Back to skill

Security audit

OpenClaw Audit Log Hook

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant for audit logging, but its example records sensitive tool inputs, outputs, and user/session identifiers without effective redaction.

Review before installing. This may be acceptable only in environments where complete tool-call auditing is intended and logs are tightly controlled. Do not use the sample as-is with credentials, private files, user messages, or production tools unless you first add mandatory recursive redaction, minimize logged fields, pseudonymize identifiers, and define retention and access controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:13
Finding

Raw Tool Parameters and Results Are Logged Without Effective Redaction

Content
View full analysis
{ const entry = { ts: new Date().toISOString(), event: "before_tool_call", tool: event.tool.name, params: JSON.stringify(event.tool.params).slice(0, 500), session: ctx.sessionKey, user: ctx.session?.senderId || 'unknown' }; console.log("[AUDIT]", JSON.stringify(entry)); return {}; }); api.registerHook("after_tool_call", async ({ event, ctx }) => { const entry = { ts: new Date().toISOString(), event: "after_tool_call", tool: event.tool.name, result: String(event.result).slice(0, 200), error: event.error?.message || null, duration: event.durationMs, session: ctx.sessionKey }; console.log("[AUDIT]", JSON.stringify(entry)); return {}; }); ``` The documented redaction function is: ```javascript function redactSensitive(obj) { const sensitive = ['apiKey', 'token', 'password', 'secret']; for (const key of Object.keys(obj)) { if (sensitive.some(s => key.toLowerCase().includes(s))) { obj[key] = '[REDACTED]'; } } return obj; } ``` ### Technical Analysis The hooks serialize raw tool parameters and results directly into console output. Tool calls can contain API tokens, passwords, authorization headers, private messages, command-line credentials, file contents, personal identifiers, or other sensitive data. The use of `.slice(0, 500)` and `.slice(0, 200)` only truncates the recorded values; it does not sanitize them. Any secret appearing within those prefixes remains exposed. Although a redaction function is documented, it is never invoked before the audit entries are logged. The fun ...[truncated 2495 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims sensitive fields will be auto-redacted, but the actual hook examples log raw tool parameters and results and never call the redaction helper. This creates a direct path for secrets, credentials, personal identifiers, command output, and other sensitive material to be written to logs, where retention and broader access can turn a single tool invocation into a durable data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The audit logging description says all tool calls are recorded for auditing and debugging, but it does not warn that parameters, results, session keys, and sender IDs may be stored. In this context, tool inputs and outputs can easily contain sensitive operational data, so lack of disclosure increases privacy risk and makes unsafe deployment more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The implementation examples actively serialize and log raw params and results without warning that sanitization must happen first. Because this is sample code users are likely to copy directly, the incomplete guidance materially increases the chance of insecure logging and leakage of secrets or personal data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.