Back to skill

Security audit

Install Skills from Clawhub for all Agents

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but its installer can persistently replace global OpenClaw skills and lacks containment checks around path-derived file operations.

Review before installing. Only run it with trusted, simple skill slugs and agent names, verify the resolved OpenClaw home path, avoid untrusted input for flags or environment variables, and make sure backups are kept before replacing a global skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install-global-skill.js:159
Finding

Path Traversal Through Unvalidated Skill Slug and Agent Name

Content
View full analysis
/workspaces/.`, ); } return resolved; } ``` ```js const slug = args.slug; const stagedDir = path.join(layout.stagingRoot, slug); const globalDir = path.join(layout.globalRoot, slug); const tempGlobalDir = `${globalDir}.tmp`; const result = installOrUpdate(slug, args.version, layout); const stagedOrigin = path.join(stagedDir, '.clawhub', 'origin.json'); if (!exists(stagedOrigin)) { throw new Error(`Staged skill missing origin file: ${stagedOrigin}`); } const stagedMeta = readJson(stagedOrigin); let backupPath = null; if (exists(globalDir) && !args.skipBackup) { backupP ...[truncated 3668 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
- Prefer `scripts/install-global-skill.js` over manual file operations.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
- Prefer `scripts/install-global-skill.js` over manual file operations.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly states that the skill will install or upgrade software and then promote it into the machine's global OpenClaw home skills directory, but it does not warn that this modifies the local environment outside the current workspace. That omission can mislead users or downstream agents into making persistent system-level changes without clear consent, increasing the risk of unintended trust of newly installed global skills.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to read environment variables such as OPENCLAW_HOME and OPENCLAW_AGENT to resolve installation targets, but it declares no explicit tool scope or permissions boundary. That creates an undeclared capability surface where the skill can influence filesystem operations based on ambient environment state, increasing the risk of unintended writes, installs, or promotion into sensitive paths if the runtime exposes env access broadly.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install-global-skill.js:50