Back to skill

Security audit

Skill Migrate

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but its publish workflow can copy and upload scripts or sensitive config files with too little review, and it defaults converted packages to a fixed author identity.

Review the generated package before publishing, especially scripts and configuration files, and remove secrets such as .env files or tokens. Confirm the author metadata, slug, version, and file list manually before allowing clawhub publish to run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:46
Finding

Allowlist-Only File Copying Can Publish Secrets or Malicious Scripts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:46-61, SKILL.md:114-118, and references/text-file-extensions.txt:12-13
Vulnerability Type: Inadequate content validation before copying and publication
Risk Level: High

Relevant code segment from SKILL.md:46-61 (English translation):

text
Step 1: Read the source Skill
  → Read SKILL.md and all child files under the WorkBuddy Skill directory
  → Identify frontmatter fields, document structure, and references/scripts/assets content

Step 2: Format conversion
  → Perform frontmatter field mapping
  → Perform body adaptation
  → Copy valid files to the OpenClaw directory

Step 3: Compliance validation
  → Execute all validation rules
  → Output the validation report
  → Automatically fix issues or notify the user

Step 4: Publish to ClawHub
  → Confirm login status
  → Execute clawhub publish

Relevant code segment from SKILL.md:114-118 (English translation):

text
1. references/*.md → Copy directly
2. references/*.yaml / *.yml → Copy directly
3. references/*.html → Copy directly
4. references/*.json → Copy directly
5. scripts/*.py / *.js / *.bat → Copy directly as text files

Relevant code segment from references/text-file-extensions.txt:12-13:

text
Data/configuration:
.json, .yaml, .yml, .toml, .xml, .csv, .tsv, .ini, .cfg,
.conf, .env, .properties

Technical Analysis

The conversion workflow uses an extension allowlist as its principal security boundary. It directly copies executable script formats such as Python, JavaScript, and batch files, as well as potentially sensitive configuration formats such as .env, JSON, YAML, and INI.

A text-file extension only indicates the file representation; it does not establish that the content is safe. An allowlisted file can contain:

  • API keys, access tokens, passwords, or private endpoints.
  • Destructive or covert script behavior.

...[truncated 2262 chars]

Remediation
View remediation

Remediation Suggestions

  1. Deny .env, credential files, private keys, token caches, and local configuration files by default, regardless of whether their extensions are text-based.
  2. Scan every copied file for secrets using entropy checks, known credential patterns, and provider-specific token detectors.
  3. Perform static behavioral analysis of executable scripts before copying or publication. Flag process execution, network downloads, persistence mechanisms, destructive filesystem operations, credential access, and obfuscated content.
  4. Resolve and validate every source path before copying. Reject symbolic links, hard links to files outside the source directory, path traversal, and special device files.
  5. Generate a complete manifest containing file paths, hashes, sizes, and detected risks.
  6. Require explicit user approval of the manifest and script changes before publication.
  7. Separate format validation from security validation. Passing the extension allowlist must never imply that file content is trusted.
  8. Publish from a newly created staging directory containing only reviewed files rather than recursively copying the source tree.
  9. Run conversion and analysis in a restricted sandbox without access to unrelated credentials or sensitive host files.
  10. Abort publication when secret scanning or behavioral analysis produces unresolved findings.

other

Warning
Location
SKILL.md:88
Finding

Automatic Injection of a Fixed Third-Party Author Identity

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:88, SKILL.md:144, and references/conversion-examples.md:35
Vulnerability Type: Attribution and provenance manipulation
Risk Level: Medium

Relevant code segment from SKILL.md:86-91 (English translation):

text
| WorkBuddy field | OpenClaw equivalent | Conversion operation |
| — | metadata.openclaw.emoji | Add and infer from the Skill topic |
| — | metadata.openclaw.author | Add, defaulting to "以七"; user may customize |
| — | metadata.openclaw.homepage | Add if a GitHub repository exists |
| — | metadata.openclaw.requires | Add if the Skill uses environment variables or external CLI tools |
| — | metadata.openclaw.envVars | Add if the Skill requires environment variables |

Relevant code segment from SKILL.md:142-145 (English translation):

text
| Check | Rule | Fix |
| Author field | Recommended | Default to "以七" |

Relevant code segment from references/conversion-examples.md:33-35 (English translation):

text
1. Remove the unsupported agent_created field.
2. Add metadata.openclaw.emoji inferred from the topic.
3. Add metadata.openclaw.author with the default value "以七".

Technical Analysis

The conversion rules insert a fixed author identity when adapting a source Skill, regardless of whether that identity created or owns the source material. This operation changes provenance rather than merely transforming file syntax.

Because conversion can be followed immediately by publication, the generated metadata can publicly associate unrelated Skills with the fixed identity. The process does not require confirmation that the default identity matches the authenticated ClawHub account, the source author, or an authorized publisher.

This is an integrity and attribution issue rather than direct local code execution. It can obscure the original creator and cause consumers to make trust decisions based on inaccura ...[truncated 1047 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the fixed author default.
  2. Preserve verified source attribution when it is available and compatible with the destination format.
  3. If no author is available, leave the field unset or ask the user to provide it explicitly.
  4. Before publication, display the resolved author identity and require affirmative confirmation.
  5. Validate that the requested author is consistent with the authenticated ClawHub account or documented delegation.
  6. Record source provenance separately from publisher identity so conversion does not conflate authorship, ownership, and publication.
  7. Never treat automatic metadata population as successful identity verification.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase for publishing is broad enough that ordinary user language like '发布skill到ClawHub' could invoke a conversion-plus-publish flow without an explicit confirmation boundary. In this skill, publication is a state-changing external action, so ambiguous activation increases the risk of unintended deployment of transformed content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The bulk-conversion trigger '批量转换所有skill' lacks scope, path, and safety constraints, which could cause the agent to scan and modify a large set of local skills unexpectedly. Because the workflow includes reading all subfiles and potentially preparing content for later publishing, an overly broad batch trigger can amplify mistakes and expose unrelated projects to processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

标题和全文均以中文撰写,未说明该技能文档仅面向中文用户,也未提供可选语言或本地化说明。按照规则,若技能在自然语言层面强制特定语言且没有用户选择或合理限定,属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and the entire document are written in Chinese, which effectively imposes a single language for the skill specification without any stated opt-in, alternative locale, or region-specific justification. Under the policy, language constraints should either be optional for users or clearly documented as necessary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill states that converted files are written to '~/.openclaw/workspace/skills//' but does not present this as an upfront warning near the top-level behavior description. Hidden or easy-to-miss write locations reduce user awareness and can lead to unexpected filesystem changes, especially when users think they are only requesting validation or format inspection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This plain-text reference file is entirely written in Chinese and provides no indication that language selection is optional or that the locale is intentionally limited to a Chinese-speaking audience. Under the policy criteria, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.