Back to skill

Security audit

OpenClaw RPA

Security checks for vulnerabilities and agentic risk

Overview

This RPA skill is coherent, but it asks for high-impact local automation authority while storing cookies and API keys insecurely and executing generated Python code on the user's machine.

Install only if you are comfortable with a desktop RPA tool that can run generated Python, store login cookies and API keys on disk, send screenshots to configured vision providers, and make arbitrary API calls. Use a dedicated workspace or VM, avoid real production credentials where possible, review generated scripts before replay, rotate any keys placed into scripts, and delete saved cookie/key files when no longer needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
recorder_server.py:944
Finding

Arbitrary Python execution in the recorder process

Content
View full analysis
", "exec") exec(compiled, ns) ``` The execution path is exposed through the recorder action: ```python elif action == "python_snippet": raw_code = (data.get("code") or "").rstrip() if not raw_code.strip(): error = "python_snippet requires a non-empty 'code' field" else: error = await _python_snippet_run(raw_code, page) if not error: if "page.evaluate" in raw_code: global _SESSION_HAS_PAGE_EVALUATE _SESSION_HAS_PAGE_EVALUATE = True error = _check_snippet_reads_extract_files(raw_code) if not error: code_block = _step_code(step_n, context, raw_code.splitlines()) ``` ### Technical Analysis The recorder compiles and executes supplied Python inside its own process. The execution namespace does not remove or replace `__builtins__`. Python therefore makes standard built-ins available, including `__import__`, `open`, `eval`, and `exec`. Restricting the methods of the Playwright `page` object does not restrict Python itself. A snippet can import `os`, `subprocess`, `socket`, or HTTP libraries; read arbitrary files accessible to the recorder account; modify files; start processes; and communicate with arbitrary network services. The post-execution structural check does not provide preventive isolation. It runs only after the snippet has already executed, so rejecting the snippet at that stage cannot reverse its side effects. ### Attack Path 1. An attacker places prompt-injection content on a website or influences the task instructions processed by the agent. 2. The content induces the agent to submit a `python_snippet` action containing at ...[truncated 972 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
recorder_server.py:2232
Finding

Vision API credentials are embedded directly into generated scripts

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
recorder_server.py:2251
Finding

Vision screenshots and bearer credentials are transmitted with TLS verification disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
recorder_server.py:1979
Finding

Arbitrary API actions can automatically disable TLS certificate verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
recorder_server.py:2456
Finding

Authenticated browser cookies are stored and replayed as plaintext bearer credentials

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
recorder_server.py:1979
Finding

Agent-controlled API requests permit SSRF and internal-network access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
recorder_server.py:2048
Finding

Executed snippets are persisted verbatim into standalone replay scripts

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Dependency installation is not reproducibly pinned or integrity verified

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (127)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly promotes saving login cookies and auto-injecting them into future runs to bypass repeated authentication, but does not emphasize that session cookies are effectively bearer tokens. If those stored cookies are stolen, reused by another process, or mishandled, an attacker may gain account access without credentials or 2FA.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill encourages writing user-supplied API keys directly into scripts for replay while failing to provide a clear, prominent warning that the secret will be stored persistently in plaintext. Users may reasonably assume the key is transient, when in fact it becomes part of a long-lived executable artifact.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The onboarding/API guidance tells the agent to write provided API keys directly into scripts for future replay, normalizing insecure secret persistence as a feature. This is dangerous because it transforms a temporary credential submission into a durable secret embedded in executable code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs embedding user-supplied API secrets directly into generated replay scripts, creating persistent plaintext secret storage in files that may be reused, copied, backed up, or committed to source control. This materially increases the blast radius of any local compromise or accidental sharing.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These instructions operationalize direct secret embedding into generated scripts instead of transient or environment-based handling. That design bakes credentials into code artifacts, making compromise via logs, backups, file sharing, or repository upload much more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The vision-mode flow requests API keys for local caching and reuse but does not clearly warn users about where the credentials are stored, how long they are retained, or who can access them. This weak transparency around credential persistence can lead to accidental exposure and noncompliant handling of cloud secrets.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The vision flow asks users to paste third-party API keys, validates them, then caches and reuses them across sessions. Persisting reusable cloud credentials locally without strong storage guarantees or prominent warning creates a durable secret exposure risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The examples explicitly show generated scripts containing real API keys when the user supplies them, which can be copied verbatim into production behavior by implementers and users. Example code strongly shapes usage, so this materially reinforces insecure secret-handling patterns.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
zh-CN: "SKILL.zh-CN.md"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
zh-CN: "SKILL.zh-CN.md"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented python_snippet feature allows arbitrary Python injection into the generated script and states it is executed and validated at record time. That creates a direct arbitrary-code-execution pathway with access to local files, network, subprocesses, and possibly credentials, making this especially dangerous in a skill already designed to automate the host environment.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
rpa_manager.py`, resolve paths **relative to this skill directory** (parent of `SKILL.md`).

