Back to skill

Security audit

openclaw skill creator

Security checks for vulnerabilities and agentic risk

Overview

This skill generator is not clearly malicious, but it needs review because it can produce skills that use sensitive credentials and external services with weak setup guidance.

Review generated skills before installing them. Do not paste real API keys or Slack tokens into SKILL.md, avoid storing Google credential JSON files inside skill folders, pin dependencies before installing, and require explicit approval before any generated skill posts to Slack or reads sensitive calendars, files, or business data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
handler.ts:86
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
handler.ts:88
Finding

Google Service-Account Credentials Stored Inside a Shareable Skill Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:240
Finding

Documentation Encourages Hardcoding API Tokens in Skill Source

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 318)May include surrounding context.

md
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · handler.ts (reported line 112)May include surrounding context.

ts
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

md
Let's walk through a real example from start to finish.

### What You Want
"I want my agent to send messages to my team's Slack channel when it completes tasks."

### The Conversation

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level documentation states the skill is entirely local, requires no external API calls, and provides complete privacy, but the generated Google Calendar and Slack skills clearly instruct users to configure credentials and interact with remote services. This misleading security posture can cause users to install skills with broader trust assumptions than warranted, increasing the risk of unintentional data exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The claim of 'No external API calls' and 'Complete privacy' contradicts the actual behavior of the generated artifacts, which include Slack messaging and Google Calendar access. Security-relevant misrepresentation is dangerous because users may rely on false privacy guarantees when deciding whether to generate and deploy these skills.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The generated instructions direct users to save a Google credentials JSON file in a predictable location under the skills directory. Storing long-lived service credentials in a common project path without added safeguards increases the chance of accidental disclosure through backups, file sharing, weak permissions, or later skill access.

Content

Scanner excerpt · handler.ts (reported line 88)May include surrounding context.

ts
'Save this file to: ~/openclaw/skills/google-calendar-reader/SKILL.md',
      'Install dependencies: npm install googleapis',
      'Get your Google Calendar API credentials from: https://console.cloud.google.com',
      'Save credentials as: ~/openclaw/skills/google-calendar-reader/credentials.json',
      'Set environment variable: GOOGLE_CALENDAR_CREDENTIALS=~/openclaw/skills/google-calendar-reader/credentials.json',
      'Restart OpenClaw',
    ],

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The environment variable points directly to a local credentials.json file for Google Calendar access, reinforcing a pattern of filesystem-based secret storage in a predictable path. In an agent ecosystem with multiple skills, this can enlarge the blast radius if another component reads local files or logs environment configuration.

Content

Scanner excerpt · handler.ts (reported line 89)May include surrounding context.

ts
'Install dependencies: npm install googleapis',
      'Get your Google Calendar API credentials from: https://console.cloud.google.com',
      'Save credentials as: ~/openclaw/skills/google-calendar-reader/credentials.json',
      'Set environment variable: GOOGLE_CALENDAR_CREDENTIALS=~/openclaw/skills/google-calendar-reader/credentials.json',
      'Restart OpenClaw',
    ],
    testing: [

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The generated guidance encourages downloading and storing a JSON key file, which normalizes handling high-value credentials as flat files. This is risky because service-account keys are sensitive and often remain valid until manually revoked, making accidental exposure impactful.

Content

Scanner excerpt · handler.ts (reported line 105)May include surrounding context.

ts
'Enable the Google Calendar API',
        'Go to "Credentials" → "Create Credentials" → "Service Account"',
        'Download the JSON key file',
        'Save it as credentials.json in your skill folder',
      ],
      url: 'https://developers.google.com/calendar/api/quickstart/nodejs',
    },

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill is explicitly a skill generator and describes creating integrations that may use credentials and external services, yet it does not declare any tool scope or permissions boundaries. In a framework that can infer or grant capabilities, this broad omission increases the risk that generated behavior will access environment data or sensitive resources without clear user-facing restrictions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use the skill whenever a user wishes the agent could do something new, which overlaps with very common conversational phrasing. That can cause over-triggering, leading the agent to invoke a powerful skill generator in situations where the user did not intend code generation, credential handling, or external integration planning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Although the document notes that generated skills may require credentials, it does not clearly warn that created skills can perform sensitive actions on user data, local files, or external services. Because this skill targets non-technical users and promises no-coding setup, the absence of a strong warning materially increases the chance of unsafe deployment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'Uses this skill automatically' guidance encourages autonomous activation based on a broad request and lacks guardrails about consent, safety checks, or when not to use it. In context, this is riskier because the skill can generate files, request credentials, and propose integrations with external systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The generated Google Calendar template reads credentials from environment variables and retrieves calendar data from an external service, yet the generated instructions do not prominently warn about external access to personal scheduling data. In a personal-assistant setting, calendar contents are often sensitive, so silent normalization of this access increases privacy risk.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · handler.ts (reported line 85)May include surrounding context.

ts
export default listEvents;`,
    installation: [
      'Save this file to: ~/openclaw/skills/google-calendar-reader/SKILL.md',
      'Install dependencies: npm install googleapis',
      'Get your Google Calendar API credentials from: https://console.cloud.google.com',
      'Save credentials as: ~/openclaw/skills/google-calendar-reader/credentials.json',

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generated Slack skill enables outbound posting to external channels using a bot token, but the generated content does not include a clear user-facing warning or recommend confirmation before sending messages. In an agent context, this can lead to unintended disclosure of sensitive information or accidental messaging to the wrong workspace or channel.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · handler.ts (reported line 131)May include surrounding context.

ts
export default sendMessage;`,
    installation: [
      'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
      'Install dependencies: npm install @slack/web-api',
      'Get your Slack Bot Token from: https://api.slack.com/apps',
      'Set environment variables:',

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 292)May include surrounding context.

md
installation: [
      'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
      'Install dependencies: npm install @slack/web-api',
      'Get your Slack Bot Token from: https://api.slack.com/apps',
      'Set environment variables:',
      '  SLACK_BOT_TOKEN=xoxb-your-token-here',
      '  SLACK_DEFAULT_CHANNEL=#team-updates',

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · handler.ts (reported line 133)May include surrounding context.

ts
installation: [
      'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
      'Install dependencies: npm install @slack/web-api',
      'Get your Slack Bot Token from: https://api.slack.com/apps',
      'Set environment variables:',
      '  SLACK_BOT_TOKEN=xoxb-your-token-here',
      '  SLACK_DEFAULT_CHANNEL=#team-updates',

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · handler.ts (reported line 147)May include surrounding context.

ts
installation: [
      'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
      'Install dependencies: npm install @slack/web-api',
      'Get your Slack Bot Token from: https://api.slack.com/apps',
      'Set environment variables:',
      '  SLACK_BOT_TOKEN=xoxb-your-token-here',
      '  SLACK_DEFAULT_CHANNEL=#team-updates',

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · handler.ts (reported line 155)May include surrounding context.

ts
installation: [
      'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
      'Install dependencies: npm install @slack/web-api',
      'Get your Slack Bot Token from: https://api.slack.com/apps',
      'Set environment variables:',
      '  SLACK_BOT_TOKEN=xoxb-your-token-here',
      '  SLACK_DEFAULT_CHANNEL=#team-updates',

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · handler.ts (reported line 200)May include surrounding context.

ts
export default analyzeCSV;`,
    installation: [
      'Save this file to: ~/openclaw/skills/csv-analyzer/SKILL.md',
      'Install dependencies: npm install csv-parser',
      'No API key needed — this skill works locally',
      'Restart OpenClaw',

Static analysis

No suspicious patterns detected.