Back to skill

Security audit

node-connection-doctor

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a node troubleshooting tool, but it asks for an unused persistence-capable cron permission and documents confirmation-free repair mode for system-changing fixes.

Review before installing. The core diagnostic behavior is coherent, but remove or question the system:cron permission unless scheduled checks are explicitly needed, and avoid using any silent repair mode until the skill clearly previews changes, supports rollback or backup guidance, and confirms before token resets or gateway restarts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
HOOK.md:8
Finding

Unnecessary Scheduled-Task Permission Violates Least Privilege

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/utils.js:13
Finding

Diagnostic Report Generator Inserts Unescaped Data into HTML

Content
View full analysis
#+=|{}.!\\-])/g, '\\$1'); } ``` ```js results.forEach(r => { const statusClass = r.ok ? 'ok' : 'error'; html += `
`; html += `${r.step}
`; if (r.ok) { html += `✅ Status: Healthy`; if (r.output) html += `
text
${escapeMarkdown(r.output)}
`; } else { html += `❌ Error: ${escapeMarkdown(r.error)}`; if (r.details) html += `
text
${escapeMarkdown(r.details)}
`; } html += `
`; }); ``` ### Technical Analysis `generateReportHTML()` inserts diagnostic fields directly into an HTML document. The helper named `escapeMarkdown()` escapes Markdown punctuation but does not perform HTML encoding. In particular, it does not safely encode `<`, `>`, `&`, single quotes, or double quotes. Consequently, values in `r.step`, `r.output`, `r.error`, or `r.details` can be interpreted as HTML rather than displayed as text. If an attacker can influence gateway output, error output, or another result passed to this helper, they can inject elements or scripts into the generated report. The included entry script does not currently call `generateReportHTML()`, so exploitation requires this exported helper to be used by the advertised HTML-report workflow or another caller. This limits current reachability but does not make the report generator safe. ### Attack Path 1. An attacker influences diagnostic output consumed by the report generator. For example, a compromised local `openclaw` executable or gateway component returns a value containing an HTML payload such as ``. 2. A caller passes that output through the `results` collection to `generateReportHTML()`. 3. The function applies Markdown ...[truncated 743 chars]
Remediation
View remediation
/g, '>') .replace(/"/g, '"') .replace(/'/g, '''); } ``` 2. Apply `escapeHTML()` to `r.step`, `r.output`, `r.error`, and `r.details` before interpolation. 3. Keep Markdown and HTML escaping as separate functions because they protect different output contexts. 4. Prefer constructing reports with DOM APIs and assigning untrusted values through `textContent` instead of concatenating HTML strings. 5. Add tests using payloads containing `
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (26)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is written entirely in Chinese, including the final instruction to the user, with no indication that other languages are supported or that Chinese is required for a region-specific purpose. That creates a natural-language locale policy concern because it implicitly constrains user interaction to one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file uses a single language throughout and does not indicate that Chinese is optional, user-selected, or required for a justified regional context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is written in Chinese and presents the behavior and marketing copy in a single language, with no indication that users can choose another language or that the skill is intended only for a Chinese-speaking region. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The silent mode enables auto_confirm=true and states that no confirmation prompt is shown before executing repairs. Given the skill's described ability to reset tokens, restart gateways, and restore defaults under admin/root permissions, this meaningfully increases the chance of unintended or automated disruptive changes without human validation.

Content

Scanner excerpt · README-ClawHub.md (reported line 127)May include surrounding context.

