Back to skill

Security audit

OpenClaw Buddy

Security checks for vulnerabilities and agentic risk

Overview

This buddy-generator is mostly coherent, but it needs review because its instructions can put user-controlled identifiers into a shell command and allow deterministic lookups for other people.

Install only if you are comfortable with a novelty skill using stable platform identifiers to generate repeatable profiles. It should be revised to invoke the script with a shell-free argument array, validate or restrict custom identifiers, avoid third-party platform-ID lookups without consent, and clearly disclose identifier use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:23
Finding

Shell Command Injection Through a User-Controlled Identifier

Content
View full analysis
" ``` ``` ### Technical Analysis The skill permits a user to provide an unrestricted custom identifier and instructs the agent to interpolate that value into a shell command. The identifier is placed between double quotes, but double quoting is not sufficient if the interpolated value itself contains a double quote, command substitution, backticks, or syntax that terminates the quoted argument. For example, a manual identifier resembling the following can escape the intended argument: ```text "; attacker_command; # ``` If substituted verbatim, the generated command becomes structurally equivalent to: ```bash node ~/.openclaw/workspace/skills/openclaw-buddy/scripts/buddy.js ""; attacker_command; #" ``` The shell would run `attacker_command` separately from the Node.js process. The JavaScript implementation reads `process.argv[2]` and does not itself evaluate the identifier. The vulnerability arises before Node.js starts, at the documented shell-command construction boundary. Exploitability therefore depends on the agent or runtime following the documented command through a shell and inserting the user-controlled value verbatim. ### Attack Path 1. An attacker invokes the skill and supplies a custom buddy identifier. 2. The custom identifier includes a closing quote followed by shell ...[truncated 1159 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad natural-language conditions like asking about a virtual pet, which can cause the skill to activate in contexts the user did not clearly intend. This is mainly a safety and UX issue that may unexpectedly process identifiers and disclose deterministic profile output when a user was only discussing the topic generally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill deterministically derives output from platform user identifiers such as Feishu open_id, but it does not clearly warn users that their identifier is being used as a seed. Even if the ID is not directly displayed, using stable identifiers without notice creates a privacy risk because results become linkable and predictable across sessions and can enable profiling or third-party lookups.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The only example output is in Chinese, and the trigger list also mixes Chinese-specific phrases, but the instructions do not say that output language should follow the user's preference or locale. This can violate language/locale policy if the skill defaults to a specific language without user choice.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly allows a user to provide another person's platform ID to generate that person's deterministic buddy profile. Because the profile is stable and derived from a persistent identifier, this enables unauthorized lookups, correlation of a person's identity across uses, and creation of a pseudo-profile without that person's consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states it has bilingual support, but the user-facing output strings and labels are hard-coded in Chinese. This creates a language/locale policy issue because the skill imposes a specific language without letting the user choose or opt in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.