Back to skill

Security audit

Skill Safety Scanner

Security checks for vulnerabilities and agentic risk

Overview

This is a local skill scanner, but it includes unsafe removal and persistent scheduling instructions that users should review carefully before installing.

Install only if you want a local audit helper and are prepared to review commands before running them. Do not use the raw `rm -rf` removal template as written; prefer the official uninstall command or a validated, canonical path. Avoid enabling the cron memory reporting unless you understand where findings are stored and how untrusted evidence is sanitized.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:94
Finding

Unsafe interpolation of skill names into destructive shell commands

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 94–102
Vulnerability Type: Command injection and unsafe path construction
Risk Level: High

Vulnerable Code:

bash
### 5. Optional: Auto-remove dangerous skills

If the user confirms, execute removal for DANGEROUS-rated skills:

```bash
# For each DANGEROUS skill named [skill-name]:
clawhub uninstall [skill-name] 2>/dev/null
rm -rf ~/.openclaw/workspace/skills/[skill-name]

Technical Analysis

The removal instructions place a skill name obtained from installed-skill metadata directly into shell commands. They do not require shell-safe argument passing, quoting, identifier validation, path canonicalization, or an end-of-options marker.

If an installed skill can have an attacker-controlled name containing shell metacharacters, whitespace, option-like prefixes, or path traversal sequences, mechanical substitution of that name into the documented commands can change their meaning. The rm -rf operation is especially dangerous because traversal components could cause the resolved target to leave the intended skills directory.

User confirmation does not eliminate this vulnerability: the user may approve removing a dangerous skill without recognizing that its displayed name changes the command or deletion target.

Attack Path

  1. An attacker causes a skill with a crafted name to be installed or otherwise represented in scanner output.
  2. The security audit classifies the skill as dangerous.
  3. The Agent follows the documented removal workflow and substitutes the discovered name for [skill-name].
  4. The shell interprets injected metacharacters or option-like content, or rm resolves traversal components outside the expected skill directory.
  5. Commands execute or files are recursively removed with the privileges of the Agent process.

This path depends on the surrounding platform permitting crafted skill identifiers and on the ...[truncated 513 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer a structured uninstall API that accepts a skill identifier as a discrete argument and does not invoke a shell.
  • Enforce a strict allowlist for skill identifiers, such as a narrowly defined set of letters, digits, hyphens, and underscores.
  • Reject identifiers containing path separators, traversal components, control characters, whitespace, shell metacharacters, or leading option prefixes.
  • Resolve the candidate deletion path canonically and verify that it is a direct child of the canonical skills directory before deletion.
  • Pass command arguments as an argument array rather than constructing a shell command string.
  • Use an end-of-options marker where supported.
  • Avoid exposing raw rm -rf commands. Implement deletion through a bounded removal routine that refuses symlinks and out-of-root targets.
  • Display both the validated identifier and canonical target path when requesting confirmation.

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:118
Finding

Untrusted scanner findings can be persisted into Agent memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 118–123
Vulnerability Type: Persistent storage of attacker-controlled content
Risk Level: Medium

Vulnerable Code:

bash
## Scheduling

To scan automatically after every new skill install, or on a daily schedule:

```bash
openclaw cron add --name "skill-safety-scanner:daily" --cron "0 3 * * *" \
  --prompt "Run the skill-safety-scanner skill and report findings to memory."

Technical Analysis

The scheduled prompt directs the Agent to write scanner findings into persistent memory. Those findings may contain skill names, file content, code snippets, and other evidence originating from untrusted installed skills.

The instructions do not require untrusted fields to be sanitized, bounded, escaped, structurally separated from instructions, or stored outside the Agent's instruction-bearing memory. Consequently, instruction-like text embedded in a malicious skill could be copied into persistent state and later interpreted as guidance rather than inert evidence.

The cron entry also causes this ingestion process to recur across sessions. The security concern reported here is the poisoning of persistent Agent memory rather than the disclosed scheduling feature by itself.

