Back to skill

Security audit

工作流编排

Security checks for vulnerabilities and agentic risk

Overview

This workflow skill mostly matches its stated orchestration purpose, but it can automatically start cross-skill advertising workflows and proxy arbitrary skill commands with too little scoping or user control.

Install only in an environment where workflow authors and event emitters are trusted. Before production use, require explicit allowlists for callable skills and commands, validation of workflow definitions and event payloads, confirmation for distribution or paid-resource actions, and redaction of workflow arguments from logs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
index.ts:551
Finding

Unrestricted Caller-Controlled Cross-Skill Command Dispatch

Content
View full analysis
{ const id = await orchestrator.createWorkflow({ name: args.name, steps: args.definition, context: args.context }); ``` The caller-controlled step is subsequently dispatched without validation: ```typescript // Add workflow metadata resolvedArgs._workflow = { workflowId, stepId: step.id, attempt }; this.api.log(`debug`, `Executing ${step.skill}:${step.command} with args: ${JSON.stringify(resolvedArgs)}`); // Execute command via API const result = await this.api.executeCommand(step.skill, step.command, resolvedArgs); ``` ### Technical Analysis The public `workflow create` command accepts an arbitrary object as its workflow definition. The supplied steps determine the `skill`, `command`, and command arguments passed to `api.executeCommand`. No strict step schema, command allowlist, capability check, or per-command authorization is applied before dispatch. Consequently, the orchestrator acts as a generic command proxy. A caller who is authorized to create and start workflows may be able to invoke commands in other installed skills that the caller could not invoke directly. The exact commands available depend on the surrounding OpenClaw environment, but the reachable privilege scope includes every skill and command that the orchestrator's API context is permitted to execute. ### Attack Path 1. An attacker obtains permission to invoke the orchestrator's `workflow create` and `workflow start` subcommands. 2. The attacker creates a ...[truncated 956 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.ts:404
Finding

Sensitive Workflow Arguments Exposed Through Debug Logging

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
index.ts:687
Finding

Unvalidated Event Automatically Starts an External Distribution Workflow

Content
View full analysis
{ const { demandId, demand } = data as { demandId: string; demand: any }; api.log("info", `Demand approved: ${demandId}, creating auto-workflow`); // Create a standard ad production workflow try { const wfId = await orchestrator.createStandardAdWorkflow({ demandId, prompt: demand.description || "Standard creative", count: 10, platforms: ["抖音", "穿山甲"] // Default platforms }); api.log("info", `Auto-created workflow: ${wfId}`); // Optionally start immediately await orchestrator.startWorkflow(wfId); api.log("info", `Workflow ${wfId} started automatically`); ``` ### Technical Analysis Loading the skill registers a `demand.approved` event listener that creates and immediately starts a multi-stage advertising workflow. The generated workflow includes AI generation, review, delivery preparation, distribution, and analytics commands. The listener trusts the event payload through a TypeScript cast but does not perform runtime validation, authenticate the event source, check authorization, prevent duplicate events, or request confirmation before starting the workflow. The behavior and hard-coded target platforms are also not disclosed in the reviewed `SKILL.md`. If untrusted or less-privileged components can emit the event, the listener provides an indirect route to resource-consuming and externally visible operations. ### Attack Path 1. An attacker or compromised component gains the ability to emit or influence a `demand.approved` event. 2. The attacker supplies a `demandId` and controlled `demand.description`. 3. The listener accepts the payload without runtime schema or provenance validation. 4. A standard workflow is created using the attacker-co ...[truncated 800 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.ts:485
Finding

Workflow Conditions Fail Open and Do Not Enforce Declared Comparisons

Content
View full analysis
): boolean { try { // Very simple condition evaluation - in production use a proper expression parser // For now, just check if a context variable exists and is truthy if (condition.startsWith("results.")) { const path = condition.slice(7); const value = this.getContextValue(path, context); return value ? true : false; } // Default: condition must be a boolean expression // This is a placeholder - real implementation would use a safe eval return true; } catch (error) { this.api.log(`error`, `Condition evaluation failed: ${condition} - ${error}`); return false; } } ``` ### Technical Analysis The evaluator supports only a truthiness lookup for strings beginning with `results.`. It does not parse comparison operators such as `<`, despite the built-in template declaring such an expression. For `results.auto-check.score < 8`, the evaluator treats `auto-check.score < 8` as a literal property path rather than evaluating the score comparison. Other unsupported conditions reach the default `return true`, causing malformed or unknown policy expressions to pass open. This makes conditional workflow controls unreliable. If conditions are used to enforce approval, quality, authorization, or safety gates, a caller can select an unsupported condition format that executes the protected step rather than blocking it. ### Attack Path 1. A caller creates a workflow containing a sensitive step guarded by ...[truncated 1096 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is documented as a generic workflow orchestrator, but the finding indicates it also registers undeclared event triggers and automatically launches cross-skill workflows. That creates hidden high-privilege behavior: a user or reviewer may authorize a coordination component without realizing it can autonomously react to business events and invoke other skills, which materially changes the trust and attack surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Documenting a terminate action without warning about destructive consequences can lead users or calling agents to stop active workflows without understanding that in-flight tasks, state, or downstream operations may be interrupted. In an orchestrator that coordinates multiple dependent skills, termination can have broader operational impact than a normal single-step cancel action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow engine executes arbitrary skill/command pairs from workflow definitions via api.executeCommand(step.skill, step.command, resolvedArgs), allowing user-supplied workflow data to invoke other skills with templated arguments. Without authorization, command allowlisting, or user disclosure, this becomes a generic cross-skill execution primitive that can be abused to perform unintended actions in other subsystems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The event handler automatically creates and starts a workflow when a "demand.approved" event is received, which can trigger multiple downstream skill commands without any user confirmation, authorization gate, or provenance check on the event source. In an orchestration skill, this is especially dangerous because a single untrusted or spoofed event can fan out into content generation, review, delivery, and analytics actions across other skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language description at L04 is exclusively in Chinese and does not provide an alternative language or indicate that the package is intentionally region-specific. This can violate language/locale policy by forcing a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description and user-facing instructional content are written in Chinese, and the file does not indicate that the skill is region-specific or that users may choose another language. This can be a natural-language policy issue when a specific language is effectively forced without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Natural-language strings in step names, command descriptions, help text, and default platform labels are presented exclusively in Chinese, with no indication that users can choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"license": "MIT",
  "dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Static analysis

No suspicious patterns detected.