Back to skill

Security audit

OpenClaw Swarm

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only orchestration skill whose context-sharing features are disclosed and purpose-aligned, though users should avoid sharing secrets or full history unnecessarily.

Install only if you want subagents to share task context. Prefer minimal context sharing, avoid using full history unless necessary, and do not place secrets, credentials, private files, or sensitive personal data in shared context_store namespaces.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly documents spawning subagents with contextSharing values up to "full" but provides no warning that this can disclose complete conversation history, secrets, or other sensitive user data to additional agents. In an orchestration skill, this omission is dangerous because it normalizes broad context propagation and may cause users or downstream agents to expose more data than necessary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes a shared context_store with read, write, delete, list, subscribe, and broadcast capabilities but omits any warning about persistence, cross-subagent visibility, or accidental modification/deletion of shared data. This creates a real risk of sensitive information leakage and integrity issues because multiple subagents may access or alter common state without clear user consent or safety constraints.

Content

No source excerpt is available for this finding.