3️⃣ 静默模式 (自动化)

bash
openclaw skill run node-connection-doctor --input '{"mode": "fix", "auto_confirm": true}'

注意: 不显示确认提示,直接执行。适合自动化脚本。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises a silent repair mode that executes fixes immediately with administrator/root privileges and explicitly states it will not show a confirmation prompt. In the context of a tool that can reset tokens, rebind nodes, restart services, and restore default configs, this creates a real risk of unintended destructive configuration changes without adequate warning about rollback, backups, or side effects.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CLAUHUB_FORM_HELPER.html (reported line 88)May include surrounding context.

html
|---------|---------|
| 🔍 **Auto Diagnosis** | Checks 20+ common issues (gateway status, pairing config, Tailscale, firewall) |
| 📋 **Fix Recommendations** | Provides exact CLI commands for your specific error |
| ⚡ **One-Click Fix** | (Optional) Automatically executes safe fixes (reset token, restart gateway) |
| 📊 **Diagnostic Report** | Exportable summary for support or future reference |

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

md
|---------|---------|
| 🔍 **Auto Diagnosis** | Checks 20+ common issues (gateway status, pairing config, Tailscale, firewall) |
| 📋 **Fix Recommendations** | Provides exact CLI commands for your specific error |
| ⚡ **One-Click Fix** | (Optional) Automatically executes safe fixes (reset token, restart gateway) |
| 📊 **Diagnostic Report** | Exportable summary for support or future reference |

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises system-changing repair actions such as resetting pairing tokens, rebinding the gateway, and restarting services, but the description does not clearly foreground the operational and security consequences of those actions. In a troubleshooting skill for node connectivity, such actions can disrupt service, invalidate existing trust relationships, or cause unintended configuration changes if users do not understand what will be modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents the FAQ content in Chinese beginning at the main section heading, and the rest of the user-facing guidance continues in that language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly justified.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CLAUHUB_FORM_HELPER.html (reported line 126)May include surrounding context.

html
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CLAUHUB_FORM_HELPER.html (reported line 170)May include surrounding context.

html
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README-ClawHub.md (reported line 117)May include surrounding context.

md
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 69)May include surrounding context.

md
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/validation-guide.md (reported line 31)May include surrounding context.

md
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/test-run.js (reported line 11)May include surrounding context.

js
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills.json (reported line 47)May include surrounding context.

json
mode: process.argv[2] || 'diagnose', // diagnose | fix
  verbose: true,
  dry_run: process.argv.includes('--dry-run'),
  auto_confirm: false
};

// 直接运行诊断逻辑 (简化版,供截图用)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description 'Automatically diagnose and fix OpenClaw node connection issues' is broad and does not define clear trigger conditions, operational boundaries, or limits on what 'fix' actions may be taken. In a troubleshooting skill that may execute repair actions, vague activation and scope increase the risk of unintended invocation or user misunderstanding about potentially system-affecting behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest sells a 'Full Repair Service' with 'automatic fix execution' but does not include an explicit warning that the skill may modify system or network configuration. In the context of node connectivity, automated fixes could alter gateways, networking, or Tailscale-related settings, making the absence of prominent warning and guardrails materially risky.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · skills.json (reported line 31)May include surrounding context.

json
price: 50
    name: Enterprise API
    period: monthly
    description: Unlimited API access for businesses
documentation: SKILL.md
scripts:
  - scripts/diagnose.js

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This HTML file presents the skill publishing helper with Chinese-only UI text such as "发布表单" and later Chinese instructions, while the embedded skill content itself is largely English. Because there is no opt-in or documented locale constraint, the file effectively imposes a specific language/locale on users, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file is primarily written in Chinese but includes substantial English interface text and testing language such as output labels and the support note. There is no statement that the skill or guide supports multiple languages or that English is required, so it appears to impose mixed-language usage without explicit user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's title, status messages, errors, and recommendations are all presented in Chinese, including user-facing console output. This imposes a specific language/locale on all users without any opt-in or documented regional justification, which matches the language-policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file includes user-facing natural-language descriptions and comments in Chinese (for example the title and operation descriptions) while other interaction text is in English. Because the skill does not offer a language/locale selection or document that it is intended for a specific locale, this may violate language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file contains user-facing strings in both Chinese and English, including the title and status messages, but provides no indication that language selection is optional or region-specific. This can violate language/locale policy expectations when a skill imposes or assumes a language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/diagnose.js:17

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/fix.js:27