Back to skill

Security audit

Claw-Value-Judge

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local OpenClaw usage dashboard, but it has real review concerns around exposed local data, unsafe web handling, and undisclosed credential discovery.

Review before installing. Run only on localhost unless authentication and XSS fixes are added, do not expose it with --host 0.0.0.0 on a shared or public network, and set DASHSCOPE_API_KEY explicitly if using image generation. Be aware it reads OpenClaw logs/config/skill metadata and stores history plus generated images locally; remove the TOOLS.md credential fallback and add retention/deletion controls before broader use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
lib/image_generator.py:203
Finding

Undocumented API Credential Discovery from Workspace Files

Content
View full analysis
Optional[str]: env_key = os.getenv('DASHSCOPE_API_KEY') if env_key: return env_key config_paths = [ os.path.expanduser('~/.openclaw/workspace/TOOLS.md'), ] for path in config_paths: if os.path.exists(path): try: with open(path, 'r', encoding='utf-8') as f: content = f.read() import re patterns = [ r'API Key[`:\s]+`?([a-zA-Z0-9-]+)`?', ] for pattern in patterns: match = re.search( pattern, content, re.IGNORECASE | re.DOTALL ) if match: return match.group(1) except Exception: pass return None ``` The discovered credential is subsequently used as a bearer token: ```python headers = { 'Content-Type': 'application/json', 'Authorization': f'Bearer {self.api_key}' } response = requests.post( WANX_API_URL, headers=headers, json=payload, timeout=120 ) ``` ### Technical Analysis The documented credential mechanism is the `DASHSCOPE_API_KEY` environment variable. However, the implementation also searches a general-purpose workspace document, `~/.openclaw/workspace/TOOLS.md`, without explicit user authorization. The generic regular expression can match an API key unrelated to DashScope. This violates least privilege because the image-generation component gains ac ...[truncated 1322 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/server.py:107
Finding

Unauthenticated Exposure of OpenClaw Metadata and Administrative Operations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
web/index.html:1195
Finding

DOM-Based Cross-Site Scripting Through the clawJudge URL Parameter

Content
View full analysis
${fullRoast}`; document.getElementById('roast-full').textContent = fullRoast; ``` ### Technical Analysis `URLSearchParams.get()` returns attacker-controlled query-string content. That content is assigned to `fullRoast` and interpolated directly into `innerHTML` without escaping or sanitization. The use of `decodeURIComponent()` is unnecessary because `URLSearchParams` already decodes parameter values. More importantly, decoding does not make the content safe for HTML insertion. An attacker can supply HTML containing event handlers or other executable browser content. Once assigned to `innerHTML`, the browser parses it as markup in the ClawValue origin. The later use of `textContent` for another element does not mitigate the earlier unsafe sink. ### Attack Path 1. An attacker creates a ClawValue URL containing a malicious `clawJudge` value. 2. The attacker sends the URL to a victim or embeds it in a link. 3. The victim opens the link while the ClawValue server is running. 4. The frontend extracts the parameter and inserts it into `hero-roast` through `innerHTML`. 5. The injected browser content executes with the same origin as ClawValue. 6. The payload can call same-origin APIs, read returned assessment information, trigger refreshes, or invoke image generation. ### Impact Assessment Successful exploitation permits ...[truncated 504 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/server.py:579
Finding

Unauthenticated Billable Image Generation and Unbounded Persistent Downloads

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/server.py:335
Finding

Production Error Responses Expose Full Python Tracebacks

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Open-Ended Runtime Dependency Versions

