Back to skill

Security audit

Boxed FFmpeg

Security checks for vulnerabilities and agentic risk

Overview

This media-processing skill is not overtly malicious, but it asks users to install or update a gateway plugin and run an unverified WASM binary downloaded from a mutable GitHub URL.

Review this skill carefully before installing. Use it only if you trust the skill publisher, the GitHub repository hosting the WASM file, and the openclaw-wasm-sandbox plugin source. Prefer a packaged or pinned WASM artifact with a published SHA-256 or signature, avoid unconditional plugin updates, and run media jobs in a dedicated directory containing only the intended input and output files.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:30
Finding

Unverified Remote WASM Payload Retrieval and Execution

Content
View full analysis
", args: ["", "", ""] }) ``` ### Technical Analysis The Skill instructs the agent to download an executable WebAssembly component from a personal GitHub repository's mutable `main` branch and then execute that component. The download is not pinned to an immutable commit or version, and the instructions provide no cryptographic checksum or signature verification. Consequently, the executable reviewed at one point in time is not guaranteed to be the executable later downloaded by a user. A repository owner, compromised repository account, or attacker able to alter the upstream content could replace the WASM component without changing this Skill. Although execution occurs in a WASM sandbox, the module is intentionally granted access to the selected `workDir`. Sandbox isolation reduces direct host exposure but does not establish payload integrity or protect files exposed within the mounted working directory. ### Attack Path 1. An attacker compromises the upstream GitHub repository or otherwise gains the ability to modify the WASM file on its `main` branch. 2. The attacker replaces the legitimate FFmpeg component with a malicious WASM payload. 3. A user follows the Skill instructions and downloads the modified component to the expected local path. 4. No digest or signature check detects the substitution. 5. The ...[truncated 906 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:20
Finding

Unpinned Sandbox Plugin Installation and Update

Content
View full analysis
= 0.2.0`.** ```bash openclaw plugins install clawhub:openclaw-wasm-sandbox openclaw plugins update openclaw-wasm-sandbox openclaw gateway restart ``` ``` ### Technical Analysis The documented requirement accepts any plugin version equal to or newer than `0.2.0`, while the installation and update commands do not pin an exact audited version or integrity digest. Running the update command can therefore retrieve whichever version the package source currently resolves as latest. The subsequent gateway restart activates the installed dependency. This creates a supply-chain trust boundary: future plugin releases, compromised registry metadata, or a compromised publisher account could cause code not covered by the original review to be installed and loaded. This finding concerns unsafe dependency mutability rather than evidence that the named plugin is currently malicious. ### Attack Path 1. An attacker compromises the plugin publisher account, distribution source, or release process. 2. The attacker publishes or substitutes a malicious plugin version that satisfies the broad `>= 0.2.0` requirement. 3. A user follows the documented unpinned install or update command. 4. The package manager retrieves the attacker-controlled version because no exact version or integrity lock is required. 5. The user runs the documented gateway restart. 6. The gateway loads the substituted plugin with the permissions available to the plugin runtime. ### Impact Assessment A malicious sandbox plugin could affect every operation routed through that plugin and may have broader access than an individual sandboxed WASM module. Depending on the OpenClaw plugin security model and gateway process permissions, the plugin could potentially ac ...[truncated 364 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to download and trust a WASM binary from a remote GitHub URL at runtime, even though the skill’s stated purpose is local media processing. This creates a supply-chain risk: if the remote file, repository, or transport path is compromised, the agent could fetch and execute untrusted code inside the sandbox, potentially enabling data access, persistence, or sandbox escape depending on plugin weaknesses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file describes operations that write new media files via convert and extract-audio, but it does not explicitly warn users about the data-modifying effect or possible overwrite risk. Although L113 notes that an output file appears in workDir, that is operational detail rather than a clear user warning about filesystem impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.