`
- `npm install <package>`
- `curl <url> | bash`

### 2. Source Identification

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt Β· SKILL.md (reported line 23)May include surrounding context.

md
- `git clone <url>` β€” GitHub/GitLab repositories
- `pip install <package>` β€” Python packages
- `npm install <package>` β€” Node packages
- `curl <url> | bash` β€” Shell scripts
- Downloading any external code for execution

## How It Works

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states the skill 'triggers automatically when OpenClaw detects installation commands,' but it does not clearly define scope, exclusions, or safeguards. In an agentic environment, broad automatic activation can cause the skill to intercept or influence many commands unexpectedly, increasing the chance of unsafe autonomous behavior or user-consent bypass.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command detection section includes broad shell-pattern matching for installation-related commands without describing validation, exclusions, or safety checks. Overbroad trigger logic in a security skill is especially risky because it may engage on dangerous shell constructs and create a false sense of safety around commands that should never be auto-approved.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt Β· README.md (reported line 237)May include surrounding context.

md
Contributions are welcome! Here's how:

1. **Fork** this repository
2. **Create a branch** (`git checkout -b feature/amazing-feature`)
3. **Commit changes** (`git commit -m 'Add amazing feature'`)
4. **Push to branch** (`git push origin feature/amazing-feature`)
5. **Open a Pull Request**

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger 'Downloading any external code for execution' is expansive and not bounded by specific commands, contexts, or exclusions. In a markdown skill description, this can cause unintended invocation because many common development actions could match it without clear scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· references/vulnerability-databases.md (reported line 16)May include surrounding context.

REST API

bash
curl -H "Accept: application/vnd.github+json" \
     "https://api.github.com/advisories?ecosystem=npm&severity=high&per_page=100"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· SKILL.md (reported line 137)May include surrounding context.

bash
curl -H "Accept: application/vnd.github+json" \
     "https://api.github.com/advisories?ecosystem=npm&severity=high&per_page=100"

Query by package:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· references/vulnerability-databases.md (reported line 17)May include surrounding context.

bash
curl -H "Accept: application/vnd.github+json" \
     "https://api.github.com/advisories?ecosystem=npm&severity=high&per_page=100"

Query by package:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· references/vulnerability-databases.md (reported line 22)May include surrounding context.

bash
curl -H "Accept: application/vnd.github+json" \
     "https://api.github.com/advisories?ecosystem=npm&severity=high&per_page=100"

Query by package:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· references/vulnerability-databases.md (reported line 296)May include surrounding context.

bash
curl -H "Accept: application/vnd.github+json" \
     "https://api.github.com/advisories?ecosystem=npm&severity=high&per_page=100"

Query by package:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· references/vulnerability-databases.md (reported line 179)May include surrounding context.

API

bash
curl -X POST "https://api.osv.dev/v1/query" \
     -H "Content-Type: application/json" \
     -d '{
       "package": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· references/vulnerability-databases.md (reported line 302)May include surrounding context.

API

bash
curl -X POST "https://api.osv.dev/v1/query" \
     -H "Content-Type: application/json" \
     -d '{
       "package": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt Β· references/vulnerability-databases.md (reported line 306)May include surrounding context.

md
osv_payload = {
        'package': {'name': package, 'ecosystem': ecosystem},
    }
    osv_response = requests.post(osv_url, json=osv_payload)
    osv_vulns = osv_response.json().get('vulns', [])
    
    # 3. Calculate risk

Static analysis

No suspicious patterns detected.