Back to skill

Security audit

Clawpage

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent purpose, but its defaults can publish sensitive conversation internals such as reasoning, tool outputs, images, and local details.

Review carefully before installing. Use messages-only export by default, avoid including reasoning, tool calls, tool results, images, paths, or event metadata unless you explicitly need them, inspect the full generated YAML before committing or pushing, and prefer pinned/local versions of the clawpage npm tools.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/setup.md:39
Finding

Unpinned npm Packages Are Downloaded and Executed

Content
View full analysis
| --exclude-process=] ``` ### Technical Analysis The Skill instructs the Agent to invoke npm packages through `npx` without specifying an exact version, lockfile, or integrity checksum. Package resolution can therefore retrieve a release that differs from the one available when the Skill was audited. Both package runtime code and applicable npm lifecycle scripts execute with the privileges of the Agent user. The `clawpage` parser is also given direct access to a local session log and a project output directory. Consequently, compromise of the npm package, publisher account, registry resolution path, or a future package release could turn an expected conversion operation into arbitrary local code execution. This finding does not establish that either referenced package is currently malicious. The vulnerability is the mutable and unverified dependency execution mechanism. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or the relevant package-resolution path. 2. The attacker publishes a malicious release under the package name used by the unversioned `npx` command. 3. A user invokes the Skill for project setup or session conversion. 4. `npx` resolves and downloads the mutable package release. 5. Package lifecycle or runtime code executes under the Agent user's account. 6. The malicious code can access resources available to that account, including session logs, repository content, environment variables, Git credentials exposed to the process, and w ...[truncated 551 chars]
Remediation
View remediation
{repoName} --dir {localDir} npx --yes clawpage@ parse {sessionPath} \ -o {projectDir}/chats/.tmp/{timestamp}.yaml ``` 2. Prefer installing dependencies from a committed lockfile and running the locally locked binary rather than resolving packages dynamically during every invocation. 3. Verify package provenance, expected publisher identity, source repository, and package integrity before execution. 4. Use npm integrity metadata or an equivalent checksum-verification mechanism where practical. 5. Disable or isolate lifecycle scripts if they are unnecessary. 6. Run conversion in a restricted environment with access only to the selected session and destination directory. 7. Avoid exposing unrelated credentials and sensitive environment variables to the package process. 8. Document a controlled dependency-update and security-review procedure. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/platforms/openclaw.md:43
Finding

