Back to skill

Security audit

Openclaw Security Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible OpenClaw security tool, but it can expose secrets in reports and change authentication settings in risky ways.

Install only if you are comfortable reviewing and running each command manually. Avoid JSON reports and shared output paths until raw secret redaction is fixed, do not paste or share command output, and back up ~/.openclaw/openclaw.json before using token rotation or hardening.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scanner.py:126
Finding

Plaintext Secrets Are Included in JSON Scan and Report Output

Content
View full analysis
50 else matched_value, "auto_fixable": False }) ``` The scan command directly serializes the resulting object: ```python # scripts/main.py:77-79 if args.format == "json": print(json.dumps(results, indent=2, ensure_ascii=False)) ``` The report generator carries the same finding objects into JSON reports: ```python # scripts/report.py:46-49 if include_secrets: secrets_results = scan_secrets(deep=deep) report["secrets_findings"] = secrets_results["findings"] report["secrets_summary"] = secrets_results["summary"] ``` ```python # scripts/report.py:68-70 def format_json(report: Dict) -> str: """Format report as JSON.""" return json.dumps(report, indent=2, ensure_ascii=False) ``` Reports may then be persisted to a caller-selected path: ```python # scripts/main.py:156-165 if output: if args.output: Path(args.output).write_text(output) print(f"Report saved to: {args.output}") else: print(output) ``` ### Technical Analysis The scanner correctly creates a masked representation in `matched`, but it also retains the original detected value in `full_match`. Values of 50 characters or fewer are stored without redaction. Longer values expose their first 50 characters, which is sufficient to reveal many API keys, passwords, and authentication token ...[truncated 1958 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/token.py:75
Finding

Token Rotation Accepts Empty or Cryptographically Weak Token Lengths

Content
View full analysis
str: """Generate a secure random token.""" alphabet = string.ascii_letters + string.digits return ''.join(secrets.choice(alphabet) for _ in range(length)) ``` ```python # scripts/token.py:81-123 def rotate_token(new_token: str = None, length: int = 32) -> Dict: """ Rotate the authentication token. Args: new_token: Optional new token to use. If not provided, generates one. length: Length of token to generate if new_token not provided. Returns: Dict with old and new token info. """ if not CONFIG_FILE.exists(): return {"error": "Config file not found"} # Read current config with open(CONFIG_FILE, 'r') as f: config = json.load(f) old_token = config.get("gateway", {}).get("auth", {}).get("token", "") # Generate new token if not provided if new_token is None: new_token = generate_token(length) # Update config if "gateway" not in config: config["gateway"] = {} if "auth" not in config["gateway"]: config["gateway"]["a ...[truncated 2653 chars]
Remediation
View remediation
str: if not isinstance(length, int): raise TypeError("Token length must be an integer") if not MIN_TOKEN_LENGTH <= length <= MAX_TOKEN_LENGTH: raise ValueError( f"Token length must be between {MIN_TOKEN_LENGTH} and {MAX_TOKEN_LENGTH}" ) alphabet = string.ascii_letters + string.digits return ''.join(secrets.choice(alphabet) for _ in range(length)) ``` 2. Validate `new_token` when caller-supplied values are supported. Reject empty, short, or otherwise invalid values before modifying the configuration. 3. Use an `argparse` validation function so unsafe values fail before confirmation or file access. 4. Generate and validate the replacement token before reading or modifying persistent configuration. 5. Write the configuration atomically: - Create a temporary file in the same directory. - Apply mode `0600`. - Flush and synchronize it. - Replace the original with `os.replace()`. 6. Preserve restrictive ownership and permissions from the existing configuration. 7. Keep a protected backup or provide a safe rollback mechanism in case the gateway rejects the new configuration. 8. Add tests for negative, zero, short, valid, excessively large, and non-integer values. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:54
Finding

Documented Deep-Audit, Auto-Fix, Quiet, and Custom-Pattern Options Are Silently Ignored

Content
View full analysis
Dict: """ Run comprehensive security audit. Args: deep: Include deeper checks auto_fix: Attempt to fix issues automatically quiet: Suppress output Returns: Dict with audit results """ config = load_config() skill_config = load_skill_config() findings = [] # Config checks findings.append(check_gateway_bind(config)) findings.append(check_auth_mode(config)) findings.append(check_token_strength(config)) findings.append(check_tailscale(config)) findings.append(check_plugins(config)) # Access checks findings.append(check_paired_devices()) findings.extend(check_channel_permissions()) findings.append(check_exec_approvals()) ``` The scan parser accepts a custom pattern: ```python # scripts/main.py:269-275 scan_parser = subparsers.add_parser("scan", help="Scan for secrets") scan_parser.add_argument("--deep", action="store_true", help="Deep scan") scan_parser.add_argument("--pattern", help="Custom pattern to scan") ``` However, the supplied pattern is discarded: ```python # scripts/main.py:70-76 def cmd_scan(args, i18n: dict): """Scan for secrets.""" print_header(i18n.get("title", "OpenClaw Security Guard"), i18n) results = scan_secrets( custom_patterns=None, ...[truncated 2466 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill documentation indicates token rotation and direct modification of authentication configuration, which is materially more sensitive than passive security reporting. Directly reading and writing auth tokens raises the risk of credential leakage, accidental lockout, unauthorized persistence changes, or insecure storage if the operation is not tightly scoped and clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill documentation indicates token rotation and direct modification of authentication configuration, which is materially more sensitive than passive security reporting. Directly reading and writing auth tokens raises the risk of credential leakage, accidental lockout, unauthorized persistence changes, or insecure storage if the operation is not tightly scoped and clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The skill documentation indicates token rotation and direct modification of authentication configuration, which is materially more sensitive than passive security reporting. Directly reading and writing auth tokens raises the risk of credential leakage, accidental lockout, unauthorized persistence changes, or insecure storage if the operation is not tightly scoped and clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documentation indicates token rotation and direct modification of authentication configuration, which is materially more sensitive than passive security reporting. Directly reading and writing auth tokens raises the risk of credential leakage, accidental lockout, unauthorized persistence changes, or insecure storage if the operation is not tightly scoped and clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill documentation indicates token rotation and direct modification of authentication configuration, which is materially more sensitive than passive security reporting. Directly reading and writing auth tokens raises the risk of credential leakage, accidental lockout, unauthorized persistence changes, or insecure storage if the operation is not tightly scoped and clearly disclosed.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.json (reported line 12)May include surrounding context.

