Back to skill

Security audit

New Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is broadly about setting up OpenClaw agents, but its scripts have unsafe input handling, persistent credential/config changes, and automatic cross-agent permissions that need review before use.

Review and harden the scripts before installing or running this skill. Only use manifests you authored and inspected, avoid putting live tokens in chat or version-controlled JSON files, validate agent IDs as simple slugs, remove automatic agentToAgent.allow changes unless explicitly needed, and expect the batch script to modify OpenClaw config and restart the gateway.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/batch-setup.sh:38
Finding

Arbitrary Python Code Execution Through Manifest Path Injection

Content
View full analysis
/dev/null; then echo "❌ Invalid JSON in manifest file" exit 1 fi ``` The same unsafe interpolation pattern appears again during agent registration: ```bash python3 -c " import json, subprocess, os state_dir = os.environ.get('OPENCLAW_STATE_DIR', os.path.expanduser('~/.openclaw')) with open('$MANIFEST') as f: agents = json.load(f) ``` ### Technical Analysis The user-supplied manifest path is interpolated directly into Python source code inside a single-quoted Python string. Shell quoting does not make this safe because the expanded filename becomes part of the source passed to `python3 -c`. A filename containing a single quote, closing parentheses, semicolons, and Python statements can terminate the intended string and append arbitrary Python code. This is source-code injection rather than ordinary argument injection. For example, a crafted filename shaped like the following can close the `open()` and `json.load()` calls before appending a command: ```text x'));__import__("os").system("id");# ``` The initial validation command is already vulnerable, so exploitation occurs before the script creates workspaces or validates the manifest's intended schema. ### Attack Path 1. An attacker creates a valid JSON manifest whose filename contains Python syntax. 2. The attacker or a victim invokes: ```bash ./scripts/batch-setup.sh '' ``` 3. The shell expands `$MANIFEST` inside the string passed to `python3 -c`. 4. The filename terminates the Python string and injects additional statements. 5. Python executes the injected statements with the privileges of the user running the setup script. 6. The p ...[truncated 857 chars]
Remediation
View remediation
/dev/null; then echo "Invalid JSON in manifest file" exit 1 fi ``` Apply the same correction to the registration block: ```bash python3 - "$MANIFEST" <<'PYEOF' import json import os import subprocess import sys manifest_path = sys.argv[1] state_dir = os.environ.get( "OPENCLAW_STATE_DIR", os.path.expanduser("~/.openclaw"), ) with open(manifest_path, encoding="utf-8") as f: agents = json.load(f) # Continue registration using the parsed data. PYEOF ``` Alternatively, consistently use the existing `MANIFEST_PATH` environment variable inside quoted heredocs. Do not construct executable Python, shell, or JSON expressions through string interpolation. Add regression tests using filenames containing quotes, semicolons, spaces, newlines, parentheses, and shell metacharacters. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/batch-setup.sh:65
Finding

Arbitrary Filesystem Writes Through Unvalidated Agent Identifiers

Content
View full analysis
}" AGENT_NAME_LOWER="${AGENT_NAME,,}" AGENT_ID="${AGENT_NAME_LOWER}-agent" STATE_DIR="${OPENCLAW_STATE_DIR:-$HOME/.openclaw}" WORKSPACE_DIR="${STATE_DIR}/workspace-groups/${AGENT_NAME_LOWER}" ``` It then creates and overwrites files at the derived location: ```bash mkdir -p "${WORKSPACE_DIR}" cat > "${WORKSPACE_DIR}/IDENTITY.md" << EOF # IDENTITY.md - Who Am I? - **Name:** ${AGENT_NAME} - **Role:** AI assistant - **Emoji:** Agent EOF ``` The scripts also write `SOUL.md`, `AGENTS.md`, and `USER.md` in the same directory. ### Technical Analysis Neither script validates agent identifiers as safe path components. In batch mode: - An absolute `id` causes `os.path.join()` to discard the preceding `state_dir/workspace-groups` path. - An `id` containing `../` can escape the expected workspace root. - Existing symbolic links can redirect file writes outside the intended directory. In single-agent mode, traversal sequences such as `../../target` remain effective because the path is constructed through string concatenation and is ...[truncated 1590 chars]
Remediation
View remediation
&2 exit 1 fi ``` Additional hardening should include: - Rejecting absolute paths, separators, `.` and `..` components, control characters, and empty identifiers. - Refusing workspace directories or destination files that are symbolic links. - Checking the canonical destination immediately before each write. - Creating files with restrictive permissions. - Using safe atomic writes and refusing unexpected existing files unless overwrite is explicitly approved. - Validating `OPENCLAW_STATE_DIR` under an appropriate trust policy. ]]>

