Back to skill

Security audit

Project Coordinator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it gives broad project automation authority and documents an unverified GitHub install path that users should review carefully.

Install through the ClawHub/OpenClaw registry path when possible. Before enabling the skill, be comfortable with it spawning subagents that can inspect and modify workspace files and run shell commands for project work; avoid the GitHub main-branch install path unless you verify the exact commit or checksum yourself.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned and Unverified Remote Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31-37
Vulnerability Type: Supply-chain exposure through mutable, unverified remote content
Risk Level: Medium

bash
# Clone the repo
git clone https://github.com/KaigeGao1110/Project-Coordinator.git ~/.openclaw/skills/project-coordinator

# Or download directly
curl -L https://github.com/KaigeGao1110/Project-Coordinator/archive/refs/heads/main.zip -o /tmp/project-coordinator.zip
unzip /tmp/project-coordinator.zip -d ~/.openclaw/skills/
mv ~/.openclaw/skills/Project-Coordinator-main ~/.openclaw/skills/project-coordinator

Technical Analysis

Both installation methods retrieve the mutable default branch from a personal GitHub repository. Neither method pins an audited commit or immutable release, and the instructions do not verify a checksum or cryptographic signature.

The downloaded ZIP is not directly executed by these commands. However, it is extracted into the OpenClaw skills directory, where its contents can subsequently be loaded as Agent instructions. The effective behavior installed on a user's system can therefore differ from the content reviewed during this audit.

This creates a time-of-check to time-of-use supply-chain risk. If the upstream repository is compromised or its default branch is modified, future users may install altered Skill instructions or additional files without an integrity check detecting the change.

Attack Path

  1. An attacker compromises the upstream repository, its maintainer account, or the content served for the mutable main branch.
  2. The attacker adds malicious Skill instructions or executable components to the repository.
  3. A user follows the documented git clone or curl installation procedure.
  4. The altered content is installed without commit pinning, signature verification, or checksum validation.
  5. OpenClaw subsequently loads the attacker-controlled Skill.
  6. The malicious content can ...[truncated 944 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the mutable main reference with an immutable, audited commit hash or versioned release artifact.
  • Publish a SHA-256 digest for every release and verify it before extraction.
  • Prefer signed release artifacts and verify the signature against a documented maintainer key.
  • For Git installation, explicitly check out the approved commit and verify the resulting commit identifier.
  • Fail closed if integrity or signature validation fails.
  • Keep the front-matter version, embedded manifest version, README badge, and installation artifact version synchronized to improve provenance.
  • Prefer a trusted registry installation path only when the registry provides package provenance, immutable version resolution, and signature or integrity verification.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:34
Finding

Predictable Shared Temporary Archive Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34-35
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Low

bash
curl -L https://github.com/KaigeGao1110/Project-Coordinator/archive/refs/heads/main.zip -o /tmp/project-coordinator.zip
unzip /tmp/project-coordinator.zip -d ~/.openclaw/skills/

Technical Analysis

The installation procedure uses the fixed path /tmp/project-coordinator.zip. On multi-user systems, shared temporary directories are commonly writable by other local users. A predictable path can create collision, symlink, or race-condition risks if an attacker can manipulate that path while installation is taking place.

The commands also perform no integrity check between download and extraction. Although curl normally replaces the target contents, the fixed pathname leaves avoidable opportunities for local interference, concurrent installer collisions, or substitution before unzip reads the archive. The precise exploitability depends on operating-system protections, filesystem permissions, and curl behavior in the target environment.

Attack Path

  1. A local attacker predicts that installation will use /tmp/project-coordinator.zip.
  2. The attacker creates or manipulates that path, or races the interval between download and extraction.
  3. The installer writes through an attacker-influenced filesystem object, or unzip reads substituted archive content.
  4. Attacker-selected files may be extracted into the user's OpenClaw skills directory.
  5. If the substituted archive contains malicious Skill content, it may be loaded with the permissions subsequently granted to that Skill.

Impact Assessment

A successful local attack could cause unintended file overwrite or installation of substituted Skill content under the invoking user's privileges. If malicious content reaches the skills directory and is loaded, its practical scope could include the workspace and co ...[truncated 228 chars]

Remediation
View remediation

Remediation Suggestions

  • Create a private temporary directory using mktemp -d.
  • Set restrictive permissions and store the downloaded archive only inside that directory.
  • Install a cleanup trap so the temporary directory is removed on both success and failure.
  • Verify the archive's cryptographic checksum or signature before extraction.
  • Ensure extraction fails rather than overwriting unexpected existing files.
  • Validate archive entries before extraction to reject absolute paths, parent-directory traversal, symbolic-link abuse, and other unsafe entries.
  • Use an installation pattern such as:
bash
tmp_dir="$(mktemp -d)"
trap 'rm -rf -- "$tmp_dir"' EXIT
curl --fail --location \
  "https://github.com/KaigeGao1110/Project-Coordinator/archive/<pinned-commit>.zip" \
  --output "$tmp_dir/project-coordinator.zip"
echo "<expected-sha256>  $tmp_dir/project-coordinator.zip" | sha256sum --check -
unzip "$tmp_dir/project-coordinator.zip" -d "$tmp_dir/extracted"

The placeholder commit and digest must be replaced with immutable, audited release values.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
**Note:** The Coordinator should NOT directly read, copy, move, or delete session transcript files. All such operations must be performed by a dedicated archive-subagent using the archive-project skill.

**Subagent sandboxing:** When spawning subagents, each subagent runs in an isolated sandbox with workspace-only filesystem access. Subagents cannot access credentials, environment variables, or session transcripts outside their scope. Network access is restricted per platform policy.

The Coordinator SHOULD directly call tools:
- `exec` — run commands, check files

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The language section states that all output is in English, which imposes a fixed language policy on users and agents. Under the policy criteria, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises permissions to spawn subagents, read workspace files, and execute shell commands, but it does not pair those capabilities with a prominent user-facing warning or consent flow. That makes it easier for users to invoke a materially powerful automation path without understanding that code execution and file modifications may occur.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

git clone https://github.com/KaigeGao1110/Project-Coordinator.git ~/.openclaw/skills/project-coordinator

Or download directly

curl -L https://github.com/KaigeGao1110/Project-Coordinator/archive/refs/heads/main.zip -o /tmp/project-coordinator.zip unzip /tmp/project-coordinator.zip -d ~/.openclaw/skills/ mv ~/.openclaw/skills/Project-Coordinator-main ~/.openclaw/skills/project-coordinator

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough that the skill may activate for loosely defined project-like requests without strong user confirmation. In a skill that can spawn subagents, read workspace files, and execute shell commands, ambiguous activation increases the chance of unintended privileged actions being taken on the user's behalf.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The architecture section states 'Main Session (never runs code directly)' and presents the Coordinator as the execution boundary, but later documentation explicitly says the Coordinator itself should directly call exec, write, and read tools. This is an internal documentation contradiction about where direct tool execution occurs, which can mislead operators about the skill's actual execution model.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.