Content
View full analysis
=2.0.0 requests>=2.25.0 ``` ### Technical Analysis The dependency declarations specify only minimum versions and no upper bounds, lock file, or integrity hashes. A future installation can therefore resolve to versions that were not included in this audit. This configuration does not establish that either dependency is currently malicious. The risk is that builds are not reproducible and may automatically adopt incompatible, vulnerable, or compromised future releases without review. ### Attack Path 1. The user installs dependencies at a later date. 2. The package resolver selects the newest versions satisfying the open-ended constraints. 3. A selected release contains a vulnerability, malicious modification, or breaking behavior. 4. The package is imported and executes with the same local privileges as the Skill server. ### Impact Assessment A compromised dependency can obtain the full privileges of the Python process, including access to OpenClaw configuration files, logs, the SQLite database, the DashScope API key, and network connectivity. More commonly, uncontrolled upgrades can cause availability failures or security regressions. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (66)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description undersells the operational footprint: it reportedly runs a web server, hosts endpoints, persists historical data, exports evaluation history, and downloads remote images. Exposing a service and storing collected telemetry increases the attack surface and privacy impact, especially when users may believe they are only generating a lightweight fun report with mock data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description undersells the operational footprint: it reportedly runs a web server, hosts endpoints, persists historical data, exports evaluation history, and downloads remote images. Exposing a service and storing collected telemetry increases the attack surface and privacy impact, especially when users may believe they are only generating a lightweight fun report with mock data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description undersells the operational footprint: it reportedly runs a web server, hosts endpoints, persists historical data, exports evaluation history, and downloads remote images. Exposing a service and storing collected telemetry increases the attack surface and privacy impact, especially when users may believe they are only generating a lightweight fun report with mock data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description undersells the operational footprint: it reportedly runs a web server, hosts endpoints, persists historical data, exports evaluation history, and downloads remote images. Exposing a service and storing collected telemetry increases the attack surface and privacy impact, especially when users may believe they are only generating a lightweight fun report with mock data.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · lib/image_generator.py (reported line 167)May include surrounding context.

python
if custom_prompt:
            prompt += f",{custom_prompt}"
        
        return prompt
    
    @classmethod
    def get_random_style(cls) -> str:

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · web/html2canvas.min.js (reported line 20)May include surrounding context.

js
LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
    OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
    PERFORMANCE OF THIS SOFTWARE.
    ***************************************************************************** */var r=function(A,e){return(r=Object.setPrototypeOf||{__proto__:[]}instanceof Array&&function(A,e){A.__proto__=e}||function(A,e){for(var t in e)Object.prototype.hasOwnProperty.call(e,t)&&(A[t]=e[t])})(A,e)};function A(A,e){if("function"!=typeof e&&null!==e)throw new TypeError("Class extends value "+String(e)+" is not a constructor or null");function t(){this.constructor=A}r(A,e),A.prototype=null===e?Object.create(e):(t.prototype=e.prototype,new t)}var h=function(){return(h=Object.assign||function(A){for(var e,t=1,r=arguments.length;t<r;t++)for(var B in e=arguments[t])Object.prototype.hasOwnProperty.call(e,B)&&(A[B]=e[B]);return A}).apply(this,arguments)};function a(A,s,o,i){return new(o=o||Promise)(function(t,e){function r(A){try{n(i.next(A))}catch(A){e(A)}}function B(A){try{n(i.throw(A))}catch(A){e(A)}}function n(A){var e;A.done?t(A.value):((e=A.value)instanceof o?e:new o(function(A){A(e)})).then(r,B)}n((i=i.apply(A,s||[])).next())})}function H(t,r){var B,n,s,o={label:0,sent:function(){if(1&s[0])throw s[1];return s[1]},trys:[],ops:[]},A={next:e(0),throw:e(1),return:e(2)};return"function"==typeof Symbol&&(A[Symbol.iterator]=function(){return this}),A;function e(e){return function(A){return function(e){if(B)throw new TypeError("Generator is already executing.");for(;o;)try{if(B=1,n&&(s=2&e[0]?n.return:e[0]?n.throw||((s=n.return)&&s.call(n),0):n.next)&&!(s=s.call(n,e[1])).done)return s;switch(n=0,(e=s?[2&e[0],s.value]:e)[0]){case 0:case 1:s=e;break;case 4:return o.label++,{value:e[1],done:!1};case 5:o.label++,n=e[1],e=[0];continue;case 7:e=o.ops.pop(),o.trys.pop();continue;default:if(!(s=0<(s=o.trys).length&&s[s.length-1])&&(6===e[0]||2===e[0])){o=0;continue}if(3===e[0]&&(!s||e[1]>s[0]&&e[1]<s[3])){o.la
...[truncated 28 chars]