Public Conversation Exports Include Sensitive Process Data by Default

Content
View full analysis
Remediation
View remediation
parse {sessionPath} \ -o {projectDir}/chats/.tmp/{timestamp}.yaml \ --exclude-process=all ``` 2. Require explicit, granular opt-in before including any of the following: - Reasoning or thinking blocks - Tool calls and arguments - Tool results - Session events and working directories - Images or binary content 3. Keep `visibility: private` throughout extraction, review, and commit. Change it to `public` only after a separate publication confirmation. 4. Present a structured summary of sensitive content before committing, including the number of tool results, paths, URLs, images, and potential secret matches. 5. Apply automated secret scanning to the completed YAML file using patterns for common credentials, entropy-based detection, private keys, authentication headers, and provider-specific tokens. 6. Redact or normalize local paths, private network details, repository remotes, environment values, and working-directory metadata by default. 7. Require a final diff or complete preview after redaction and before both commit and push. 8. Treat reasoning traces and tool results as high-sensitivity data even when no conventional secret pattern is detected. 9. Clearly warn that committing a file preserves sensitive content in Git history even if it is removed in a later commit. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The content fidelity rule requires verbatim copying of all message text, tool arguments, and tool results into a public page. Tool inputs and outputs frequently contain secrets, filesystem paths, API responses, tokens, PII, or other sensitive operational data, so verbatim publication creates a direct exfiltration path. Because the skill is specifically for external publication, the context makes this more dangerous, not less.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly instructs publishing full assistant thinking/reasoning blocks in a public share format. Internal reasoning can contain sensitive intermediate analysis, hidden safety logic, or traces of user-provided secrets and should not be exposed externally. In a skill whose purpose is public sharing of conversations, this materially increases disclosure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly instructs platform authors to extract and preserve thinking blocks as full reasoning text and to 'never skip or summarize' them. In an agent-conversation publishing skill, this creates a direct pathway for exposing hidden chain-of-thought, sensitive intermediate reasoning, secrets echoed during deliberation, or policy/internal metadata that should not be shared publicly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guidance explicitly tells the agent to extract and publish full reasoning traces, verbatim tool arguments, tool results, and embedded images when converting sessions to public web pages. That creates a direct risk of disclosing sensitive internal chain-of-thought, secrets present in tool inputs/outputs, file paths, tokens, personal data, or other confidential material far beyond what is necessary to share a conversation transcript.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to publish conversation content to a public web page, but the top-level description does not clearly warn users that exported chats may become publicly accessible and could expose sensitive information. Although later workflow steps include redaction guidance, users may invoke the skill based on the short description alone and consent to sharing before understanding the privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs writing accumulated chat output to a temporary markdown file on disk, but provides no warning, consent step, or retention guidance despite handling full session transcripts. Because this skill is specifically for sharing conversations publicly, the session data is likely to contain sensitive prompts, tool outputs, secrets, or personal data, and persistent local copies increase the chance of accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The jq preprocessing step converts session JSONL into a plain-text intermediate file containing extracted message text, thinking, and tool-call data, which can make secrets and sensitive context easier to read, search, and exfiltrate. In the context of a conversation-sharing skill, this is especially dangerous because it normalizes broad extraction of potentially private content without warning the user that another persistent derivative file is being created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template mandates verbatim inclusion of sensitive-prone artifacts without any caution, filtering, or redaction guidance. That omission creates an unsafe default where users or agents may publish confidential tool data and image content unintentionally. Given the skill's purpose of creating public web pages, the lack of warning or safeguards substantially elevates exposure risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Inlining base64 image payloads in a public export can leak screenshots or embedded visual data that may contain credentials, personal information, or proprietary content. Base64 encoding is not protection; it merely repackages the raw image bytes for easy redistribution. In a publishing workflow, this increases the chance of accidental disclosure at scale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented default is to include 'Everything,' explicitly including thinking, tool calls, and other process content when generating a public share page. That exceeds the stated high-level purpose of sharing conversations and can disclose hidden reasoning, tool arguments, environment details, and other internal artifacts that users may not realize will be published.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defaults to maximum-content export without an explicit privacy warning, making accidental disclosure likely. In this context, the danger is elevated because the output is meant to become a public web page, so exposed chain-of-thought, tool parameters, and tool results could be irreversibly published or indexed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs use of npx clawpage without pinning a specific package version, which allows whatever version is currently published to be fetched and executed. In a workflow that publishes conversation data, a compromised or malicious package update could execute arbitrary code or exfiltrate sensitive session contents during conversion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This example also uses unpinned npx clawpage, so execution depends on the latest registry state rather than a reviewed artifact. Because the command processes chat logs that may contain secrets, an upstream package compromise could expose highly sensitive content or run arbitrary code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx clawpage without version pinning creates a supply-chain risk because the tool may resolve to a different package version at each run. In this skill's context, that is more dangerous because the tool is given access to full session logs intended for public sharing, increasing the blast radius of any malicious package behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This invocation repeats the same unpinned package execution pattern, leaving users exposed to arbitrary upstream changes. Since the workflow transforms and prepares conversational records for publication, the command may handle private reasoning, tool arguments, and other sensitive artifacts that a compromised package could steal.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The final example continues to recommend unversioned npx execution, preserving the same remote-code and supply-chain exposure. Repetition across multiple examples increases the chance users will copy unsafe commands directly into sensitive environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs extraction of full reasoning traces without any warning that such content may contain sensitive internal deliberation or confidential information. In the context of a tool designed to publish conversations to a public URL, omission of a warning and consent gate materially increases the chance of accidental oversharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to create repositories, modify config files, push commits, and enable deployment to public hosting, but it does not include an explicit safety checkpoint warning that these actions change local and remote state and may publish sensitive conversation content. In this skill's context, that omission is more dangerous because the purpose is to share AI conversations as public web pages, so accidental disclosure and unintended irreversible changes are realistic outcomes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The setup instructs users to run npx create-clawpage {repoName} --dir {localDir} without pinning a specific package version or verifying provenance. That causes execution of whatever package version is current at runtime, creating a supply-chain risk where a compromised or maliciously updated package could run arbitrary code on the user's machine during project scaffolding.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The truncation step creates yet another derived file from session content and does so without any notice about persistent storage or the risk that the retained tail of the conversation may still contain highly sensitive recent data. Since the last 200 lines often capture the most recent and operationally sensitive exchange, this derived artifact can expose exactly the content most likely to include credentials, debugging output, or confidential instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.