Back to skill

Security audit

Openclaw Safety Guard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real OpenClaw health monitor, but it automatically installs dependencies, scans private local OpenClaw data, creates persistent reports, and sends notifications with several scoping and data-safety gaps.

Review before installing. Use a dedicated Feishu bot with least-privilege credentials, keep Feishu Drive upload disabled unless explicitly needed, run setup only where cron persistence and the first automatic scan are acceptable, and avoid scanning repositories or memory files that may contain secrets until report redaction and dashboard escaping are fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_dashboard.py:127
Finding

Stored Script Injection Through Unescaped Dashboard Data

Content
View full analysis
str: """Inject watchdog data and fix file:// compatibility.""" data_json = json.dumps(data, ensure_ascii=False, separators=(",", ":")) script_tag = f'' # crossorigin breaks file:// protocol (CORS), but type="module" is required for ES6 html = html.replace(' crossorigin', '') if "" in html: return html.replace("", f"{script_tag}\n", 1) return script_tag + "\n" + html ``` One source of externally controllable evidence is `scripts/scan_security.py:136-157`: ```python evidence = [] for label, regex in regex_rules: try: res = subprocess.run( ["git", "log", "-p", "--all", "--pickaxe-regex", f"-G{regex.pattern}", "--oneline", "--diff-filter=A"], cwd=target, capture_output=True, text=True, timeout=30 ) except Exception: continue if not res.stdout.strip(): continue added_lines = [ line[1:].strip() for line in res.stdout.splitlines() if line.startswith("+") and not line.startswith("+++") ] matched_lines = [line for line in added_lines if regex.search(line)] if matched_lines: hits.append(label) evidence.append(f"{label} 命中示例: {matched_lines[0][:160]}") ``` Another source is `scripts/scan_memory.py:315-327`: ```python evidence = [] for fpath, lines in matches.items(): evidence.append(f"{fpath}:") f ...[truncated 3385 chars]
Remediation
View remediation
str: return ( json.dumps(data, ensure_ascii=False, separators=(",", ":")) .replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) data_json = safe_json_for_html(data) data_tag = ( '' ) ``` The frontend should then read the value using `textContent`: ```javascript const element = document.getElementById("watchdog-data"); const data = JSON.parse(element.textContent); ``` 2. Apply context-appropriate escaping even when using `application/json`; an unescaped `` sequence can still terminate a script element at the HTML parser level. 3. Minimize evidence collection. Avoid preserving raw lines from Git history or memory when a count, file name, line number, or redacted excerpt is sufficient. 4. Redact credentials and token-like strings before they enter report files. The security scanner currently retains a matching line as evidence, which can itself expose the secret that the scanner detected. 5. Render all report-controlled frontend strings through React text nodes. Do not introduce `dangerouslySetInnerHTML` for titles, evidence, file paths, or remediation instructions. 6. Add regression tests using payloads including: ```text

T08 · Insecure Dependencies

Warning
Location
scripts/setup.py:73
Finding

Automatic Third-Party Dependency Installation During Setup and Dashboard Generation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (110)

Tainted flow: 'req' from os.environ.get (line 59, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate_dashboard.py (reported line 64)May include surrounding context.

python
data=token_payload,
            headers={"Content-Type": "application/json"},
        )
        with urllib.request.urlopen(req, timeout=10) as resp:
            token_data = json.loads(resp.read())
        token = token_data.get("tenant_access_token", "")
        if not token:

Tainted flow: 'req' from os.environ.get (line 59, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate_dashboard.py (reported line 76)May include surrounding context.

python
data=token_payload,
            headers={"Content-Type": "application/json"},
        )
        with urllib.request.urlopen(req, timeout=10) as resp:
            token_data = json.loads(resp.read())
        token = token_data.get("tenant_access_token", "")
        if not token:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Uploading generated artifacts to Feishu Drive and exposing shareable links would be a material expansion over simple Feishu DM notification because it can broaden the audience and persistence of potentially sensitive scan results. In a security-reporting skill, exfiltration risk is elevated because dashboards and JSON may contain host paths, configuration state, or detected issues.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
92% confidence
Finding

browserslist 4.28.1 is reported vulnerable to crash/prototype write via untrusted browserslist-stats input and to unbounded memory growth from distinct query results. Although typically used in build tooling, this becomes more dangerous if the skill ingests repository-controlled config or external stats files during automated scans or dashboard generation, because it could disrupt CI/agent execution and potentially taint objects in the Node process.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'react-dnd' resembles popular package 'react-dom'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_dashboard.py (reported line 57)May include surrounding context.

python
print("WARN: FEISHU_APP_ID/SECRET not set, skipping bot info fetch")
        return {}
    try:
        # Step 1: get tenant access token
        token_payload = json.dumps({"app_id": app_id, "app_secret": app_secret}).encode()
        req = urllib.request.Request(
            "https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal",

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Accessing the workspace .env file constitutes credential access because that file commonly contains unrelated secrets beyond Feishu credentials. In this skill context, reading from the shared workspace is more dangerous because the script is a notification helper, yet it is granted the ability to inspect a central secrets file, increasing blast radius if the script is misused, modified, or chained with other components.

