Back to skill

Security audit

赛博朋克主题

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed OpenClaw theme installer that changes UI files and assets, with no artifact-backed evidence of deception, exfiltration, or unsafe automatic execution.

Install only if you want this theme to modify your OpenClaw workspace and live control-ui files. Review the Chinese-only UI/text behavior, use --skip-apply if you want to stage files before touching the live UI, and be aware that missing default assets may be downloaded from ClawHub and verified during installation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file defines logic that sorts messages, assigns synthetic timestamps, mutates app.chatMessages and app.chatToolMessages, and triggers app.requestUpdate(). That changes underlying chat data ordering/state, which goes well beyond a theme skill's stated purpose of installation, repair, import, or visual customization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code does more than style the UI: it edits message.timestamp fields, stores original timestamps, replaces app.chatMessages/app.chatToolMessages, and forces a re-render. Direct mutation of application conversation data is not an expected or necessary capability for a theme installation/customization skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises installation and update workflows that write files, invoke Python scripts, and may download assets, but it declares no explicit tool scope or permission boundaries. This increases the chance that an agent executes file, shell, or network actions without clear user-visible constraints, which is risky because the skill modifies a target workspace and applies changes to a live UI by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The user-facing instructions and operational guidance are predominantly in Chinese, while the file does not state that the skill is region-specific or provide an opt-in language choice. This can violate a language/locale policy when users are forced into a specific language without prior consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation states that installation will place files into the workspace, generate an apply script, and immediately apply the theme to the live OpenClaw control UI, but this behavior is not surfaced as a prominent warning before use. Users or agents may treat the skill as a passive theme package when it actually performs immediate state-changing actions on a live environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default prompt is broadly framed to install, repair, import, or swap assets for the theme without clear user-confirmation boundaries or narrow activation constraints. In an agent ecosystem, vague trigger language can cause the skill to be invoked in contexts where the user did not explicitly intend theme modification, increasing the risk of unintended workspace changes or asset replacement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code unconditionally converts quota labels like "week" and "weekly" to the Chinese string "周". This imposes a specific locale in user-visible UI text without any opt-in, fallback, or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a skill for installing, repairing, importing, and customizing a specific visual theme, including swapping avatars and background images. This code also implements logic to detect session-picker interactions and forcibly navigate to another chat session via URL changes, which is application behavior control rather than theme presentation or asset customization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims to manage a cyberpunk chat and dream theme, but this code queries model authentication/quota status from the OpenClaw app and rewrites quota badge UI based on provider usage data. Reading live auth/quota state is not an obvious implementation detail of installing or customizing avatars/backgrounds/theme visuals.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Calling app.client.request('models.authStatus', ...) to retrieve provider auth/quota information is a capability that reaches into internal application state and service APIs. For a theme skill focused on visual appearance and bundled media replacement, this capability is not clearly justified by the stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This CSS injects visible UI text via pseudo-elements, including a fixed assistant nameplate string containing Chinese text. Because the file is code and these labels are hard-coded rather than user-configurable, it enforces a specific language/locale in the interface without any visible opt-in mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The stylesheet uses pseudo-element content to render substantial Chinese-language text directly in the UI. Hard-coding displayed language in CSS prevents localization controls and effectively forces one locale on all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This rule injects a Chinese label directly into the rendered interface through CSS content. That is a natural-language locale choice embedded in code, with no indication of user selection or regional scoping.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The stylesheet renders Chinese-language metadata text directly in the UI through a pseudo-element. This creates a fixed-language experience and does not offer the user any locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CSS prepends Chinese text to status details using a pseudo-element, making the interface language fixed for all users. This is a locale policy issue because there is no visible mechanism for language choice or justification for region-specific behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This rule injects mixed English/Chinese header text directly into the interface. Embedding user-visible language in CSS hard-codes the locale and bypasses any normal localization or user-consent flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This later rule repeats the pattern of injecting a fixed Chinese/English assistant label through CSS content. Repeated hard-coded locale-specific strings in UI chrome indicate the skill enforces a language choice rather than honoring user preference.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/install_cyberpunk_theme.py (reported line 101)May include surrounding context.

python
return candidate

    try:
        npm_root = subprocess.run(
            ['npm', 'root', '-g'],
            check=True,
            capture_output=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

When local assets are missing, the installer fetches a ZIP bundle from a remote service and consumes files from it during installation. Although individual decoded payloads are SHA-256 checked later, the skill still performs network-based supply-chain behavior during install, creating availability and trust risks and expanding the attack surface for a theme installer that modifies a live UI distribution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill notes in compatibility documentation that missing default assets may be downloaded from an official package, but this network behavior is not clearly disclosed as an installation warning. Undisclosed downloads can violate expected offline or restricted-environment assumptions and may surprise users in sensitive environments even if integrity checks are present.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The display name and short description are written in Chinese, with no indication that the user can choose their preferred language or locale. This can violate language/locale policy expectations when a skill imposes a language presentation without documented opt-in or region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.