T02 · Agent Memory Poisoning

Error
Location
scripts/batch-setup.sh:65
Finding

Persistent Agent Instruction Injection Through Manifest Metadata

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/batch-setup.sh:151
Finding

Unconditional Grant of Agent-to-Agent Authorization in Batch Mode

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The core batch behavior largely matches the declared batch-setup purpose: creating multiple agents, wiring channels, writing config once, and restarting the gateway once. However, the declared description overstates supported channels: the code only handles telegram, feishu, discord, and slack, with no implementation for WhatsApp, Signal, or Google Chat. The description also mentions single and batch mode, but this code chunk is strictly a batch script. Additionally, the script alters tools.agentToAgent.allow, granting inter-agent capability not described. These are material description-to-behavior mismatches, even though the primary purpose is broadly aligned.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says the skill creates agents and connects them to messaging channels, supporting both single and batch modes with a single config write and gateway restart. The supplied code only sets up a workspace, creates markdown files, optionally backs up the OpenClaw config, and runs openclaw agents add for one agent. It explicitly states that channel account/binding addition and gateway restart still need to be done manually afterward. Therefore the code's actual behavior is materially narrower than the declared purpose, and key promised capabilities—channel connection, batch mode, config mutation for bindings, and restart orchestration—are absent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to paste a live Telegram bot token into a prompt to the agent, but provides no warning about secure handling, storage, logging, or redaction. In an agent system, prompts may be persisted in chat history, logs, telemetry, or workspace files, so encouraging direct submission of credentials creates a realistic secret-exposure risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill instructs use of shell commands and configuration edits but declares no explicit tool scope or permissions boundary. In an agent environment, missing scope metadata can cause over-broad execution authority, making it easier for the skill to run filesystem and shell operations without clear review or restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation tells users to place bot tokens and app secrets into configuration and run mutating gateway commands, but gives no warning about secret handling, file protection, auditability, or service disruption. This increases the chance of credential leakage through config files, shell history, logs, screenshots, or unsafe repository commits, and can also cause unintended availability impact from restarts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The batch manifest example embeds live-style app secrets directly in a JSON file without warning that the file is sensitive. In this skill's context, that is more dangerous because batch manifests are likely to be saved, shared, version-controlled, or reused, creating a straightforward path to credential exposure and compromise of connected messaging accounts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/batch-setup.sh (reported line 51)May include surrounding context.

sh
cp "${CONFIG_PATH}" "${CONFIG_PATH}.bak.$(date +%Y%m%d%H%M%S)"
echo "📦 Config backed up"

# 2. Create all workspaces
echo ""
echo "━━━ Phase 1: Creating workspaces ━━━"
python3 << 'PYEOF'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script generates SOUL.md content in Chinese and includes fixed Chinese instructions for the agent's role and principles. This imposes a specific language/locale on created agents without offering the user a choice or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script writes bearer tokens and app secrets from the manifest directly into the persistent openclaw.json config file without an explicit warning or stronger secret-handling controls. Storing credentials on disk increases exposure through backups, filesystem compromise, accidental sharing, or permissive file permissions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically appends every created agent to tools.agentToAgent.allow, which expands privileges beyond simple agent creation and channel binding. This can enable unintended cross-agent communication and data flow between agents, increasing blast radius if one agent is misconfigured, prompt-injected, or exposed to untrusted channel input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes Chinese-language role and workflow content into SOUL.md and AGENTS.md, including a Chinese role label and Chinese operating instructions. This imposes a specific language/locale on the generated skill behavior without offering a user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.