Back to skill

Security audit

Multi Agent Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it can change OpenClaw configuration, install other skills, and grant broad agent powers without enough user control.

Install only if you intend this skill to administer your OpenClaw setup, not just design a team. Before use, require a dry run, review exact config diffs, approve each dependency install, avoid optional third-party skills by default, restrict generated agents to least-privilege profiles, and validate team/role IDs to prevent path or agent-collision issues.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/materialize_team.mjs:8
Finding

Root-Level Path Traversal Enables Arbitrary File Creation and Overwrite

Content
View full analysis
s.trim()).filter(Boolean); const leaderId = args['leader-id'] || `${team}-team-leader`; const roleIdMap = new Map(roles.map(r => [r, (r==='team-leader' ? leaderId : r)])); ``` ```js const teamRoot = `/root/.openclaw/workspace-${team}`; fs.mkdirSync(teamRoot,{recursive:true}); for (const d of ['requirements','architecture','design','implementation','qa']) fs.mkdirSync(path.join(teamRoot,'shared',d),{recursive:true}); const resolvedRoleIds = roles.map(r => roleIdMap.get(r)); cfg.agents.list = cfg.agents.list.filter(a => !resolvedRoleIds.includes(a?.id)); ``` ```js for (const rid0 of roles){ const rid = roleIdMap.get(rid0); const p = PRESET[rid0] || {zh:rid0, emoji:'🤖'}; const displayBase = locale.startsWith('zh') ? p.zh : rid0; const display = rid0==='team-leader' ? `${displayBase}(${team})` : displayBase; const agent = { id: rid, workspace: `${teamRoot}/${rid}`, model: {primary:model, fallbacks:FALLBACKS}, identity: {name: display, emoji: p.emoji}, tools: {profile:'full'}, subagents: {allowAgents: rid0==='team-leader' ? roles.filter(x=>x!=='team-leader').map(x=>roleIdMap.get(x)) : [leaderId]} }; cfg.agents.list.push(agent); fs.mkdirSync(agent.workspace,{recursive:true}); let soul; let agents; if (rid0 === 'team-leader') { const soulTpl = fs.readFileSync(path.join(__dirname, '..', 'references', 'team-leader-template.md'), 'utf8'); const agentsTpl = fs.readFileSync(path.join(__dirname, '..', 'references', 'team-leader-agents-template.md'), 'utf8'); soul = soulTpl .replaceAll('{{LEADER_ID}}', rid) .replaceAll('{{TEAM_DISPLAY}}', locale.startsWith('zh') ? `${team}团队` : team) .replace ...[truncated 2958 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/materialize_team.mjs:51
Finding

All Created Agents Receive an Unrestricted Full Tool Profile

Content
View full analysis
x!=='team-leader').map(x=>roleIdMap.get(x)) : [leaderId]} }; cfg.agents.list.push(agent); ``` ### Technical Analysis The executable materializer assigns `tools.profile` to `full` for every role, regardless of that role's operational requirements. This directly contradicts `references/permission-profiles.md`, which states that least privilege must be applied by default and that execution should be disabled for leaders, planners, analysts, and other nonimplementation roles. Documentation does not mitigate this issue because the executable configuration is authoritative. Even roles intended only to coordinate, plan, or analyze receive the same broad profile as implementation agents. This excessive authority also compounds other risks. Prompt injection, malicious task content, compromised third-party Skills, or errors in persistent agent instructions can invoke capabilities that the affected role never legitimately needed. ### Attack Path 1. A team is created with a low-risk role such as `team-leader`, `product-manager`, or an analyst. 2. The materializer assigns that role the `full` tool profile. 3. The role processes attacker-controlled or prompt-injected task content. 4. The injected content induces use of execution, process, filesystem, or network capabilities exposed by the full profile. 5. The agent performs actions outside its legitimate coordination or analysis function. ### Impact Assessment The precise tools exposed by `profile: 'full'` depend on the OpenClaw runtime, but the co ...[truncated 380 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/materialize_team.mjs:42
Finding

