Back to skill

Security audit

Channel Tree

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local hierarchy organizer that writes its own JSON state file and does not show evidence of hidden access, network use, credential handling, or destructive behavior.

Install this only if you want a local channel/session hierarchy stored under /root/.openclaw/workspace/channel_tree. Expect Chinese-language output and note that some documented commands, such as sessions and ->0, are not implemented in the bundled script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.


name: channel-tree description: Hierarchical session/channel management system: Hall → Universe → World → Forest → Tree → Channel. Multi-hall architecture, L1/L2/L3 inheritance, health monitoring, and session isolation. Triggers: "create hall", "build universe", "manage tree", "fork conversation", "organize hierarchy", "->0 to sync history and print tree".

Channel Tree Skill

Hierarchical management: 🏛️ Hall → 🌌 Universe → 🌍 World → 🌲 Forest → 📁 Tree → 📋 Channel

Hierarchy Levels

text
🏛️ Master's Hall (殿堂) - 主的领地,最大聚合
└── 🌌

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest advertises broad natural-language triggers such as "manage tree," "fork conversation," and "organize hierarchy," which are generic enough to match ordinary user requests unintentionally. In an agent environment, this can cause the skill to activate out of context and steer session management, context switching, or history synchronization actions the user did not explicitly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill documentation includes substantial Chinese-language content in hierarchy descriptions and command comments, but does not state that language selection is optional or user-driven. This can create a locale expectation without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language instructions and status messages that assume Chinese as the only interaction language. Under the policy, forcing a specific language without offering a locale choice or documenting a justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

switch_path() writes new values into os.environ, then immediately calls show_context(). However, show_context() prints the module-level constants CURRENT_HALL, CURRENT_UNIVERSE, CURRENT_WORLD, CURRENT_FOREST, and CURRENT_TREE, which were read once at import time and never refreshed, so the reported 'current context' can contradict the actual environment values just set.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.