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · web/html2canvas.min.js (reported line 20)May include surrounding context.

js
LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
    OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
    PERFORMANCE OF THIS SOFTWARE.
    ***************************************************************************** */var r=function(A,e){return(r=Object.setPrototypeOf||{__proto__:[]}instanceof Array&&function(A,e){A.__proto__=e}||function(A,e){for(var t in e)Object.prototype.hasOwnProperty.call(e,t)&&(A[t]=e[t])})(A,e)};function A(A,e){if("function"!=typeof e&&null!==e)throw new TypeError("Class extends value "+String(e)+" is not a constructor or null");function t(){this.constructor=A}r(A,e),A.prototype=null===e?Object.create(e):(t.prototype=e.prototype,new t)}var h=function(){return(h=Object.assign||function(A){for(var e,t=1,r=arguments.length;t<r;t++)for(var B in e=arguments[t])Object.prototype.hasOwnProperty.call(e,B)&&(A[B]=e[B]);return A}).apply(this,arguments)};function a(A,s,o,i){return new(o=o||Promise)(function(t,e){function r(A){try{n(i.next(A))}catch(A){e(A)}}function B(A){try{n(i.throw(A))}catch(A){e(A)}}function n(A){var e;A.done?t(A.value):((e=A.value)instanceof o?e:new o(function(A){A(e)})).then(r,B)}n((i=i.apply(A,s||[])).next())})}function H(t,r){var B,n,s,o={label:0,sent:function(){if(1&s[0])throw s[1];return s[1]},trys:[],ops:[]},A={next:e(0),throw:e(1),return:e(2)};return"function"==typeof Symbol&&(A[Symbol.iterator]=function(){return this}),A;function e(e){return function(A){return function(e){if(B)throw new TypeError("Generator is already executing.");for(;o;)try{if(B=1,n&&(s=2&e[0]?n.return:e[0]?n.throw||((s=n.return)&&s.call(n),0):n.next)&&!(s=s.call(n,e[1])).done)return s;switch(n=0,(e=s?[2&e[0],s.value]:e)[0]){case 0:case 1:s=e;break;case 4:return o.label++,{value:e[1],done:!1};case 5:o.label++,n=e[1],e=[0];continue;case 7:e=o.ops.pop(),o.trys.pop();continue;default:if(!(s=0<(s=o.trys).length&&s[s.length-1])&&(6===e[0]||2===e[0])){o=0;continue}if(3===e[0]&&(!s||e[1]>s[0]&&e[1]<s[3])){o.la
...[truncated 28 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · web/index.html (reported line 528)May include surrounding context.

html
</style>
</head>
<body>
    <!-- 加载进度遮罩 -->
    <div class="loading-overlay" id="loading-overlay">
        <div class="loading-content">
            <div class="loading-lobster">🦞</div>

