Back to skill

Security audit

Skill Safe Install

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant to make OpenClaw installs safer, but its own workflow can push agents into installing skills and skipping review without enough user-controlled gates.

Review this skill carefully before installing. It performs security checks in name, but its instructions can still proceed to permanent skill installation, skip review for hard-coded skill IDs, and modify persistent OpenClaw configuration. Use it only with explicit package names, verified publishers and digests, real isolation for test installs, and a separate confirmation before any formal install or allowlist change.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:9
Finding

Broad Keyword Triggers Force an Installation Workflow Without Final Approval

Content
View full analysis
``` The excerpt is an English translation of the original instructions. ### Technical Analysis The skill treats the mere presence of a broad keyword as authorization to start a mandatory workflow that includes formal installation. It does not distinguish an affirmative installation request from quoted text, documentation, retrieved content, a security audit, a hypothetical question, or a negated request. The instruction that no step may be skipped also attempts to override context-sensitive safety decisions. Although Step 5 requires explicit authorization before changing the allowlist, no equivalent confirmation is required immediately before the formal installation in Step 4. ### Attack Path 1. An attacker places a trigger phrase such as “install skill” in user-controlled or retrieved content. 2. The agent loads the skill and interprets the keyword match as a mandatory workflow trigger. 3. The instructions prohibit skipping Steps 0 through 5. 4. The agent searches for and selects a candidate package. 5. Step 4 runs `clawhub install ` without a documented final approval gate. 6. The selected package is installed into the normal environment. ### Impact Assessment Successful exploitation can redirect the agent from its current task and cause unintended modification of the skill installation environment. Any code, dependencies, installation hooks, ne ...[truncated 335 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:34
Finding

Hard-Coded Skill Allowlist Bypasses Security Review and Suppresses Warnings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:71
Finding

Temporary Working Directory Is Misrepresented as a Security Sandbox

Content
View full analysis
``` ``` The explanatory text is an English translation of the original instructions; the command is unchanged. ### Technical Analysis A temporary working directory provides path separation but not a security boundary. The documented command does not isolate the installer from the host filesystem, environment variables, credentials, process namespace, network, devices, or system calls. It also does not establish an unprivileged execution identity. If package installation invokes hooks, helper programs, or other executable behavior, those operations retain the permissions of the `clawhub` process. Calling this operation a sandbox and allowing it to produce a “sandbox passed” result creates a false assurance that hostile package behavior was contained. ### Attack Path 1. A malicious package reaches Step 3. 2. The workflow creates a temporary directory with `mktemp -d`. 3. `clawhub install` executes with that directory as its work directory. 4. Installation-time behavior accesses host files, inherited secrets, or network resources through the unchanged host environment. 5. The workflow may report the sandbox step as successful despite the absence of containment. 6. The package can subsequently proceed to formal installation. ### Impact Assessment Installation-time behavior has the same effective privileges as the process running `clawhub`. It can potentially read or modify any resource available to that process and communicate with reachable network services. The tem ...[truncated 288 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:62
Finding

Security Inspection Has No Fail-Closed Gate Before Formal Installation

Content
View full analysis
``` Check: - Author and update date - Dependencies and environment variables, including API keys and OAuth - Network and external-system access - Command-execution risks, including `sudo`, `rm`, and `curl | bash` ### Step 3: Sandbox Installation ```bash TMP=$(mktemp -d) clawhub --workdir "$TMP" --dir skills install ``` ### Step 4: Formal Installation ```bash clawhub install ``` Risk guidance: - Low risk: textual guidance without additional credentials - Medium risk: requires an API key with a clear access scope - High risk: OAuth connections to multiple systems or broad command execution ``` The prose is an English translation of the original instructions; the commands are unchanged. ### Technical Analysis The workflow identifies risk categories but defines no blocking condition. It does not state that an inspection failure, high-risk classification, unknown publisher, dangerous command, unexpected network access, or excessive OAuth scope must stop installation. Steps 3 and 4 follow the review as mandatory workflow stages. Explicit authorization is documented only for the later allowlist change, not for accepting the inspection findings and performing the permanent installation. As a result, inspection is informational rather than an effective security gate. ### Attack Path 1. A package is selected and passed to `clawhub inspect`. 2. Inspection reports broad command execution, dangerous shell usage, extensive OAuth permissions, or another high-risk characteristic. 3. The workflow assigns or recommends a high-risk classification. 4. No rule requires termination or renewed user consent. 5. The mandatory sequence continues through the temporary-workdir installation. ...[truncated 652 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:26
Finding

Unvalidated Skill Placeholder Is Interpolated Into Shell and jq Commands

Content
View full analysis
clawhub inspect TMP=$(mktemp -d) clawhub --workdir "$TMP" --dir skills install clawhub install jq '.skills.allowBundled += [""] | .skills.allowBundled |= unique' ~/.openclaw/openclaw.json > /tmp/openclaw.json.new ``` ### Technical Analysis The command templates do not specify validation of the skill identifier. The placeholder is unquoted in the shell commands and is embedded directly inside a quoted `jq` program. If an executing agent performs literal textual substitution using an attacker-controlled skill value, shell metacharacters, whitespace, option prefixes, command substitutions, or crafted quotation characters may alter command parsing. In the `jq` expression, crafted input may terminate the intended JSON string and inject a different filter or produce invalid configuration output. Whether exploitation succeeds depends on how the host agent substitutes and invokes the templates. Nevertheless, the documented pattern is unsafe because it supplies neither a strict slug grammar nor an argument-safe invocation mechanism. ### Attack Path 1. An attacker supplies a crafted value where a skill slug is expected. 2. The agent substitutes the value directly into one of the documented command templates. 3. A shell interprets injected whitespace or metacharacters rather than treating the value as one inert argument. 4. Alternatively, crafted quotation characters alter the `jq` filter used to update `allowBundled`. 5. The injected command executes with the privileges of the agent process, or the configuration update writes unintended content. 6. A malformed or attacker-influenced OpenClaw configuration can then affect subsequent operation. ### Impact Assessment For shell-based execution, succes ...[truncated 529 chars]
Remediation
View remediation
/tmp/openclaw.json.new ``` - Create the output file securely in the target configuration directory, validate the resulting JSON, preserve appropriate permissions, and replace the original atomically only after validation. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The whitelist rule explicitly suppresses risk warnings and exempts listed skills from normal scrutiny solely based on name/author classification. Any trust shortcut in a security-install workflow is dangerous because compromised publisher accounts, typosquatted identifiers, stale whitelist entries, or supply-chain compromise could allow a harmful skill to bypass the review path and be installed with reduced operator skepticism.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states the workflow applies when users say "install skill," but it does not further constrain context, variants, or exclusion cases. This phrase is generic enough that it could match ordinary conversational requests and cause unintended invocation of the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions are broad enough to activate on ordinary discussion about installing or reviewing skills, causing the workflow to push toward operational install steps when the user may only be asking for advice. In a security-sensitive skill, accidental invocation increases the chance of unintended package search, inspection, sandbox installation, or even formal installation if an agent follows the procedure too literally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example and output flow proceed from search and inspection into sandbox and formal installation without an explicit warning or mandatory confirmation before installing an untrusted skill. In practice, this can normalize unsafe behavior and lead operators or downstream agents to install third-party code before the risk is clearly acknowledged and accepted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The install instructions specify activation only via the Chinese phrases "安装技能" / "安全安装". This is a natural-language locale constraint, and the file does not offer alternative languages, opt-in behavior, or any justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.