Back to skill

Security audit

🦞 OpenClaw Starter Guide

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent OpenClaw setup guide, but users should handle provider keys, external API tests, and unpinned installation commands carefully.

Install only if you intend to configure OpenClaw with these third-party model providers. Review each provider skill before installing, prefer pinned or trusted versions when available, do not run install commands with sudo/root, use test or limited-scope API keys, keep keys out of chats/screenshots/repos/logs, and back up OpenClaw config/session files before manual edits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Third-Party Packages and Skills Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:42-44, SKILL.md:130-132, SKILL.md:171-174, SKILL.md:371-375, and README.md:23-27
Vulnerability Type: Unpinned and unaudited third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:42-44:

bash
# Install ClawHub CLI (used to install skills)
npm i -g clawhub

SKILL.md:130-132:

bash
clawhub install add-minimax-provider

SKILL.md:171-174:

bash
clawhub install add-siliconflow-provider  # DeepSeek/Qwen/Kimi
clawhub install add-newcli-provider       # Claude/GPT/Gemini

SKILL.md:371-375:

markdown
| Skill | Installation command | Description |
|------|----------|------|
| SiliconFlow | `clawhub install add-siliconflow-provider` | 98+ models, including free models |
| MiniMax | `clawhub install add-minimax-provider` | ¥49/month subscription plan |
| NewCLI | `clawhub install add-newcli-provider` | Claude/GPT/Gemini |

README.md:23-27:

markdown
| Skill | Installation command |
|------|----------|
| SiliconFlow (free starting option) | `clawhub install add-siliconflow-provider` |
| MiniMax (subscription-based primary option) | `clawhub install add-minimax-provider` |
| NewCLI (Claude/GPT/Gemini) | `clawhub install add-newcli-provider` |

Technical Analysis

The guide instructs users to install the mutable latest release of the clawhub npm package globally and then install three third-party skills by name. None of the commands specify an exact version, immutable release identifier, integrity hash, signature, or trusted source commit.

The installed packages and skills are not included in this repository, so their implementation and installation behavior cannot be audited from the submitted files. Package registries and skill marketplaces resolve mutable names at installation time. Consequently, the software installed by a future user may differ fro ...[truncated 2237 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the ClawHub CLI to an exact reviewed version rather than resolving the latest release:

    bash
    npm install --global clawhub@<reviewed-version>
    
  2. Pin each provider skill to an immutable version, release identifier, or source commit if ClawHub supports that capability.

  3. Publish expected SHA-256 digests or signed provenance information for every referenced artifact and require users to verify integrity before installation.

  4. Link each dependency to its official source repository and identify the exact source revision corresponding to the recommended release.

  5. Add an explicit review step instructing users to download and inspect the skill manifest, scripts, lifecycle hooks, requested permissions, and network destinations before activation.

  6. Prefer a project-local installation over a global npm installation where practical. Disable npm lifecycle scripts during initial retrieval when compatible:

    bash
    npm install --ignore-scripts clawhub@<reviewed-version>
    

    Any required scripts should be inspected before being run separately.

  7. Perform installation in a least-privileged, isolated environment without production API keys or sensitive OpenClaw configuration. Do not run the installation as root or through sudo.

  8. Use lockfiles, trusted registries, package signatures, software bills of materials, and automated dependency monitoring to detect unexpected publisher or artifact changes.

  9. Document a regular review process so pinned versions are upgraded only after the new artifacts and their transitive dependencies have been audited.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents the skill description entirely in Chinese ('小白养成手册 — 从零到多 Agent AI 系统的完整指南') with no indication that the skill is region-specific or that other language options are available. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation description says to use this skill when the user says "怎么开始", which is a very common phrase in ordinary conversation and not narrowly tied to OpenClaw or model-configuration guidance. Because the trigger list lacks exclusion conditions or contextual constraints, the skill could activate in unintended situations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description lists phrases like "省钱方案", "模型怎么选", and "fallback 怎么配" without stating that they only apply in the context of OpenClaw setup or provider/model configuration. These phrases are broad enough to overlap with many unrelated conversations, creating ambiguity about when this skill should versus should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill name and description are entirely in Chinese and the invocation phrases are Chinese-only, with no indication that users may interact in other languages or that the skill is intentionally limited to a Chinese-speaking audience for a documented reason. This creates a language/locale policy concern because the skill appears to impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This section instructs users to place API keys into configuration and contact third-party services, but it does not clearly warn about secret handling, provider trust, billing exposure, or least-privilege practices. In a setup guide, that omission increases the chance that users will paste real production keys into insecure environments, screenshots, logs, or shared configs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
"models": {
    "providers": {
      "siliconflow": {
        "baseUrl": "https://api.siliconflow.cn/v1",
        "apiKey": "<YOUR_KEY>",
        "api": "openai-completions",
        "models": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill provides a live curl command that sends an authenticated request to an external API using a bearer token, without strong warnings about secret exposure, shell history retention, network disclosure, or unintended billing. Although framed as diagnostics, it normalizes direct secret-bearing network calls that less experienced users may run unsafely.

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

bash
# 判断额度是否可用的唯一可靠方法
curl -s https://api.minimaxi.com/v1/chat/completions \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{"model":"MiniMax-M2.1","messages":[{"role":"user","content":"test"}],"max_tokens":3}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill provides a live curl command that sends an authenticated request to an external API using a bearer token, without strong warnings about secret exposure, shell history retention, network disclosure, or unintended billing. Although framed as diagnostics, it normalizes direct secret-bearing network calls that less experienced users may run unsafely.

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

bash
# 判断额度是否可用的唯一可靠方法
curl -s https://api.minimaxi.com/v1/chat/completions \
  -H "Authorization: Bearer <API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{"model":"MiniMax-M2.1","messages":[{"role":"user","content":"test"}],"max_tokens":3}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This troubleshooting curl example sends authenticated requests to an arbitrary base URL and encourages manual connectivity testing without clarifying data-handling and credential-safety risks. In context, users may substitute real endpoints and keys, exposing secrets in terminal history or sending test data to unintended services.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

md
tail -20 ~/.openclaw/logs/gateway.err.log

# 3. 测试模型可用性
curl -s '<BASE_URL>/chat/completions' \
  -H 'Authorization: Bearer <KEY>' \
  -H 'Content-Type: application/json' \
  -d '{"model":"<MODEL>","messages":[{"role":"user","content":"test"}],"max_tokens":5}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The troubleshooting guidance recommends inspecting logs and directly editing session files without cautioning about sensitive data exposure, corruption risk, backups, or access controls. Users could inadvertently disclose conversation contents, tokens, or break system state by manual file manipulation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.