Back to skill

Security audit

Agent Council

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its stated purpose, but it needs review because its scripts can generate unsafe shell commands and make broad OpenClaw, Discord, workspace, and cron changes.

Review before installing. Only run it in an OpenClaw environment where you are comfortable letting it read Discord bot credentials, change gateway config, restart the gateway, create or rename Discord channels, write agent workspaces, and optionally add recurring cron jobs. Avoid copying generated config.patch commands when channel context or existing prompts may contain untrusted text, and do not use the workspace rewrite option on directories containing untrusted symlinks or sensitive Markdown files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup_channel.py:164
Finding

Shell Command Injection Through an Unescaped Channel Context

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rename_channel.py:154
Finding

Shell Command Injection Through an Unescaped Existing System Prompt

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rename_channel.py:87
Finding

Workspace Boundary Bypass Through Symbolic-Link File Writes

Content
View full analysis
/path/to/external/file.md ``` 2. The external target is writable by the user and contains a matching old channel-name reference. 3. The user runs: ```text rename_channel.py --workspace workspace ... ...[truncated 1066 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (22)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · README.md (reported line 314)May include surrounding context.

})

text

### Send Messages to Agents

**Direct communication:**
```typescript

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 433)May include surrounding context.

})

text

### Send Messages to Agents

**Direct communication:**
```typescript

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · README.md (reported line 394)May include surrounding context.

text

**4. Agent-to-agent communication:**
Agents can send messages to each other:
```typescript
// In Watson's context
sessions_send({

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 513)May include surrounding context.

text

**4. Agent-to-agent communication:**
Agents can send messages to each other:
```typescript
// In Watson's context
sessions_send({

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description is substantially broader than the code. The code does perform a subset of Discord channel organization tasks for OpenClaw, but it is specifically limited to renaming one Discord channel, checking a related config field, and updating workspace references. It does not provide functionality for creating autonomous AI agents, setting up multi-agent systems, or general-purpose channel management. This is a material description-behavior mismatch because the primary declared purpose overstates and mischaracterizes the implemented capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description claims a broad, complete toolkit for both autonomous AI agent creation and Discord channel management. The supplied code only implements Discord channel setup: it reads local config, obtains a Discord bot token and guild ID, checks whether a channel exists, optionally creates it, and generates a gateway config patch containing the provided context as a system prompt. There is no functionality related to creating autonomous AI agents or setting up multi-agent systems. While Discord channel organization is accurately represented, the overall declared purpose materially overstates the code’s capabilities and primary scope.

Content

No source excerpt is available for this finding.

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 470)May include surrounding context.

md
### Finding Discord IDs

**Enable Developer Mode:**
- Settings → Advanced → Developer Mode

**Copy IDs:**

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 301)May include surrounding context.

md
### Finding Discord IDs

**Enable Developer Mode:**
- Settings → Advanced → Developer Mode

**Copy IDs:**

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 680)May include surrounding context.

md
1. **Organize channels in categories** - Group related agent channels
2. **Use descriptive channel names** - Clear purpose from the name
3. **Set specific system prompts** - Give each channel clear context
4. **Document agent responsibilities** - Keep SOUL.md updated
5. **Set up memory cron jobs** - For agents with ongoing work
6. **Test agents individually** - Before integrating into team

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/rename_channel.py (reported line 109)May include surrounding context.

python
try:
        prompt = config['channels']['discord']['guilds'][guild_id]['channels'][channel_id].get('systemPrompt', '')
        if old_name in prompt:
            return prompt
    except (KeyError, TypeError):
        pass
    return None

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 16)May include surrounding context.

md
- Optional cron job setup

**Discord Channel Management:**
- Create Discord channels via API
- Configure OpenClaw gateway allowlists
- Set channel-specific system prompts
- Rename channels and update references

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly promotes a 'Health tracking agent' and 'wellness monitoring' but provides no warning about handling sensitive personal or health data, retention, access controls, or regulatory/privacy considerations. In a multi-agent system with Discord bindings and memory logs, this omission can lead users to store or transmit sensitive health information in insecure channels or files.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and instructs use of capabilities that modify files, read environment/configuration, and perform network/API actions, but it declares no explicit tool scope or permission boundaries. In a skill that can patch gateway config, restart services, and call Discord APIs, missing scope disclosure increases the chance of over-privileged execution and unsafe invocation by users or agents.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 489)May include surrounding context.

md
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)

#### 2. Run Creation Script

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)

#### 2. Run Creation Script

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 318)May include surrounding context.

md
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)

#### 2. Run Creation Script

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes automation that creates files, updates gateway configuration, and restarts the gateway, but it does not present a prominent warning about those side effects before operational steps. This omission can cause users or calling agents to trigger disruptive or persistent system changes without informed consent or pre-change review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Discord setup and rename workflows perform live API changes and may update workspace files, but the documentation does not foreground these effects as operationally risky actions. That creates a real risk of unintended production changes, data churn, or confusing file rewrites when used by an autonomous agent or inattentive operator.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script offers to create a recurring cron job that will automatically write to files under the agent workspace on an ongoing basis. Although it prompts once at setup time, it does not clearly communicate the persistence, frequency, and continued autonomous modification behavior as a security-relevant side effect, which can lead to unexpected file changes, data growth, or abuse if the agent/session later behaves unexpectedly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

This creates session persistence by registering an automated recurring task tied to the agent session, allowing the agent to keep acting and writing state over time without further per-run approval. In the context of an agent-management skill, persistence is expected functionality, but it still expands the attack surface because a compromised or misconfigured agent can continue operating, storing data, or consuming resources indefinitely.

Content

Scanner excerpt · scripts/create-agent.sh (reported line 294)May include surrounding context.

sh
echo -e "${YELLOW}📅 Memory System${NC}"
echo ""
echo "Would you like to set up a daily memory cron job for $NAME?"
echo "This will create a job that reviews and updates the agent's daily memory file."
echo ""
read -p "Create daily memory cron? (y/n): " -n 1 -r
echo ""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code searches all markdown files under the provided workspace and writes changes back to disk automatically when matches are found. Although progress is printed, there is no confirmation prompt or explicit disclosure in the script's top-level usage/docstring that running with --workspace will perform in-place edits across files.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 688)May include surrounding context.

md
## Requirements

**Bot Permissions:**
- `Manage Channels` - To create/rename channels
- `View Channels` - To read channel list
- `Send Messages` - To post in channels

Static analysis

No suspicious patterns detected.