Back to skill

Security audit

Gateway Notify

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently installs a disclosed OpenClaw startup hook that sends gateway-start notifications to a user-selected messaging channel.

Install only if you want a persistent OpenClaw hook that automatically sends gateway startup metadata to your configured messaging service. Review the generated config.json and handler.ts before restarting the gateway, and verify ~/.openclaw/hooks/gateway-notify before using the uninstall deletion command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
1. Create the hook directory at `~/.openclaw/hooks/gateway-notify`
2. Generate `HOOK.md` and `handler.ts` with your channel config
3. Enable the hook
4. Print instructions to restart the gateway

After restart, you'll receive a notification like:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The uninstall command uses rm -rf on a filesystem path, which is inherently risky because it irreversibly deletes content without confirmation. In this skill, the path is constrained to the hook's installation directory, so the context lowers severity, but it still presents a real chance of accidental deletion if users copy, edit, or run the command in the wrong environment.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

bash
openclaw hooks disable gateway-notify
rm -rf ~/.openclaw/hooks/gateway-notify

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The uninstall command uses rm -rf on a filesystem path, which is inherently risky because it irreversibly deletes content without confirmation. In this skill, the path is constrained to the hook's installation directory, so the context lowers severity, but it still presents a real chance of accidental deletion if users copy, edit, or run the command in the wrong environment.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

bash
openclaw hooks disable gateway-notify
rm -rf ~/.openclaw/hooks/gateway-notify

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly sends gateway startup details, including timestamp and local gateway address, to third-party messaging services but does not warn users that operational metadata will leave the host and be processed by external providers. This creates a real privacy and data-handling risk, especially for users who may not realize startup events and network details are being transmitted off-system.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

text

The script will:
1. Create the hook directory at `~/.openclaw/hooks/gateway-notify`
2. Generate `HOOK.md` and `handler.ts` with your channel config
3. Enable the hook
4. Print instructions to restart the gateway

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The uninstall instructions include a recursive deletion command against a user directory without any warning to verify the path first. Although the target path is specific, destructive shell commands can cause accidental data loss if copied blindly, modified incorrectly, or expanded unexpectedly in edge cases.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated handler hard-codes toLocaleString("en-US", { hour12: false }), which imposes a specific locale in user-facing notification content. This is a natural-language/locale policy issue because the skill does not offer a language or locale choice, nor document why a U.S. English format is required.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL.md:104