Back to skill

Security audit

Visual Explainer for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

This skill mainly creates visual HTML reports, but it can gather broad project/session context and publish reports publicly, so users should review its scope before installing.

Use this skill only if you are comfortable with it reading repository content, git history, and in some workflows conversation or OpenClaw memory context, then writing persistent local HTML reports. Review reports for secrets or internal details before using the share workflow, avoid sharing by latest-file default on sensitive projects, and only use the Vercel helper or CDN-backed diagrams if you trust those external dependencies.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
``` 3. Parse and report the live URL and claim URL. **Requirements:** - `scripts/share.sh` expects a `vercel-deploy` helper script in an OpenClaw skill path (see script output if missing). **Notes:** - Deployments are public. - Keep the local file path in your response so the user can re-share later. ``` ### Technical Analysis The diff-review and project-recap workflows direct the Agent to inspect persistent files under `~/.openclaw/workspace/memory/` and mine conversation history. This collection exten ...[truncated 2624 chars]:16
Finding

Excessive Collection and Persistence of Agent Memory and Conversation History

Content
View full analysis
` for file-level overview - `git diff --name-status --` for new/modified/deleted files (separate src from tests) - Line counts: compare key files between `` and working tree (`git show :file | wc -l` vs `wc -l`) - New public API surface: grep added lines for exported symbols, public functions, classes, interfaces (adapt the pattern to the project's language — `export`/`function`/`class`/`interface` for TS/JS, `def`/`class` for Python, `func`/`type` for Go, etc.) - Feature inventory: grep for new actions, keybindings, config fields, event types on both sides - Read all changed files in full — include surrounding code paths needed to validate behavior - Check whether `CHANGELOG.md` has an entry for these changes - Check whether `README.md` or `docs/*.md` need updates given any new or changed features - Reconstruct decision rationale: if this work was done in the current session, mine the conversation for approaches discussed, alternatives rejected, and trade-offs made. Check for progress docs (`~/.openclaw/workspace/memory/{project}/progress.md`, `memory/YYYY-MM-DD.md`, `OPEN_ITEMS.md`) or plan files that may contain reasoning. For committed changes, read commit messages and PR descriptions. ``` From `prompts/project-recap.md:14-24`: ```markdown **Data gathering phase** — run these first to understand the project: 1. **Project identity.** Read `README.md`, `CHANGELOG.md`, `package.json` / `Cargo.toml` / `pyproject.toml` / `go.mod` for name, description, version, dependencies. Read the top-l ...[truncated 5112 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/share.sh:26
Finding

Mutable CDN Code and Unverified External Deployment Helper Execution

Content
View full analysis
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjs'; import elkLayouts from 'https://cdn.jsdelivr.net/npm/@mermaid-js/layout-elk/dist/mermaid-layout-elk.esm.min.mjs'; ``` From `templates/slide-deck.html:798-800`: ```html ``` ```html ``` From `scripts/share.sh:26-44`: ```bash # Find vercel-deploy helper script (OpenClaw-first, then legacy paths) VERCEL_SCRIPT="" for dir in \ ~/.openclaw/workspace/skills/vercel-deploy/scripts \ ~/.openclaw/skills/vercel-deploy/scripts \ /usr/local/lib/node_modules/openclaw/skills/vercel-deploy/scripts \ ~/.pi/agent/skills/vercel-deploy/scripts \ /mnt/skills/user/vercel-deploy/scripts do if [ -f "$dir/deploy.sh" ]; then ...[truncated 3711 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (72)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented primarily as a local HTML visualization generator, but it also includes a workflow to publicly deploy generated output to Vercel. That mismatch is security-relevant because users or higher-level orchestrators may authorize the skill expecting only local file generation, while the skill can publish potentially sensitive content to a public URL.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
3. Keep `SKILL.md` and `skill.json` in this folder as the OpenClaw-adapted entrypoints

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

Embed in HTML and clean up

descriptive alt text

rm /tmp/ve-img.png

text

See `./references/css-patterns.md` for image container styles (hero banners, inline illustrations, captions).

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt materially expands the skill from generating visual explanations into a broad codebase auditor/editor that reads arbitrary files, interrogates git history, and rewrites documents in place. That scope shift is dangerous because users or orchestrators invoking a presentation-focused skill may not expect repository-wide inspection and direct modification of original content, increasing the chance of unintended data access and destructive edits.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/css-patterns.md (reported line 1028)May include surrounding context.

html
<svg class="connectors" style="position:absolute;inset:0;width:100%;height:100%;pointer-events:none;">
  <path d="M 150,100 C 150,200 350,100 350,200" fill="none" stroke="var(--accent)" stroke-width="1.5" stroke-dasharray="4 3"/>
  <!-- Arrowhead -->
  <polygon points="348,195 352,205 356,195" fill="var(--accent)"/>
</svg>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/slide-patterns.md (reported line 40)May include surrounding context.

...
...
...
```

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/slide-patterns.md (reported line 538)May include surrounding context.

md
</ul>
    </div>
    <div class="slide__aside reveal">
      <!-- optional: illustration, icon, mini-diagram, accent SVG -->
    </div>
  </div>
</section>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Including rm /tmp/ve-slide-title.png as part of a prescribed workflow encourages direct shell command execution and file deletion based on prompt instructions. While the specific path is fixed and low-risk in isolation, this pattern trains the agent to perform destructive shell actions from untrusted content and can combine dangerously with broader tool-use behaviors.

Content

Scanner excerpt · references/slide-patterns.md (reported line 1146)May include surrounding context.