Team Creation Can Silently Replace Existing Global Agents

Content
View full analysis
[r, (r==='team-leader' ? leaderId : r)])); ``` ```js const resolvedRoleIds = roles.map(r => roleIdMap.get(r)); cfg.agents.list = cfg.agents.list.filter(a => !resolvedRoleIds.includes(a?.id)); ``` ```js for (const rid0 of roles){ const rid = roleIdMap.get(rid0); const p = PRESET[rid0] || {zh:rid0, emoji:'🤖'}; const displayBase = locale.startsWith('zh') ? p.zh : rid0; const display = rid0==='team-leader' ? `${displayBase}(${team})` : displayBase; const agent = { id: rid, workspace: `${teamRoot}/${rid}`, model: {primary:model, fallbacks:FALLBACKS}, identity: {name: display, emoji: p.emoji}, tools: {profile:'full'}, subagents: {allowAgents: rid0==='team-leader' ? roles.filter(x=>x!=='team-leader').map(x=>roleIdMap.get(x)) : [leaderId]} }; cfg.agents.list.push(agent); ``` ### Technical Analysis Only the team leader receives a team-prefixed ID by default. Specialist roles retain generic global identifiers such as `qa-engineer`, `product-manager`, or `fullstack-engineer`. Before adding the new agents, the script removes every existing `agents.list` entry whose ID matches a requested role. It does not determine whether the existing entry belongs to the same team, detect a collision, compare ownership, or request replacement authorization. Consequently, creating a new team can silently replace unrelated agents. The replacement changes the agent's workspace, model, identity, tool profile, and A2A permissions while preserving the familiar agent ID. ### Attack Path 1. An OpenClaw installation already contains an agent with a generic ID such as `qa-engineer`. 2. A user or attacker requests creation of another ...[truncated 887 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/provisioning-playbook.md:11
Finding

Optional Third-Party Skills Are Installed Automatically Without Per-Item Approval

Content
View full analysis
` first 2. if no match/error/rate-limit, fallback to `clawhub` 3. perform security pre-check before install: - **primary scanner: `skill-vetter`** protocol - inspect source and publisher trust signal - inspect version and recency - inspect notable risk signals (network access, exec/shell usage, external messaging, credential scope, download-and-execute patterns) - classify risk (LOW / MEDIUM / HIGH / EXTREME) 4. if risk is HIGH/EXTREME, mark as `blocked_for_review` and skip auto-install for that item 5. install non-blocked items automatically No per-item confirmation is required under this policy; instead provide a complete post-install report. ``` ### Technical Analysis The provisioning policy instructs the agent to search external registries and automatically install both required and optional Skills. Any dependency classified below HIGH, including MEDIUM-risk dependencies, may be installed without prior per-item approval. A security scanner is useful but cannot guarantee package safety. Registry metadata, package contents, publisher accounts, and mutable versions may change after review. Search-based package selection also introduces dependency-confusion, typosquatting, misleading-name, and publisher-compromise risks. Automatically installing optional dependencies unnecessarily increases the attack surface because those components are not required for the requested task. ### Attack Path 1. A broad role definition causes the capability mapping to identify an optional or required ...[truncated 897 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/materialize_team.mjs:96
Finding

Sensitive OpenClaw Configuration Is Duplicated into Persistent Backup and Temporary Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (22)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/dialog-flow.md (reported line 33)May include surrounding context.

md
- proceed now (yes/no)


## C.1 Role display rule during confirmation
- Use user's language.
- Show role display names + function/value only.
- Do NOT show agent IDs during this phase.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · references/materialization-checklist.md (reported line 21)May include surrounding context.

md
## 3) Team-level checks
- `team-leader` exists and is single intake role
- risk override policy documented (HIGH/EXTREME requires explicit confirmation)
- team shared directory exists: `/workspace-<team>/shared/`
- no-raw-bulk-output rule is documented for all roles
- team-leader boundary documented (orchestrate only, no specialist implementation)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- `team-leader` exists and is single intake role
- risk override policy documented (HIGH/EXTREME requires explicit confirmation)
- team shared directory exists: `/workspace-<team>/shared/`
- no-raw-bulk-output rule is documented for all roles
- team-leader boundary documented (orchestrate only, no specialist implementation)

## 4) Completion gate

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/create-playbook.md (reported line 94)May include surrounding context.

md
- `team-leader` exists and is single intake role
- risk override policy documented (HIGH/EXTREME requires explicit confirmation)
- team shared directory exists: `/workspace-<team>/shared/`
- no-raw-bulk-output rule is documented for all roles
- team-leader boundary documented (orchestrate only, no specialist implementation)

## 4) Completion gate

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/materialization-checklist.md (reported line 23)May include surrounding context.

md
- `team-leader` exists and is single intake role
- risk override policy documented (HIGH/EXTREME requires explicit confirmation)
- team shared directory exists: `/workspace-<team>/shared/`
- no-raw-bulk-output rule is documented for all roles
- team-leader boundary documented (orchestrate only, no specialist implementation)

