Back to skill

Security audit

Context Monitor

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real menu-bar monitor, but it needs Review because it hides agent setup steps and uses recurring SSH/install behavior with weak safeguards.

Install only if you are comfortable with a persistent SwiftBar plugin that reads OpenClaw session data and may SSH to another machine every 30 seconds. Review the hidden agent setup section and scripts first, avoid unattended --yes installs, verify SSH host keys manually, and do not rely on environment-variable customization unless the SSH command handling is fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/install.sh:153
Finding

Unverified Remote Homebrew Installer Recommended for Direct Shell Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/install.sh, lines 153-164
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Medium

Vulnerable code:

bash
else
  error "SwiftBar not installed and Homebrew not found."
  echo ""
  echo "  Option 1: Install Homebrew first:"
  echo "    /bin/bash -c \"\$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)\""
  echo "    brew install --cask swiftbar"
  echo ""
  echo "  Option 2: Download SwiftBar directly:"
  echo "    https://github.com/swiftbar/SwiftBar/releases"
  echo ""
  echo "  Then run this installer again."
  exit 1
fi

Technical Analysis

When Homebrew is unavailable, the installer prints a command that downloads the current HEAD revision of Homebrew's installation script and passes it directly to Bash. The project does not automatically execute this command, and the URL belongs to the official Homebrew GitHub repository rather than a personal pastebin. Nevertheless, the recommended workflow creates a remote code-execution channel whose effective payload can change after this Skill has been reviewed.

No release, commit, checksum, or cryptographic signature is pinned or verified. If the upstream repository, GitHub account, delivery infrastructure, or DNS/TLS trust path is compromised, a user following the displayed instruction would execute the substituted payload immediately.

Installing Homebrew may be useful for obtaining SwiftBar, but direct execution of a mutable remote script is not the minimum-risk method required for the declared menu-bar monitoring functionality. The script already presents direct SwiftBar installation as an alternative.

Attack Path

  1. SwiftBar and Homebrew are absent from the user's Mac.
  2. The user runs scripts/install.sh.
  3. The installer displays the curl | bash-equivalent command as the primary option.
  4. An attacker compromises or in ...[truncated 866 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer directing users to Homebrew's official installation documentation rather than printing a ready-to-run remote shell pipeline.
  • Recommend downloading the installer to a local file, inspecting it, and executing it separately.
  • If automated retrieval is retained, pin the URL to a reviewed immutable commit rather than HEAD.
  • Verify the downloaded file against a trusted, published cryptographic digest or signature before execution.
  • Present direct installation of a signed SwiftBar release as the preferred minimal-dependency path.
  • Clearly state that Homebrew installation is optional and requires separate informed user approval.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/swiftbar-plugin.sh:10
Finding

SSH Option and Remote Command Injection Through Unvalidated Environment Variables

Content
View full analysis

Vulnerability Details

File Location: scripts/swiftbar-plugin.sh, lines 10-13
Vulnerability Type: Command and argument injection
Risk Level: High

Vulnerable code:

bash
MINI="${OPENCLAW_SSH_TARGET:-localhost}"
SSH_OPTS="-o ConnectTimeout=3 -o StrictHostKeyChecking=accept-new -o BatchMode=yes"
STATUS_SCRIPT="${OPENCLAW_STATUS_SCRIPT:-~/.openclaw/openclaw-status.py}"

RAW=$(ssh $SSH_OPTS $MINI "python3 $STATUS_SCRIPT" 2>/dev/null)

Technical Analysis

The plugin accepts OPENCLAW_SSH_TARGET and OPENCLAW_STATUS_SCRIPT from its environment and interpolates them into an SSH command without sufficient validation or safe argument construction.

$MINI is expanded without quotes. Consequently, whitespace causes shell word splitting, allowing the value to introduce additional SSH options and operands. In particular, injected SSH configuration options such as ProxyCommand can cause SSH to launch an attacker-selected local helper command.

$STATUS_SCRIPT is inserted into the string sent to the remote shell. Shell metacharacters in this variable are interpreted by that remote shell. For example, a value containing a command separator could append an arbitrary command after the intended Python invocation.

SwiftBar invokes the plugin repeatedly according to the filename interval, so an injected configuration can trigger on every refresh. Although exploitation requires control over the plugin's environment or configuration, code that can influence those variables does not need direct access to the remote OpenClaw host to abuse the trusted SSH connection.

Attack Path

Local execution through SSH option injection:

  1. An attacker gains the ability to influence OPENCLAW_SSH_TARGET in the SwiftBar plugin environment or associated launch configuration.
  2. The attacker supplies a value that is split into an SSH option such as an attacker-defined ProxyCommand and a destination operand.
  3. Swi ...[truncated 1493 chars]
Remediation
View remediation

Remediation Suggestions

  • Validate OPENCLAW_SSH_TARGET against a strict grammar for the supported form, such as a conservative user@hostname pattern, and reject whitespace, leading hyphens, control characters, and shell metacharacters.
  • Insert -- before the destination where supported, while recognizing that validation is still required because SSH option parsing has special behavior.
  • Store SSH options in a Bash array rather than a space-delimited string:
    bash
    SSH_OPTS=(
      -o ConnectTimeout=3
      -o StrictHostKeyChecking=accept-new
      -o BatchMode=yes
    )
    
  • Invoke SSH with quoted array and target expansions:
    bash
    ssh "${SSH_OPTS[@]}" "$MINI" ...
    
