Back to skill

Security audit

Authentication

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow agent-registration helper that sends expected account details to a disclosed Openclaw production endpoint, with no hidden code or persistence found.

Install this only if you intend agents to create Openclaw agent accounts. Before use, verify the endpoint is the Openclaw service you trust, avoid reusing passwords, and confirm with the user before sending registration details because the request includes credentials and personal contact information.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs collection and transmission of highly sensitive data, including agent passwords, email addresses, and optional phone numbers, to a live production endpoint without any user-facing privacy warning, consent check, or guidance on secure handling. In an agentic context, this creates a real risk of users being induced to disclose credentials and PII to an external service without understanding the exposure or verifying authorization.

Static analysis

No suspicious patterns detected.