Clean up

rm /tmp/ve-slide-title.png

text

**Prompt craft for slides:** Be specific about style, dominant colors, and mood. Pull colors from the preset's CSS variables. Examples:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script searches for and invokes an external deployment helper, enabling network publication capability that is not justified by the declared purpose of a visual HTML generator. This hidden expansion of capability is dangerous because users or higher-level tooling may trust the skill as local-only while it actually exfiltrates output to a third-party hosting service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script takes a local HTML file and deploys it to a publicly reachable Vercel URL, creating external data exposure functionality that goes beyond the skill's stated role of generating self-contained HTML. In an agent context, generated pages may contain sensitive plans, code diffs, architecture details, or user data, so publishing them without strong consent and guardrails can leak confidential information.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/architecture.html (reported line 7)May include surrounding context.

html
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Architecture Diagram — Reference Template</title>
<!--
  Reference template for the visual-explainer skill: CSS Grid architecture layout.
  Warm terracotta/sage palette — distinctly different from the teal (mermaid)
  and rose (data-table) templates so agents absorb variety, not a single palette.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/mermaid-flowchart.html (reported line 7)May include surrounding context.

html
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>CI/CD Pipeline — Reference Template</title>
<!--
  Reference template for the visual-explainer skill: Mermaid diagrams.
  Teal/cyan palette — distinctly different from terracotta (architecture)
  and rose (data-table) templates so agents absorb variety.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/slide-deck.html (reported line 7)May include surrounding context.

html
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>API Gateway Redesign — Reference Slide Deck</title>
<!--
  Reference template for the visual-explainer skill: slide decks.
  Midnight Editorial preset — deep navy, serif display, warm gold accents.
  Distinctly different from the terracotta (architecture), teal (mermaid),

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/slide-deck.html (reported line 711)May include surrounding context.

html
</div>
  </section>

  <!-- SLIDE 7: DASHBOARD -->
  <section class="slide slide--dashboard" style="background-image:radial-gradient(ellipse at 70% 30%, var(--accent-dim) 0%, transparent 40%);">
    <h2 class="slide__heading reveal">Performance Impact</h2>
    <div class="slide__kpis">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/slide-deck.html (reported line 785)May include surrounding context.

html
<cite class="reveal">&mdash; Edge Computing Principle</cite>
  </section>

  <!-- SLIDE 11: FULL-BLEED -->
  <section class="slide slide--bleed">
    <div class="slide__bg slide__bg--gradient"></div>
    <div class="slide__scrim"></div>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The changelog advertises a zero-friction sharing flow that deploys generated HTML to a live public URL with 'no account or authentication required' and without any warning about sensitive content exposure. In the context of a visual explainer skill, outputs may include code diffs, architecture details, plans, or internal data, so encouraging instant publication materially increases the risk of accidental data leakage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use the skill when the user asks for "a diagram, architecture overview, diff review, plan review, project recap, comparison table, or any visual explanation of technical concepts." Phrases like "any visual explanation" and the wide list of common request types are very broad for a manifest/markdown trigger description, with no negative examples or clear boundaries for when the skill should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to "Also use proactively when you are about to render a complex ASCII table" relies on a subjective internal condition and can overlap with many normal responses. Although a threshold is given, it still lacks clear constraints about user consent or contexts where automatic HTML generation should be avoided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs automatic file creation and browser opening as a default behavior without a clear user warning or confirmation. This can create unexpected side effects, expose sensitive local content on screen, or trigger unintended application launches in environments where passive analysis was expected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented behavior says the skill creates self-contained local HTML explainers, but it also advertises a workflow that deploys them to a public URL. Even if optional, this expands the trust boundary from local-only rendering to external publication, creating risk of unintended disclosure of code, plans, or internal architecture.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
**Surfaces whisper, they don't shout.** Build depth through subtle lightness shifts (2-4% between levels), not dramatic color changes. Borders should be low-opacity rgba (`rgba(255,255,255,0.08)` in dark mode, `rgba(0,0,0,0.08)` in light) — visible when you look, invisible when you don't.

**Backgrounds create atmosphere.** Don't use flat solid colors for the page background. Subtle gradients, faint grid patterns via CSS, or gentle radial glows behind focal areas. The background should feel like a space, not a void.

**Visual weight signals importance.** Not every section deserves equal visual treatment. Executive summaries and key metrics should dominate the viewport on load (larger type, more padding, subtle accent-tinted background zone). Reference sections (file maps, dependency lists, decision logs) should be compact and stay out of the way. Use `<details>/<summary>` for sections that are useful but not primary — the collapsible pattern is in `./references/css-patterns.md`.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The share feature is not necessary for the core purpose of generating visual explanation pages, yet it introduces public deployment and dependency on an external helper. Unnecessary outbound publication features increase attack surface and can lead to data exposure if used on sensitive generated pages.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt explicitly instructs the agent to mine conversation history and local memory/progress files to reconstruct rationale, which goes beyond what is necessary to generate a diff review. This creates an avoidable privacy boundary violation: unrelated sensitive notes, prior session content, or workspace memory may be accessed and surfaced in the output without user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt instructs access to conversation history and local memory/progress files without any privacy notice, consent gate, or scope limitation. Because diff review does not inherently require those sources, this unnecessarily broadens access to potentially sensitive user/project information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The optional surf gemini --generate-image step invokes an external tool/service unrelated to the core requirement of producing an HTML diff review. That can exfiltrate repository-derived concepts or change details to a third-party model and expands the attack surface without clear necessity or consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.