Back to skill

Security audit

OpenClaw Token Saver

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a token-saving guide, but it needs review because it recommends unsafe remote installer execution and includes under-scoped reset and proxy-bypass guidance.

Review before installing. Avoid running the README's curl-to-shell Ollama installer without separate verification, and do not enable any automatic compact/reset behavior unless you understand whether it can discard conversation context. The proxy-forwarding suggestion should be treated as non-compliant or unsupported unless your provider explicitly permits that use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:221
Finding

Unverified Remote Installer Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: README.md:221
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
# Install Ollama
curl -fsSL https://ollama.com/install.sh | sh

# Run local model
ollama run qwen2.5:14b

Technical Analysis

The installation instructions download a mutable script from an external URL and immediately pipe its contents into sh. The downloaded payload is neither version-pinned nor authenticated through a separately verified signature or checksum. Users are also given no opportunity to inspect the retrieved script before execution.

HTTPS protects data in transit under normal conditions, but it does not make a mutable upstream script safe. A compromise of the hosting endpoint, its deployment pipeline, the relevant domain or TLS trust chain, or another upstream component could change the effective payload after this Skill has been reviewed.

Installing Ollama supports the documented local-model functionality, but direct curl | sh execution is not the minimum-risk installation mechanism. A verified package, a pinned release artifact, or a separately downloaded and inspected installer can provide the same functionality with a smaller supply-chain attack surface.

No evidence in the audited project indicates that the local token-monitor.py script invokes this command automatically. Exploitation therefore depends on a user following the README instructions.

Attack Path

  1. An attacker compromises or gains control over the remote installer content served by https://ollama.com/install.sh, or otherwise compromises a trusted part of its delivery chain.
  2. The attacker modifies the remotely hosted script to include arbitrary shell commands.
  3. A user follows the README installation instructions.
  4. curl retrieves the attacker-controlled content at execution time.
  5. The pipe passes the response directly to sh without i ...[truncated 1174 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct network-to-shell pipeline.

  2. Prefer installation from an authenticated operating-system package repository or another trusted package manager.

  3. If an installer script is necessary, reference a version-pinned release artifact rather than a mutable endpoint.

  4. Download the artifact as a separate step so users can inspect it before execution.

  5. Publish and verify a cryptographic signature using a trusted, independently distributed public key. At minimum, verify a release-specific checksum obtained through an authenticated channel.

  6. Execute the installer with ordinary user privileges whenever possible, requesting narrowly scoped elevation only for operations that require it.

  7. Document the files, packages, services, and privileges the installer is expected to use.

  8. Use a safer installation pattern such as:

    bash
    curl -fL --output ollama-install.sh \
      "https://example.invalid/ollama/releases/<PINNED_VERSION>/install.sh"
    
    echo "<EXPECTED_SHA256>  ollama-install.sh" | sha256sum --check -
    less ollama-install.sh
    sh ollama-install.sh
    

    The placeholder URL, pinned version, and checksum must be replaced with values published and authenticated by the trusted upstream release process.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The README instructs users to execute a remote installation script directly via curl piped to sh, which bypasses review of the downloaded code and creates a direct remote code execution path if the server, transport, or script supply chain is compromised. Even in documentation, this is dangerous because users may copy-paste it verbatim on trusted systems.

Content

Scanner excerpt · README.md (reported line 221)May include surrounding context.

Ollama Setup

bash
# Install Ollama
curl -fsSL https://ollama.com/install.sh | sh

# Run local model
ollama run qwen2.5:14b

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping network-fetched content into a shell is a classic chaining pattern that turns external content into immediate command execution with no validation boundary. In a skill README, this is especially risky because it normalizes unsafe operator behavior and could result in full system compromise if the fetched content is malicious or tampered with.

Content

Scanner excerpt · README.md (reported line 221)May include surrounding context.

Ollama Setup

bash
# Install Ollama
curl -fsSL https://ollama.com/install.sh | sh

# Run local model
ollama run qwen2.5:14b

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README promotes automatic token monitoring with escalating actions including 'force optimization' and 'emergency reset' but does not clearly describe safeguards, consent, rollback behavior, or what state may be modified. In a skill context, encouraging session-modifying automation without explicit warnings can lead users to enable behavior that unexpectedly alters conversation state or loses context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and primary skill content are written entirely in Chinese and the metadata explicitly tags the skill as "chinese", but the file does not offer any language choice or state that the skill is intended only for a Chinese-language audience. Per the policy, a skill that effectively enforces a specific language without opt-in should be flagged.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly suggests a '本地代理转发' approach to route requests through a web-based AI so they do not consume official tokens, which is guidance for bypassing platform billing and usage controls rather than legitimate optimization. In the context of a token-saving skill, this is especially dangerous because it normalizes evasion as an endorsed cost-reduction technique and could facilitate policy violations, account abuse, or unauthorized access patterns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural-language strings and documentation entirely in Chinese, including the module description and later CLI/report output. Because the skill does not offer any user opt-in or explain that it is intended only for a Chinese-speaking context, it appears to force a specific language, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comment and user-facing messages in this file are written in Chinese, and the configuration provides no indication that users can select another language or opt in to this locale. That can violate a language/locale policy when the skill is expected to be generally applicable rather than region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.