Back to skill

Security audit

Safe Exit Planner

Security checks for vulnerabilities and agentic risk

Overview

The skill's safety-planning content is relevant, but it requests broad filesystem access it does not need and uses an unpinned npx install path.

Install only if you are comfortable granting this skill local filesystem capability and using an installer that is not pinned to a reviewed version. A safer release should remove filesystem access unless it adds a clearly scoped, user-approved file feature, and should pin or verify its install command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:13
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13
Vulnerability Type: Excessive tool permission
Risk Level: Medium

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install safe-exit-planner"

Technical Analysis

The skill declares access to the filesystem tool even though its documented behavior is limited to presenting safety-planning instructions, crisis contacts, and external resources. No described workflow requires reading, creating, modifying, or deleting local files.

Granting a general filesystem capability violates the principle of least privilege. If untrusted conversation content, prompt injection, or subsequently modified skill instructions influence the agent, the unnecessary capability could be used to request access to files unrelated to the skill's legitimate purpose. This is especially sensitive because users invoking this skill may have safety plans, communications, or evidence of abuse stored on the device.

The declaration alone does not prove that files are currently accessed, but it creates an avoidable privilege boundary that can be exploited in a compromised execution context.

Attack Path

  1. A user installs or activates the skill.
  2. The runtime grants the agent the declared filesystem tool.
  3. Attacker-controlled conversation content, injected instructions, or a compromised future skill revision directs the agent to use that tool.
  4. The agent reads or modifies files outside any legitimate safety-planning workflow.
  5. Sensitive local information could be exposed, corrupted, or deleted, subject to the filesystem tool's actual sandbox and operating-system permissions.

Impact Assessment

Exploitation could provide access to files available to the agent process or filesystem sandbox. Potential effects include unauthorized disclosure of local documents, modification of user files, and exposure of h ...[truncated 168 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from openclaw.requires.tools because the documented skill functionality does not require local file access.
  • If future functionality legitimately requires storage, replace general filesystem access with a narrowly scoped interface restricted to a dedicated application directory.
  • Require explicit user confirmation before reading or writing any file.
  • Enforce canonical-path validation and deny path traversal, symbolic-link escapes, and access outside the approved directory.
  • Separate read and write permissions and grant only the minimum operation required.
  • Avoid persisting safety plans, abuse evidence, conversation transcripts, or other sensitive information unless the user explicitly requests it and secure storage is available.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned npx Package Creates a Mutable Supply-Chain Execution Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 14
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install safe-exit-planner"

Technical Analysis

The installation command invokes clawhub through npx without pinning a package version or integrity digest. Depending on the local package state and npm configuration, npx can retrieve executable package content from a configured registry at installation time.

Because the resolved package is mutable, the command executed by users may differ from the package version considered during this audit. Registry compromise, package-account takeover, dependency compromise, or a malicious future release could therefore introduce arbitrary code into the installation path. Package lifecycle scripts and transitive dependencies may further expand this execution surface.

This is a supply-chain weakness rather than evidence that the current clawhub package is malicious.

Attack Path

  1. An attacker compromises the package publisher, registry distribution path, or one of the package's dependencies, or publishes a malicious future release.
  2. The attacker adds malicious executable code or a lifecycle script to the version resolved by npx.
  3. A user runs npx clawhub install safe-exit-planner.
  4. npx downloads or resolves the mutable package version from the configured registry.
  5. The compromised package executes with the privileges of the invoking user.
  6. The payload could access user-readable data, alter local files, install additional components, or perform network activity, subject to operating-system and sandbox controls.

Impact Assessment

Successful exploitation could result in arbitrary code execution under the account running the installation command. The resulting scope may include access to ...[truncated 293 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a reviewed, immutable version, for example npx clawhub@<verified-version> install safe-exit-planner.
  • Prefer installation through a lockfile-backed package workflow with integrity hashes.
  • Configure and document the trusted package registry rather than relying on unspecified local registry settings.
  • Verify package provenance, signatures, and published integrity metadata before execution.
  • Review transitive dependencies and lifecycle scripts for the pinned release.
  • Disable package lifecycle scripts where installation functionality does not require them.
  • Avoid running the installation command with administrative privileges.
  • Establish a controlled update process so a new package version is audited before changing the pin.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill metadata includes an install command using npx clawhub install safe-exit-planner without pinning a specific package version. Because npx resolves and executes code dynamically, a future malicious or compromised package release could run unexpected code during installation, creating a supply-chain execution risk for anyone installing the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.