Back to skill

Security audit

Openclaw New Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent OpenClaw/Feishu setup purpose, but it asks users to provide a Feishu App Secret through chat and documents mutable install commands, which warrant Review before installation.

Install only if you are comfortable with the skill modifying ~/.openclaw and OpenClaw gateway configuration. Do not paste a real Feishu App Secret into ordinary chat unless you accept that it may be retained in transcripts or logs; prefer entering it locally or through a secret manager, restrict file permissions on openclaw.json and backups, and rotate the secret if it was already exposed. Prefer a pinned, reviewed installer version rather than clawhub@latest.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
README.md:43
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md:43
Vulnerability Type: Unsafe dependency retrieval and execution
Risk Level: High

Vulnerable Code

bash
npx clawhub@latest install openclaw-new-agent

Technical Analysis

The installation instructions execute the mutable latest version of a third-party package through npx. This can download and immediately execute package code without pinning an audited version or verifying a checksum, signature, lockfile, or package integrity value.

Because the latest distribution tag can be changed after this Skill has been reviewed, the code executed by users may differ from the code considered during the audit. A compromise of the package publisher account, registry, package repository, or release process could therefore turn this documented installation command into an arbitrary-code execution channel.

Attack Path

  1. An attacker compromises the clawhub package, its publisher account, or its release pipeline.
  2. The attacker publishes a malicious version and assigns it to the latest distribution tag.
  3. A user follows the documented installation command.
  4. npx retrieves the attacker-controlled release.
  5. Package lifecycle hooks or CLI initialization code execute with the invoking user's privileges.
  6. The malicious package can access files, credentials, environment variables, and services available to that user.

Impact Assessment

Successful exploitation can provide arbitrary code execution under the account running the installation command. In the intended OpenClaw environment, this may expose OpenClaw configuration, Feishu application credentials, agent workspaces, conversation data, gateway logs, and other files accessible to the user. If the command is run by a privileged account, the impact expands to all resources available to that account.

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed version.
  • Publish and document a cryptographic integrity hash or signed release.
  • Verify package provenance and registry identity before installation.
  • Disable or separately review package lifecycle scripts where feasible.
  • Run installation using a dedicated, least-privileged account.
  • Document a trusted version-upgrade process that requires review before changing the pinned version.
  • Consider distributing the Skill as a signed, immutable archive rather than relying on a mutable registry tag.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:48
Finding

Feishu Application Secret Is Collected Through a Chat Channel

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:48-53
Additional Locations: SKILL.md:134-138, README.md:78-82
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: High

Vulnerable Code

The workflow explicitly requests the following credential through the agent interaction:

text
App ID & App Secret

The subsequent configuration template stores the supplied value directly in configuration:

json
{
  "enabled": true,
  "appId": "cli_xxx",
  "appSecret": "xxx",
  "domain": "feishu",
  "connectionMode": "websocket"
}

Technical Analysis

The Skill directs the AI agent to request a Feishu App Secret from the user through the conversational interface. Chat is not established as a protected secret-entry mechanism. The credential may be retained in Feishu message history, OpenClaw conversation state, model-provider telemetry, debugging output, backups, or audit logs.

The workflow does not define redaction controls, secure local prompting, secret-manager integration, transcript cleanup, credential rotation, or retention restrictions. It also demonstrates direct plaintext placement in openclaw.json. Consequently, both credential collection and storage increase the number of locations from which the secret may be recovered.

The App Secret is intentionally required for bot configuration, but transmitting it through chat is not necessary. The agent can instead request that the user enter it locally into a protected prompt or secret store and return only a non-sensitive reference.

Attack Path

  1. The agent asks the user to provide the Feishu App ID and App Secret.
  2. The user sends the App Secret through the chat interface.
  3. The secret is retained in one or more message histories, agent states, logs, backups, or telemetry systems.
  4. An attacker or unauthorized operator gains read access to any retained copy.
  5. The attacker extracts the ...[truncated 1033 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not request application secrets through Feishu chat or any model conversation.
  • Collect the secret through a local, non-echoing terminal prompt or an approved secret-management system.
  • Pass only a secret reference or environment-variable name to the agent.
  • Prevent secrets from being included in prompts, responses, logs, telemetry, and persistent conversation memory.
  • Store the secret in an operating-system credential store or dedicated secrets manager rather than directly in general-purpose JSON configuration.
  • If plaintext configuration is unavoidable, restrict the configuration and backup files to the owning account, such as with mode 0600.
  • Ensure backup files inherit equally restrictive permissions and define a secure retention and deletion policy.
  • Add automatic redaction for appSecret values in diagnostic output.
  • Instruct users to rotate the App Secret immediately if it has already been sent through chat or exposed in logs.
  • Apply least-privilege Feishu scopes so that credential compromise has limited impact.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly instructs users to send the Feishu App ID and App Secret to the robot, but gives no warning about secret handling, storage, logging, model access, or exposure to third-party services. This is dangerous because bot conversations may be logged, retained, inspected by models/tools, or leaked through misconfiguration, leading to credential compromise and takeover of the associated bot integration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document's operational guidance and section content are written in Chinese, including the core project overview and file descriptions, but it does not offer an alternative language or indicate that Chinese is a required locale for a region-specific skill. This can violate a language/locale policy where user-facing skill guidance should not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README tells users to run npx clawhub@latest install openclaw-new-agent, which pulls and executes the latest published package at install time without pinning a specific version or integrity hash. That creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious version is published, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This section says OpenClaw will automatically create backups, create a workspace, and modify configuration files. Although the actions are described, there is no explicit user warning that the skill will alter local files and gateway configuration, which can affect system behavior if misapplied.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The usage instructions prescribe a Chinese prompt for interacting with the AI assistant and the entire skill description is written as if Chinese is the required interaction language. There is no indication that users may choose another language or that the Chinese-only flow is a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The USER.md template hard-codes Timezone: Asia/Shanghai (GMT+8) as the default user profile value. This is a natural-language locale policy issue because it imposes a specific locale on users without opt-in, and the document does not explain that the skill is limited to a China-specific deployment context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description at L04 is entirely in Chinese and presents the skill in a single language without indicating that users may choose another language or that the skill is intentionally region-specific. Under the policy rule for language or locale constraints, this can be a locale-policy concern when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.