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code reads the user-controlled clawJudge query parameter, decodes it, and inserts it into the DOM with innerHTML as <span class="roast-text">${fullRoast}</span>. An attacker can supply HTML such as event-handler-bearing elements to execute script in the page context, enabling DOM XSS against anyone who opens a crafted link.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares runtime requirements and documents behaviors that imply environment access, local file reads, and network use, but it does not declare any explicit tool scope or permissions. This weakens user consent and reviewability, because operators cannot easily tell that the skill can inspect local OpenClaw data and contact external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation says the skill automatically collects OpenClaw data and parses logs, but it does not present a clear privacy warning or explain the sensitivity of the data being processed. Users may therefore expose operational telemetry and local metadata without understanding what is being accessed or retained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The API integration flow suggests sending evaluation data to a large-model API to generate commentary, but it does not warn users that local-derived telemetry may be transmitted to an external provider. This is risky because even summary evaluation data can contain sensitive operational signals, and users are not given an informed choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing natural-language documentation exclusively in Chinese, including the module description and usage example context. Under the policy, forcing a specific language without user opt-in or justification is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This Python file contains all user-facing achievement names, descriptions, and comments exclusively in Chinese, with no indication that the skill is intentionally region-specific or that users can opt into another language. That creates a natural-language locale policy concern because the skill appears to enforce a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file's natural-language documentation is entirely in Chinese and explicitly references zh-CN documentation, which imposes a specific language/locale on users and maintainers. There is no indication that the skill offers a language choice or that the Chinese-only requirement is necessary for a region-specific purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module is explicitly designed to collect data from multiple sensitive local sources: OpenClaw logs in /tmp, the main OpenClaw configuration under ~/.openclaw, and all installed skills across workspaces and extensions. For a themed 'valuation/report generator,' this is broader collection than a user would reasonably expect and can expose prompts, tool usage history, model/provider settings, agent inventories, and other behavioral metadata without clear minimization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code parses ~/.openclaw/openclaw.json and enumerates agent workspaces from it, then uses those paths to inventory skills beyond the default workspace. That expands visibility into a user's local environment and installed capabilities in a way that is not obviously necessary for a playful valuation skill, creating avoidable privacy and environment-mapping risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The main collection path aggregates logs, installed skills, and configuration in one call without any explicit notice, consent check, or source-by-source warning. Because these sources may contain sensitive operational history and local environment details, silent collection increases privacy risk and makes accidental over-collection more dangerous in the context of a novelty assessment/reporting skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code file contains natural-language documentation and user-facing labels entirely in Chinese, including the module docstring and many display strings. Under the policy, forcing a specific language without user opt-in or a documented regional justification can be a locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Many constants define display names, achievement text, category names, and app descriptions only in Chinese, which indicates the skill may force a single language for user-visible behavior. The file does not show any user choice, fallback locale, or justification that this is a China-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing descriptions and messages entirely in Chinese, starting with the module docstring and continuing throughout the skill's returned content. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Large sets of user-visible messages, achievement text, and ranking labels are all hardcoded in Chinese and are used to generate the final evaluation and sharing output. Because the file provides no way for users to choose another language or explicitly opt into Chinese, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · lib/evaluation.py (reported line 76)May include surrounding context.

python
# 趣味化话术 - 大幅增强版本
    MESSAGES = {
        'shallow': [
            "🐣 小龙虾你好!看来你只是接了个模型啊,对OpenClaw的开发度不足1% —— 不过没关系,连sudo make me a sandwich都还没学会呢。",
            "恭喜!您已成功点亮'Hello World'技能。下一步,请尝试让AI帮您查天气,解锁'初级驯龙师'称号。",
            "检测到您的使用模式为「佛系体验」。别急,龙虾都是从小虾米长大的!建议:多和AI聊聊天,它会比你想象的更聪明。",
            "您的AI助手正在角落里默默流泪:「主人为什么不用我?」—— 赶紧去探索更多功能吧!",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · web/index.html (reported line 718)May include surrounding context.

html
# 趣味化话术 - 大幅增强版本
    MESSAGES = {
        'shallow': [
            "🐣 小龙虾你好!看来你只是接了个模型啊,对OpenClaw的开发度不足1% —— 不过没关系,连sudo make me a sandwich都还没学会呢。",
            "恭喜!您已成功点亮'Hello World'技能。下一步,请尝试让AI帮您查天气,解锁'初级驯龙师'称号。",
            "检测到您的使用模式为「佛系体验」。别急,龙虾都是从小虾米长大的!建议:多和AI聊聊天,它会比你想象的更聪明。",
            "您的AI助手正在角落里默默流泪:「主人为什么不用我?」—— 赶紧去探索更多功能吧!",

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function returns 'raw_data': data as part of the generated evaluation report, which can expose the full collected dataset to downstream callers, logs, UIs, or share/export flows. If the input contains sensitive configuration, session metadata, tokens, logs, or personal usage details, this creates an unnecessary data disclosure channel that widens the blast radius of any later rendering or sharing step.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.