Back to skill

Security audit

Agent Optimizer by Drakon Systems

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local configuration auditor with sensitive but purpose-aligned access and opt-in persistence/network features.

Install only if you want a third-party CLI to inspect local agent configuration, workspace skills/hooks/extensions, and optional fleet OpenClaw configs. Review any proposed fixes before applying them, use dry-run first, and enroll in monitoring only if you accept the daily summary POST and cron entry.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- ~/.openclaw/cron/jobs.json
      - ~/.openclaw/exec-approvals.json
      - ~/.openclaw/workspace/ (skills, hooks, extensions scanned for patterns)
      - ~/.claude/settings.json and project .claude/settings.json
      - ~/.claude.json (MCP server config)
      - ~/.claude/CLAUDE.md and project CLAUDE.md
    network:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
- ~/.openclaw/cron/jobs.json
      - ~/.openclaw/exec-approvals.json
      - ~/.openclaw/workspace/ (skills, hooks, extensions scanned for patterns)
      - ~/.claude/settings.json and project .claude/settings.json
      - ~/.claude.json (MCP server config)
      - ~/.claude/CLAUDE.md and project CLAUDE.md
    network:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
- Send any data off-machine during audit/scan/optimize (no telemetry, no analytics; the only off-machine sends are `activate`, `update`, and — if you explicitly enroll — the optional monitoring summary described below)
- Store or prompt for API keys, SSH keys, or provider credentials
- Modify any files unless `audit --fix` or `optimize` is run with a license (writes go through a transactional engine — multi-generation backups under `~/.agent-optimizer/backups/`, post-apply verification, and auto-rollback if the change would break the config)
- Write to Claude Code config — `settings.json` findings are surfaced as recommendations, never auto-applied

## Fleet SSH Audit

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
## Auto-Fix (`audit --fix`)

`audit --fix` applies the safe, unambiguous fixes the audit finds (licensed; preview
first with `--fix --dry-run`). Both `audit --fix` and `optimize` write through a
transactional engine: each apply takes a multi-generation backup under
`~/.agent-optimizer/backups/`, re-verifies the config after writing, and auto-rolls-back
if the change would break it. Restore any generation with `agent-optimizer rollback --list`

Static analysis

No suspicious patterns detected.