Back to skill

Security audit

Openclaw Master Skills Clawhub Pkg

Security checks for vulnerabilities and agentic risk

Overview

This package is a markdown catalog and install pointer, not executable code, but it advertises many powerful third-party skills that should be reviewed individually.

Installing this master package appears low risk by itself because it only provides markdown catalogue information. Do not assume the listed skills are approved: review each individual skill before installing, especially entries involving credentials, auto-updates, memory, desktop control, social posting, or broad startup triggers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A trigger of 'starting any conversation' is effectively universal and guarantees collision with normal agent behavior. This can let one skill dominate all sessions, potentially injecting policy, tool routing, or behavior changes before user intent is understood, which is particularly risky in a broad skill marketplace.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises skills with mandatory or near-global activation language such as 'before any work,' which can cause an agent to invoke the wrong skill across unrelated tasks. In an agent-skill ecosystem, overly broad triggers can hijack normal control flow, expand tool use unnecessarily, and create security or privacy side effects if those skills perform external actions or collect context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Saying a skill should be used any time a .pptx file is involved is too broad because mere presence of a file extension does not mean the specialized skill is appropriate. This can cause inappropriate routing, accidental file handling, or unneeded tool access when the user may only want a simple inspection, rename, or unrelated operation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The phrase 'ANY network request, API call, or data fetching' is effectively universal for modern software work and can force invocation of a skill far outside its safe or intended scope. In practice, this can steer agents toward external connectivity, credential use, or network-side effects even when simpler local reasoning would suffice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

A blanket rule that a skill 'MUST be used for Vue.js tasks' is overly broad and can override user intent, agent judgment, or safer alternatives. For a repository aggregating many skills, this kind of mandatory language increases the chance of conflicting skill selection and overreach into tasks that do not need the toolchain or behavior described by that skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

'Stop waiting for prompts. Keep working.' signals autonomous continuation without clear limits, which is risky in an agent environment where actions may include file changes, network access, or other side effects. Ambiguous autonomy can lead to unapproved actions, runaway task expansion, or persistence beyond the user's intended scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

A skill that automatically updates the agent and all installed skills once daily introduces supply-chain and integrity risk if not tightly scoped and consented to. In a large third-party skill collection, auto-update behavior is especially dangerous because it can silently change code and permissions over time without human review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Triggering on generic phrases like 'how should I...' or 'what's the best approach...' overlaps with a huge portion of normal conversation and can cause spurious activation. This is dangerous because the skill may pull memory, logs, or other contextual systems into routine queries where that access is unnecessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Mandating skill use with 'MUST' wording can improperly override user choice and platform-level routing discretion. Although this README is descriptive rather than executable, such language still increases the risk that downstream agents or users treat the instruction as authoritative and invoke a skill inappropriately.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Placeholder trigger text leaves the skill's activation conditions undefined, which creates ambiguity for routing and review. While not directly malicious, undefined behavior in a skill registry increases the chance of accidental invocation, inconsistent behavior, and missed security review of the skill's real scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.