## 4) Completion gate

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The playbook expands a planning-oriented skill into taking real administrative actions: discovering, vetting, and automatically installing third-party skills, then applying permission setups. That creates a capability mismatch where users invoking a team-design skill could trigger supply-chain and configuration changes they did not explicitly authorize.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented default policy installs both required and optional skills automatically and explicitly removes per-item confirmation. This is dangerous because optional components can materially change the environment, expand attack surface, or introduce malicious packages without informed user approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic third-party package discovery and installation is not necessary for a skill whose stated purpose is team design and planning. Even with vetting steps, search/fallback/install logic introduces classic supply-chain risk, especially because fallback sources and manual review can be weaker controls than a trusted allowlist.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/snippet-templates.md (reported line 34)May include surrounding context.

md
## Return-Path Rule
Assignee must return result to delegator explicitly after completion.

## No Raw Bulk Output Rule
Do not paste large raw source/logs/json in chat.
Report concise summary + artifact path only.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The skill explicitly authorizes internal state-changing actions without user confirmation, including modifying openclaw.json and setting A2A/subagent permissions. Even if framed as deterministic setup, these are privileged configuration changes that can expand agent capabilities or alter execution topology without operator approval, increasing the risk of unintended access or unsafe automation.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
### 6) Safe execution guardrails
Before any external-effect action, apply this confirmation policy:
- No confirmation needed for internal deterministic setup:
  - creating/updating agents in openclaw.json
  - setting A2A/subagents permissions
- Confirmation required for channel/bot credential binding and other irreversible external effects.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The instruction to avoid asking the user to confirm internal steps and to execute configuration materialization and permission setup automatically grants the skill autonomy over sensitive actions. This is dangerous because the 'internal steps' include changes to openclaw.json and subagent/A2A permissions, which affect trust boundaries and operational behavior beyond simple content generation.

Content

Scanner excerpt · references/create-playbook.md (reported line 9)May include surrounding context.

md
Confirm with user:
- final role list

Do NOT ask user to confirm these internal steps; execute automatically:
1) openclaw.json agent materialization
2) A2A/subagents permission setup

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The playbook directs the agent to automatically create or update configuration, bindings, and per-role files in the workspace without an explicit user-facing warning that files will be modified. In an agent skill, silent filesystem/config mutation can lead to unintended privilege changes, broken existing setups, or overwrite of trusted team configuration, especially because it also touches A2A boundaries and bindings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L23-L27 use Chinese role titles inside an otherwise English template, which imposes a specific language choice on part of the skill output. The file does not indicate that this locale is optional, user-selected, or required for a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The playbook normalizes automatic installation of optional skills without an upfront warning that system state will be modified. Lack of clear pre-action disclosure undermines informed consent and increases the chance of silent environment changes, including introduction of risky or unnecessary dependencies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Applying tool whitelists and permission profiles per role gives the skill administrative control over effective agent capabilities. In context, this is more dangerous because the manifest describes analysis and planning outputs, so users may not expect real permission changes that can overgrant access or misconfigure execution boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L14 states that the team leader must create an English task directory, which imposes a specific language requirement in the skill instructions. This is a natural-language policy concern because the file does not offer a language choice or explain why English is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s operational instructions are written as a direct requirement in Chinese, beginning with '你是…', and nowhere provide an option for the user to choose another language or explain that the skill is region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets locale to zh-CN when the user does not provide --locale, which imposes a specific language/locale choice by default. This is a natural-language policy concern because the file does not indicate user choice or a documented justification for enforcing that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script unconditionally defaults locale to zh-CN when no --locale argument is supplied. This imposes a specific language/locale choice on generated agent identity and content behavior without explicit user opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script does more than generate a plan: it directly edits the OpenClaw runtime configuration, creates agent workspaces under /root, and can add live channel bindings for an account. In a skill described as building a reusable multi-agent team, this crosses from advisory/planning behavior into privileged environment mutation, which is dangerous because invoking the skill can silently persist agents and routing state in the runtime.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Every generated agent receives tools.profile='full', granting broad capabilities regardless of role. This violates least privilege and increases blast radius: if any created agent is misconfigured, compromised, or prompted into unsafe actions, it has unnecessary access to powerful tools that the team-construction use case does not inherently require.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The recommended format specifies Chinese text labels such as '阶段', '负责人', '正在处理', '交付位置', and '状态' with no indication that this is optional or user-selected. This creates a natural-language locale constraint that may conflict with organizational language-choice policies.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/create_team.mjs:21