Back to skill

Security audit

OMOC - Oh My OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its workflow purpose, but its mailbox commands can be aimed outside the intended state folder to read or modify JSON files.

Install only if you are comfortable with a local workflow tool writing project state under .omoc, and avoid using untrusted worker or mailbox names. The mailbox path validation issue should be fixed before using this in a sensitive workspace.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/omoc.py:111
Finding

Path Traversal in Team Mailbox File Operations

Content
View full analysis
/mailbox/` directory. An absolute path is also dangerous because joining a `pathlib.Path` with a subsequent absolute path discards the preceding mailbox path. The implementation automatically appends `.json`, which limits targets to paths ending in that extension but does not prevent traversal. The mailbox read operation parses and prints any accessible valid JSON file. The send ...[truncated 2349 chars]
Remediation
View remediation
Path: safe(worker, 'worker') return td(team) / 'mailbox' / f'{worker}.json' ``` 2. Require mailbox participants to belong to the configured team roster: ```python def require_worker(team: str, worker: str) -> None: workers = {item['name'] for item in cfg(team).get('workers', [])} if worker not in workers: raise SystemExit(f'worker_not_found: {worker}') ``` Apply this check to recipients and mailbox readers. If leaders are valid mailbox participants, represent and validate them explicitly rather than accepting arbitrary names. 3. Enforce resolved-path containment as defense in depth: ```python def mailbox_path(team: str, worker: str) -> Path: safe(worker, 'worker') base = (td(team) / 'mailbox').resolve() target = (base / f'{worker}.json').resolve() if target.parent != base: raise SystemExit('invalid mailbox path') return target ``` 4. Explicitly reject absolute paths, path separators, `.` components, and `..` components before accessing the filesystem. 5. Use the centralized safe path function for both reads and writes so future mailbox commands cannot omit validation. 6. Validate the decoded mailbox schema before modifying it. Confirm that the root value is an object and that `messages` is a list of bounded, expected message objects. 7. Add regression tests covering: - Relative traversal sequences. - Absolute paths. - Nested path separators. - Unknown workers. - Valid configured workers. - Symlink-based containment escapes. - Malformed and schema-incompatible JSON targets. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's stated purpose does not fully match the operational behaviors it advertises, including workflow composition/initialization and inter-worker mailbox coordination, and it mentions /ralplan without a corresponding implemented command/runtime. Description-behavior mismatches are dangerous because they obscure real capabilities from users and reviewers, making it easier for powerful orchestration or state mutation features to bypass scrutiny and for operators to invoke unsupported or misunderstood flows.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes stateful runtime behavior and explicitly references mutation via scripts/omoc.py, while the manifest declares no permissions or allowed-tools scope despite requiring environment access and file read/write behavior. This creates an undeclared capability boundary: a reviewer or host may underestimate what the skill can access or modify, increasing the chance of unintended filesystem or environment exposure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
Memory rules: add durable events for decisions/evidence/blockers, compact before worker handoff or when event logs grow, pass workers bounded summaries rather than raw logs.

Safety rules: no external actions without confirmation, no overlapping Ralph/team loops, no worker-owned goal mutations, no completion without verifier/review evidence, no hiding failed tasks.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code defines commands that create and overwrite workflow and memory files, including workflow.json, events.jsonl, summary markdown, and index.json, but provides no confirmation prompt, warning message, or explanatory docstring before performing those writes. Because these operations persist user-provided content and alter local state, the lack of disclosure can surprise users running the script.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The team commands initialize directories, create mailbox files, append event logs, update task state, and rewrite summary/config JSON files, yet there is no user-facing warning that running these commands will mutate on-disk coordination data. These are safety-relevant file operations because they can affect workflow state and user data without explicit disclosure beyond returning JSON after the fact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These commands save goal briefs, evidence, checkpoint history, and Ralph loop state to local files, including user-supplied text that may be sensitive, but they do not warn the user that this data will be written to disk. The absence of disclosure is notable because the stored content may include project objectives or evidence strings that users may not expect to persist.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.