Back to skill

Security audit

Navil Shield

Security checks for vulnerabilities and agentic risk

Overview

This security skill is purpose-aligned, but it installs unpinned external software that rewrites all MCP tool routes and sends telemetry by default, so it needs manual review before installation.

Install only if you are comfortable letting Navil sit between OpenClaw and every wrapped MCP server. Prefer an isolated environment such as pipx or a virtual environment, verify the package provenance and version, review the dry-run config diff, opt out of telemetry with NAVIL_DISABLE_CLOUD_SYNC=true if desired, and confirm rollback works before relying on it.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:62
Finding

Unpinned Third-Party Package Installation Bypasses Environment Protections

Content
View full analysis
/dev/null || pip install navil ``` Verification is limited to: ```bash navil --version ``` The fallback installation repeats the same unsafe pattern: ```bash pip3 install navil --break-system-packages 2>/dev/null || pip3 install navil ``` ### Technical Analysis The Skill installs `navil` from the configured Python package index without specifying an exact version or validating a cryptographic hash. Consequently, the code installed during Skill execution can differ from the code that existed when the Skill was reviewed. The `--break-system-packages` option bypasses Python's externally managed environment protection and permits modification of an interpreter environment managed by the operating system. Redirecting standard error to `/dev/null` also conceals warnings and diagnostics from the first installation attempt. The submitted project does not contain the `navil` package source or a lock file through which its implementation and transitive dependencies could be audited. The `navil --version` command confirms only that an executable is available; it does not establish package integrity or provenance. ### Attack Path 1. An attacker compromises the package-index account, distribution artifact, dependency, or package source used to resolve `navil`. 2. A user activates the Skill and follows its first-time setup instructions. 3. `pip` retrieves the current unpinned package and its transitive dependencies. 4. Package installation hooks or subsequently invoked package code execute with the privileges of the user running the agent. 5. The compromised package can access files and environment variables available to that user, alter the Python environment, or tamper with the OpenClaw configuration ...[truncated 592 chars]
Remediation
View remediation
/dev/null` so installation failures and security warnings remain visible. 5. Configure an explicitly trusted package index and verify package publisher provenance. 6. Bundle or reference auditable source corresponding exactly to the installed release. 7. Verify package integrity before invoking any `navil` command, rather than relying only on `navil --version`. ]]>

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:87
Finding

Unaudited Proxy Is Inserted into Every MCP Tool-Call Path with Telemetry Enabled by Default

Content
View full analysis
--dry-run ``` After confirmation, it performs the modification: ```bash navil wrap ``` It then instructs the agent to characterize the result as follows: ```text Your original config has been backed up automatically. Every MCP server is now monitored by Navil's security proxy. ``` Telemetry is enabled unless the user explicitly opts out: ```yaml - name: NAVIL_DISABLE_CLOUD_SYNC required: false description: "Set to 'true' to disable anonymous telemetry sharing. Default: false (sharing enabled)." ``` The documented telemetry destination and opt-out mechanism are: ```text - Destination: `https://navil-cloud-api.onrender.com/v1/telemetry` (see source: `navil/cloud/telemetry_sync.py`) - Opt-out: set `NAVIL_DISABLE_CLOUD_SYNC=true` to stop all telemetry - Full audit: inspect `navil/cloud/telemetry_sync.py` in the repo to see exactly what is collected ``` ### Technical Analysis Wrapping every MCP server inserts the externally installed `navil` package into a privileged interception point through which subsequent MCP tool calls pass. Although this behavior is related to the declared security purpose, it substantially expands the trust placed in an implementation that is not included in the audited project. The Skill states that only anonymized threat metadata is transmitted and that raw arguments, responses, file contents, prompts, and user data are excluded. However, the cited implementation file, `navil/cloud/telemetry_sync.py`, is not included in the submitted artifact. The audit therefore cannot verify the filtering, hashing, endpoint authentication, failure behavior, or exact information sent. Telemetry is opt-out rat ...[truncated 1518 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata declares activation on very broad terms like 'security', 'prompt injection', and 'data leaks', which are common topics in benign conversations. This can cause the skill to activate outside narrowly intended contexts and steer the agent toward installing software, scanning configs, or altering MCP setups when the user may have only asked for general advice, increasing the risk of unnecessary tool use and configuration changes.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'When to Use This Skill' section includes ambiguous phrases such as 'check my security' and an automatic trigger for newly added MCP servers or skills, creating a persistent tendency to invoke this skill without clear user intent. In context, this is more dangerous because the skill recommends installing a package, wrapping all MCP servers, and running security tooling, so over-activation can lead to unwarranted system changes and over-collection of sensitive configuration context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.