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The login flow instructs exporting and storing reusable cookies to a predictable local directory, which is effectively collecting and persisting authenticated session tokens. Those files can often be replayed for full account access, so this is sensitive-session-data storage with meaningful takeover risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill operationalizes a natural-language flow that collects real API keys and persists them into generated code, turning conversational input into a durable secret-at-rest artifact. This is a direct sensitive-data handling flaw because it normalizes credential ingestion and long-term storage without adequate containment.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill asks users to provide real API keys and says they may be written directly into generated scripts, yet it does not clearly warn that those scripts become long-lived secret containers. In context, this is more dangerous because the whole purpose is to generate reusable automation files likely to be rerun, shared, versioned, and stored broadly.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The vision workflow requires accepting user API keys and caching them locally for future reuse, creating persistent sensitive-credential storage driven by natural-language instructions. Because these keys can authorize paid external API usage, theft can lead to both data exposure and financial abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guidance recommends supplying real API keys in the env field and notes they will be written into the generated script, but it does not prominently warn that this causes secrets to be stored in plaintext. In an RPA skill that generates reusable automation scripts, this is especially dangerous because the artifacts are meant to be replayed, copied, and shared, increasing the chance of long-term credential leakage and abuse.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · articles/autologin-tutorial.en-US.md (reported line 197)May include surrounding context.

1 1 2026-04-07T11:01:00 ⚠️ No fixed expiry (session-type)

text

---

## FAQ

**Q: I sent `#rpa-autologin` but it says "session not found".**  
A: You haven't saved a cookie for that domain yet. Send `#rpa-login <login-page-URL>` to complete a real login first.

**Q: Where is the cookie file? Can I supply one manually?**  
A: Default path: `~/.openclaw/rpa/sessions/<domain>/cookies.json`. If you already have a Playwright-compatible cookie JSON (exported from Chrome DevTools, EditThisCookie, etc.), just drop it at that path — no need to run `#rpa-login`.

**Q: I need to log into several sites. Is that supported?**  
A: Yes. Run `#rpa-login` + `#rpa-login-done` for each site. Sessions are stored in separate per-domain subdirectories and don't interfere with each other.

**Q: Can I use the generated script on another machine?**  
A: Yes. Copy `~/.openclaw/rpa/sessions/<domain>/cookies.json` to the same path on the target machine, and point `CONFIG["cookies_path"]`

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · articles/autologin-tutorial.md (reported line 267)May include surrounding context.

1 2026-04-07T11:01:00 ⚠️ 无固定过期时间(会话型)

text

---

## 常见问题

**Q:`#rpa-autologin` 发送后提示「未找到登录会话」?**  
A:你还没有保存该域名的 Cookie,请先发送 `#rpa-login <登录页URL>` 完成一次真实登录。

**Q:Cookie 文件在哪里,能手动提供吗?**  
A:默认路径 `~/.openclaw/rpa/sessions/<域名>/cookies.json`。如果你已有从 Chrome DevTools 或其他工具导出的 Playwright 兼容格式 Cookie JSON,可以直接放到对应路径,无需执行 `#rpa-login`。

**Q:多个域名都需要登录怎么办?**  
A:对每个域名分别执行一次 `#rpa-login` + `#rpa-login-done`,保存的会话按域名隔离,互不干扰。

**Q:生成的脚本在其他机器上还能用 Cookie 吗?**  
A:可以。把 `~/.openclaw/rpa/sessions/<域名>/cookies.json` 复制到目标机器对应路径,脚本里 `CONFIG["cookies_path"]` 指向该文件即可。

**Q:携程登录�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document explicitly introduces a mode where AI-generated Python is injected into the script body and executed immediately during recording via exec(). That changes the skill from constrained, declarative RPA actions into arbitrary code execution, greatly expanding attack surface to filesystem access, network-capable libraries already in scope elsewhere, data tampering, and unintended side effects if prompt input or task context is adversarial.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code describes python_snippet as a sandbox, but the implementation exposes broad modules and default Python execution semantics. This mismatch is dangerous because users and higher-level agents may trust the feature as constrained when it can actually execute arbitrary logic, increasing the chance of unsafe use and hidden privilege expansion.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill advertises browser/Office/API automation, but this block adds an unrestricted arbitrary-Python execution capability during recording. That materially expands the trust boundary: instead of replaying user-visible automation steps, the agent can run local code on the host and access files, environment variables, and possibly network resources outside the declared scope.

Content

No source excerpt is available for this finding.

exec() call detected

High
Category
Dangerous Code Execution
Confidence
100% confidence
Finding

The recorder executes user-supplied python_snippet code with exec() and then awaits the resulting function, giving that code access to filesystem modules, environment variables, and helper objects. Because this runs at record time on the operator's machine, a malicious prompt or compromised action source could exfiltrate secrets, modify local files, or run arbitrary OS commands with the user's privileges.

Content

Scanner excerpt · recorder_server.py (reported line 1017)May include surrounding context.

python
# Execute: define __snippet__ then await it
    try:
        exec(compiled, ns)          # noqa: S102  — defines __snippet__ in ns
        await ns["__snippet__"]()   # run the async snippet
        print("[recorder] python_snippet 验证通过 / validation passed ✓", flush=True)
        return None

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · recorder_server.py (reported line 2278)May include surrounding context.

python
return __import__("json").loads(raw)
"""

    # Collect env vars used by __ENV:VAR__ placeholders in all api_call steps.
    # They appear in code blocks as:  os.environ.get("VAR_NAME", "")
    _env_var_re = re.compile(r'os\.environ\.get\("([A-Za-z_][A-Za-z0-9_]*)",\s*""\)')
    env_vars = sorted(set(_env_var_re.findall(steps)))

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The login flow writes all browser cookies to disk immediately after login completion, without an in-the-moment confirmation describing what is being saved and how it will be reused. Session cookies are bearer tokens; possession alone may enable account access, so undisclosed export materially raises account-compromise risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification, suspicious.obfuscated_code

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.zh-CN.md:181

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
recorder_server.py:225

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
rpa_manager.py:450

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
recorder_server.py:241