Content

Scanner excerpt · scripts/notify_feishu.py (reported line 55)May include surrounding context.

python
def load_env_fallback(var_names: list[str]) -> dict[str, str]:
    """Load selected vars from workspace .env when current process env is missing them."""
    env_path = Path(get_workspace_root()) / ".env"
    if not env_path.exists():
        return {}

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The explicit construction of a path to the workspace .env file shows intentional access to a centralized secret container. Even though the current code filters requested keys, the capability itself is broader than necessary for a reporting utility and creates a high-value target in an agent environment where workspace files may be reachable or influenced by other automation.

Content

Scanner excerpt · scripts/notify_feishu.py (reported line 56)May include surrounding context.

python
def load_env_fallback(var_names: list[str]) -> dict[str, str]:
    """Load selected vars from workspace .env when current process env is missing them."""
    env_path = Path(get_workspace_root()) / ".env"
    if not env_path.exists():
        return {}

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The pipeline is described as a scanning and reporting watchdog, but it unconditionally runs fix_green.py, which performs code modifications. In a safety-monitoring skill, silently transitioning from audit to write/repair behavior can cause unauthorized changes, expand the blast radius of a compromised fixer, and violate user expectations about a read-only health check.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan_comm.py (reported line 62)May include surrounding context.

python
report.add_issue(
                    "comm_missing_env_keys", "HIGH",
                    f"通道凭证环境变量缺失:{', '.join(missing_env[:3])}{'...' if len(missing_env) > 3 else ''}",
                    "在 .env 或 plist EnvironmentVariables 中补齐",
                    [str(gateway_config)],
                    evidence=[f"缺失: {', '.join(missing_env)}"],
                    fix_action="在飞书群告知 techops 补齐环境变量"

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
84% confidence
Finding

dict(os.environ) copies the entire process environment into the subprocess environment for openclaw doctor, potentially forwarding secrets such as API tokens, credentials, proxy settings, or other sensitive context unnecessarily. Passing all inherited environment variables across trust boundaries increases the chance of accidental exposure to child processes, logs, or diagnostic behavior.

Content

Scanner excerpt · scripts/scan_security.py (reported line 24)May include surrounding context.

python
def project_openclaw_env() -> dict:
    workspace_root = Path(get_workspace_root())
    env = dict(os.environ)
    env["OPENCLAW_CONFIG_PATH"] = str(workspace_root / ".openclaw" / "config")
    env["OPENCLAW_STATE_DIR"] = str(workspace_root / ".openclaw" / "state")
    env["NO_COLOR"] = "1"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan_shared.py (reported line 79)May include surrounding context.

python
report.set_metadata("permissions", "OK" if not wide_perms else f"Wide open ({len(wide_perms)} files)")

    # Sensitive config check
    sensitive_exts = {".env", ".json", ".key", ".pem", ".p12"}
    sensitive_names = {"credentials", "secret", "token", "password", "apikey"}
    sensitive_count = 0
    for f in shared_dir.rglob("*"):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that the skill scans multiple dimensions, writes local dashboard/JSON logs, and sends summaries by Feishu private message, but it does not clearly warn users what specific data may be collected, retained, or transmitted off-process. In a monitoring tool that inspects memory, shared files, cron state, permissions, and possible key leakage, the absence of explicit privacy and data-sharing disclosure creates a real risk of exposing sensitive operational metadata or secrets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented manual trigger phrases are extremely generic conversational terms such as '体检', '生成健康大盘', and '跑安全检查', which can plausibly appear in ordinary discussion and unintentionally invoke the skill. Because the skill performs scans, generates artifacts, and may send reports via Feishu, accidental activation can lead to unintended data processing and transmission.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares powerful capabilities in practice—environment-variable access, file read/write, network use, and shell execution—but does not constrain them with an explicit tool/permission scope. This weakens reviewability and increases the chance that installation or runtime behavior performs actions the user did not clearly authorize, especially because the documented flow includes setup, cron registration, scanning, report generation, and outbound Feishu messaging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.