Back to skill

Security audit

Yuzhua (驭爪) - Gesture-Controlled OpenClaw Chat

Security checks for vulnerabilities and agentic risk

Overview

The skill is clearly meant to manage Yuzhua, but it downloads and runs mutable external code and its stop command can force-kill unrelated local processes.

Install only if you trust the Yuzhua upstream repository and understand that the skill will run code from the current checkout, not a pinned reviewed release. Review YUZHUA_REPO_URL and YUZHUA_HOME before use, and be careful with stop.sh because it can kill any process listening on the configured port, especially the default 8080.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:21
Finding

Unpinned Remote Repository Retrieval Followed by Local Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/stop.sh:11
Finding

Port-Based Stop Logic Can Terminate Unrelated Processes

Content
View full analysis
/dev/null 2>&1; then return 1 fi local pids pids="$(lsof -ti tcp:"${PORT}" || true)" if [ -z "${pids}" ]; then return 1 fi log "Stopping process on port ${PORT}: ${pids}" kill ${pids} || true sleep 1 pids="$(lsof -ti tcp:"${PORT}" || true)" if [ -n "${pids}" ]; then log "Force killing: ${pids}" kill -9 ${pids} || true fi return 0 } ``` ### Technical Analysis The stop operation identifies the target solely by the TCP port configured in `YUZHUA_PORT`, which defaults to 8080. It does not verify that a discovered PID belongs to Yuzhua, has the expected executable path, was launched from `YUZHUA_HOME`, or was created by this Skill. Any process accessible to the invoking user that uses the selected port can therefore receive `SIGTERM`. After only one second, the script queries the port again and sends `SIGKILL` to any returned PID. The second lookup also introduces a time-of-check/time-of-use risk: a different process could acquire the port between the first termination and the second lookup and then be force-killed. Using an environment-controlled port is legitimate configuration behavior, but port ownership alone is insufficient authorization to terminate a process. This exceeds the least privilege needed to stop Yuzhua. ### Attack Path 1. An unrelated application listens on TCP port 8080, or an attacker causes the user to set `YUZHUA_PORT` to a port used by another application. 2. The user runs `scripts/stop.sh`. 3. `lsof -ti tcp:"${PORT}"` returns the unrelated application's PID. 4. The script sends `SIGTERM` to that PID without validating its identity. 5. If a process still occupies the port after one second, the script performs another lookup and sends `SIGKILL`. 6. The u ...[truncated 632 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a broader management skill: install, start, stop, and health-check Yuzhua. However, this code chunk implements only installation/update preparation steps. It interacts with git and the local filesystem to clone or update the repository and prepare environment files, but contains no logic to launch Yuzhua, stop it, or verify runtime health. This is a material description-to-behavior mismatch because key advertised capabilities are absent from the supplied code.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 41)May include surrounding context.

sh
}

prepare_env() {
  if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
    cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
    log "Created .env from .env.example"
    log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 42)May include surrounding context.

sh
}

prepare_env() {
  if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
    cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
    log "Created .env from .env.example"
    log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 43)May include surrounding context.

sh
prepare_env() {
  if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
    cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
    log "Created .env from .env.example"
    log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."
  fi
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 44)May include surrounding context.

sh
prepare_env() {
  if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
    cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
    log "Created .env from .env.example"
    log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."
  fi
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises shell-driven install/start/stop/health-check behavior but does not declare any explicit tool scope or permissions. In systems that rely on manifest-declared boundaries, this creates an authorization gap: an agent may invoke shell-capable scripts without clear user-visible restrictions, increasing the chance of unintended code execution or repository/script abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.