Back to skill

Security audit

Resilience Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed natural-language wrapper for a Resilience plugin, with high-trust monitoring behavior that appears purpose-aligned but should be installed deliberately.

Install this only if you want OpenClaw error/session monitoring and are comfortable granting the companion plugin sensitive local authority: hooks into model/session/tool events, a local dashboard, persistent logs/configuration, and retry/recovery controls. Review the companion plugin before using --dangerously-force-unsafe-install, and prefer explicit Resilience-named commands when opening dashboards or changing retry strategies.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises very broad natural-language triggers such as '查看今天报错统计' and '打开 resilience 面板', which could be matched during ordinary conversation rather than an explicit user request to invoke this skill. In this context, those triggers can cause unintended tool execution, including opening a browser/dashboard and exposing operational data, especially because the underlying plugin registers sensitive hooks and controls local services.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The dashboard-opening examples use very broad phrases such as '打开监控面板' and '打开错误统计页面' without naming the specific plugin, target, or requiring confirmation. In an agent environment, these generic triggers can cause the skill to hijack unrelated user requests and launch or expose the resilience dashboard unexpectedly, which is especially risky because the dashboard likely contains operational telemetry and configuration controls.

Static analysis

No suspicious patterns detected.