Attack Path

  1. An attacker publishes or installs a skill containing instruction-like text in its name, metadata, or source code.
  2. The scheduled security scan includes that attacker-controlled text in a finding or evidence snippet.
  3. The Agent follows the cron prompt and writes the raw or insufficiently sanitized finding into memory.
  4. A later Agent session loads or consults that persistent memory.
  5. The embedded text influences future reasoning, tool use, or security decisions if it is interpreted as an instruction.

Exploitation depends on the scanner reproducing attacker-controlled content and on the memory subsystem exposing stored findings as instruction-releva ...[truncated 427 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not write raw scanner findings or source snippets into instruction-bearing Agent memory.
  • Store reports in a dedicated structured file or security-report database that is treated exclusively as untrusted data.
  • Persist only normalized fields such as a validated skill identifier, finding ID, severity, file path, and line number.
  • Omit raw source snippets from long-term memory, or encode and escape them before storage.
  • Apply strict character and length limits to all attacker-influenced fields.
  • Clearly delimit stored evidence and label it as untrusted content that must never be executed or followed as instructions.
  • Require explicit user approval before enabling the recurring schedule or persisting any findings.
  • Use a fixed reporting routine that cannot alter prompts or memory rules based on scanned content.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate finding is a true issue for the same reason: it documents a forceful recursive deletion command aimed at a variable-derived filesystem path. In a security-scanning skill, bundling destructive cleanup instructions alongside analysis increases the chance users treat deletion as routine and execute it without adequate verification.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
Issue: [env-harvesting] Reads API keys and sends to external host
   Evidence: [filename]:[line] — [code snippet]
   Action: clawhub uninstall [skill-name]
           rm -rf ~/.openclaw/workspace/skills/[skill-name]

⚠️  WARN — [skill-name]
   Path: ~/.openclaw/workspace/skills/[skill-name]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicate finding is a true issue for the same reason: it documents a forceful recursive deletion command aimed at a variable-derived filesystem path. In a security-scanning skill, bundling destructive cleanup instructions alongside analysis increases the chance users treat deletion as routine and execute it without adequate verification.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
Issue: [env-harvesting] Reads API keys and sends to external host
   Evidence: [filename]:[line] — [code snippet]
   Action: clawhub uninstall [skill-name]
           rm -rf ~/.openclaw/workspace/skills/[skill-name]

⚠️  WARN — [skill-name]
   Path: ~/.openclaw/workspace/skills/[skill-name]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This duplicate finding remains valid because the workflow includes a force-delete command that could remove unintended files if path handling is unsafe. The context makes it somewhat more dangerous because the skill positions itself as a trusted safety tool, which may lower user skepticism toward destructive suggested commands.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

bash
# For each DANGEROUS skill named [skill-name]:
clawhub uninstall [skill-name] 2>/dev/null
rm -rf ~/.openclaw/workspace/skills/[skill-name]

Always show the command and ask for confirmation before removing anything.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This duplicate finding remains valid because the workflow includes a force-delete command that could remove unintended files if path handling is unsafe. The context makes it somewhat more dangerous because the skill positions itself as a trusted safety tool, which may lower user skepticism toward destructive suggested commands.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

bash
# For each DANGEROUS skill named [skill-name]:
clawhub uninstall [skill-name] 2>/dev/null
rm -rf ~/.openclaw/workspace/skills/[skill-name]

Always show the command and ask for confirmation before removing anything.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
- Does not send any data to external servers
- Does not modify any files without explicit confirmation
- Does not connect to the internet
- Does not access credentials or API keys
- Does not install anything
- Single SKILL.md file — inspect the full source above

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill metadata and top-level description emphasize a local scan/reporting function, but the documented workflow also includes destructive remediation commands and creation of a persistent scheduled task. This mismatch can mislead users about the skill’s actual capabilities and trust boundary, increasing the chance they approve file deletion or ongoing automation they did not expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation claims the skill does not modify files without explicit confirmation, yet it also instructs setting up automatic scheduled reporting to memory without any confirmation requirement in the workflow itself. That inconsistency can cause users to trust the skill as non-modifying while it actually establishes persistence or writes state indirectly.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL.md:75