  • Do not concatenate STATUS_SCRIPT into remote shell source. Validate it as an absolute path from an approved directory and reject shell metacharacters.
  • Pass the path as a positional parameter to a fixed remote command with robust shell quoting, or use a fixed collector path that cannot be changed through the environment.
  • Consider removing OPENCLAW_STATUS_SCRIPT unless runtime path customization is necessary for the declared functionality.
  • Clear or explicitly define the plugin environment during installation so ambient variables cannot silently alter its SSH behavior.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's stated purpose does not clearly disclose that it will connect to a remote host, execute a status script there, and access agent telemetry over SSH. In context, hidden or under-disclosed remote access is particularly risky because it expands trust boundaries from the local Mac to another machine and may expose sensitive operational data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's stated purpose does not clearly disclose that it will connect to a remote host, execute a status script there, and access agent telemetry over SSH. In context, hidden or under-disclosed remote access is particularly risky because it expands trust boundaries from the local Mac to another machine and may expose sensitive operational data.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
97% confidence
Finding

The skill contains hidden agent-only instructions not displayed to normal users, including operational guidance for executing commands and performing remote deployment. Hidden instructions are dangerous because they create a gap between what the user sees and what the agent may do, undermining informed consent and making privilege escalation through prompt steering more likely.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
---

<!-- Agent instructions below — not displayed on ClawHub -->

## Agent Setup Guide

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 234)May include surrounding context.

sh
error "Cannot connect to $SSH_TARGET via SSH (passwordless auth required)"
    echo ""
    echo "  Step 1 — Generate SSH key (skip if you already have one):"
    echo "    ssh-keygen -t ed25519 -N '' -f ~/.ssh/id_ed25519"
    echo ""
    echo "  Step 2 — Copy key to remote host:"
    echo "    ssh-copy-id $SSH_TARGET"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs agents and users to read local files and execute shell commands, but it declares no explicit tool scope or permissions. That omission weakens user awareness and policy enforcement, making it easier for an agent to perform filesystem and command execution actions that exceed what the visible metadata suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The agent instructions direct running an installer and performing SCP deployment without a strong user-facing warning that these steps modify the local Mac and possibly a remote host. In a skill that can install software and write files, insufficient consent messaging increases the chance of unauthorized or poorly understood system changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The hidden agent instructions tell the agent to use SCP to copy a script onto a remote host, which is a remote file-write operation beyond passive menu-bar monitoring. Even if intended for setup, this materially changes the risk profile by enabling modification of another machine from the agent workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains broad phrases like 'agent monitor,' 'observability,' and 'dashboard mac,' which can cause the skill to activate for loosely related requests. Over-broad invocation is dangerous here because the skill includes shell, installation, and remote-host setup behaviors, so accidental routing could lead to unnecessary privileged actions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/install.sh (reported line 33)May include surrounding context.

sh
echo ""
      echo "  --remote user@host  OpenClaw runs on a remote machine (SSH key auth required)"
      echo "  --local             Force local mode (OpenClaw on this Mac)"
      echo "  --yes, -y           Skip confirmation prompts (for automated/agent usage)"
      echo "  (no args)           Auto-detect based on ~/.openclaw/agents directory"
      exit 0
      ;;

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The confirm() helper auto-accepts actions not only when --yes is provided, but also whenever stdin is not a TTY. That means running the installer from another agent, pipeline, or redirected context can silently approve package installation and system changes without an explicit user decision, increasing the chance of unintended execution in automated environments.

Content

Scanner excerpt · scripts/install.sh (reported line 45)May include surrounding context.

sh
confirm() {
  local msg="$1"
  if [ "$AUTO_YES" = true ] || [ ! -t 0 ]; then
    info "$msg (auto-confirmed)"
    return 0
  fi
  ask "$msg [Y/n] "

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 94)May include surrounding context.

sh
# --- Detect SwiftBar plugin directory ---
PLUGIN_DIR=""
SWIFTBAR_PREFS="$HOME/Library/Preferences/com.ameba.SwiftBar.plist"
if [ -f "$SWIFTBAR_PREFS" ]; then
  CUSTOM_DIR=$(defaults read com.ameba.SwiftBar PluginDirectory 2>/dev/null || true)
  if [ -n "$CUSTOM_DIR" ] && [ -d "$CUSTOM_DIR" ]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/install.sh (reported line 158)May include surrounding context.

sh
error "SwiftBar not installed and Homebrew not found."
    echo ""
    echo "  Option 1: Install Homebrew first:"
    echo "    /bin/bash -c \"\$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)\""
    echo "    brew install --cask swiftbar"
    echo ""
    echo "  Option 2: Download SwiftBar directly:"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 170)May include surrounding context.

sh
fi

# ============================================================
# Step 3: Create plugin directory
# ============================================================
mkdir -p "$PLUGIN_DIR"
if [ ! -w "$PLUGIN_DIR" ]; then

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The plugin’s stated purpose is local menu bar monitoring, but it actually shells out to SSH and executes a remote Python script whose path is controllable via environment variables. That materially expands trust boundaries and attack surface: a compromised or misconfigured remote host, or an unexpected SSH target/script path, can feed untrusted output into the local UI and cause monitoring of a different system than the user expects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Using StrictHostKeyChecking=accept-new causes the plugin to trust a previously unseen SSH host key automatically, which weakens SSH’s protection against first-connection impersonation. Because the script then immediately executes a remote command and consumes its output silently, a man-in-the-middle or DNS/target redirection at first use could spoof the host and supply attacker-controlled data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.