json
"scan": {
    "paths": [
      "~/.openclaw/openclaw.json",
      "~/.openclaw/.env",
      "~/.openclaw/credentials/"
    ],
    "ignore_patterns": [

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scanner.py (reported line 190)May include surrounding context.

python
"scan": {
    "paths": [
      "~/.openclaw/openclaw.json",
      "~/.openclaw/.env",
      "~/.openclaw/credentials/"
    ],
    "ignore_patterns": [

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scanner.py (reported line 161)May include surrounding context.

python
continue

            # Only scan text files
            if filename.endswith(('.json', '.env', '.yaml', '.yml', '.conf', '.config', '.ini', '.txt', '.md')):
                filepath = Path(root) / filename
                findings.extend(scan_file(filepath))

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill promotes scanning for secrets and managing tokens without any privacy or handling warning for discovered sensitive data. This can lead users to expose credentials in reports, logs, chat history, or shared terminals, increasing the chance of credential theft or accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The changelog and usage examples advertise an automatic hardening mode with '--fix' but do not warn that it may change live system configuration. Users may run it assuming it is a read-only audit action, which can cause unintended service disruption, lockouts, or configuration drift on security-sensitive systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises --fix and hardening commands that can change configuration or system state, but it does not warn users that these operations may modify files or security settings. In a security-focused tool, users may trust and run remediation commands quickly, increasing the chance of unintended or unsafe changes without prior backup or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README describes secret scanning and report generation but omits privacy and data-handling warnings, even though these features may inspect sensitive files and write discovered secrets or metadata into output files. This can lead users to expose confidential information in generated reports, logs, terminals, or shared storage unintentionally.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises commands that read from and write to local files via the referenced Python scripts, but the manifest does not declare any explicit tool scope or permissions boundary. In a skill ecosystem, undeclared file read/write capability weakens user consent and review, making it easier for a skill to access or modify sensitive local data beyond what a user expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises '--fix' and hardening actions without prominently warning that these commands can modify system or application state. Users may invoke what sounds like a diagnostic security tool and unintentionally trigger configuration changes, causing service disruption, unexpected auth changes, or irreversible modifications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file defines all visible titles, commands, messages, and help text exclusively in Chinese, which can indicate a language/locale constraint. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale limitation is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security-best-practices.md (reported line 168)May include surrounding context.

bash
# Allow only specific IP
sudo ufw allow from 192.168.1.100 to any port 18789

# Or use iptables
sudo iptables -A INPUT -p tcp --dport 18789 -s 192.168.1.100 -j ACCEPT

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security-best-practices.md (reported line 171)May include surrounding context.

bash
# Allow only specific IP
sudo ufw allow from 192.168.1.100 to any port 18789

# Or use iptables
sudo iptables -A INPUT -p tcp --dport 18789 -s 192.168.1.100 -j ACCEPT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code writes changes directly to the configuration file when apply_hardening(fix=True) is used, but the write itself has no confirmation prompt or immediate user-facing disclosure. Although the function docstring mentions fixes can be applied, the file-modifying operation is safety-relevant and is triggered automatically from the main block.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

On direct execution, the script immediately calls apply_hardening(fix=True), causing security-affecting changes to be applied automatically with no confirmation, preview, or dry-run default. In a security tool, this is more dangerous because operators may run it expecting an audit/report and instead trigger token rotation or authentication changes that can disrupt access or unexpectedly modify production configuration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The token rotation flow prints the newly generated authentication token directly to stdout after rotation. In a security tool, this is dangerous because terminal output may be captured in shell history, CI logs, screen recordings, or remote session transcripts, causing immediate credential exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly prints result['new_token'] to stdout without any warning that terminals, logs, or session captures may retain the credential. That behavior creates a clear secret-handling flaw because anyone with access to output artifacts can reuse the token.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The report command is configured with include_secrets=True and can emit the report in JSON, Markdown, table output, or write it to disk. If the generated report contains raw secret findings or sensitive file locations, the tool turns detected secrets into a broader disclosure surface through console output and persisted artifacts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill manifest emphasizes auditing configs, scanning secrets, managing access, and generating security reports. While inspecting token strength fits that scope, this function actively generates/replaces live authentication tokens and persists them to config, which is a stronger operational credential-management capability than the surrounding documentation suggests for a security-audit tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The token rotation path overwrites the authentication config immediately and without any confirmation, backup, or transactional safety checks. In a security-management skill, silent credential replacement is risky because an accidental or unauthorized invocation can disrupt authentication, lock out legitimate services, or replace a valid token with an attacker-chosen one if the function is exposed through automation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file states that language is auto-detected based on system locale, which imposes a locale-driven behavior without explicit user choice. The policy allows locale handling when the user is offered a language choice or opts in; here, although supported languages are listed, the default behavior still forces automatic selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.