Back to skill

Security audit

wanjie-openclaw-video

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent video-generation integration, but it uses broad local credentials, background execution, runtime installation, and automatic URL opening in ways users should review before installing.

Install only if you are comfortable with this skill reading your OpenClaw provider API key, sending prompts and that credential to the Wanjie endpoint, writing prompt-bearing logs locally, installing Python packages at runtime if missing, running background workers or scheduled monitoring, and opening returned links automatically. Prefer a version that uses a dedicated skill-scoped credential, pins dependencies, redacts logs, validates returned URLs, and documents how to disable background monitoring.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
model/scripts/veo_worker.py:68
Finding

Unscoped Provider Credential Access and Transmission

Content
View full analysis
Remediation
View remediation

other

Warning
Location
model/scripts/veo_worker.py:206
Finding

Automatic Launch of an Unvalidated URL from Remote Model Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
model/scripts/video_interface.py:7
Finding

Automatic Installation of an Unpinned Runtime Dependency

Content
View full analysis
=2.25.1 ``` ### Technical Analysis When `requests` is unavailable, the skill automatically invokes pip in the active Python environment. The installation command does not specify an exact version, hashes, an approved package index, or an isolated environment. Pip honors interpreter and user configuration, including configured indexes and mirrors. A malicious or compromised package index, altered pip configuration, or future compromised dependency release could therefore supply unreviewed code. Package installation may execute package build logic, and the installed package will later execute when imported. The lower-bound-only requirement also makes builds non-reproducible because any future version satisfying the constraint may be selected. ### Attack Path 1. The active Python environment does not contain `requests`, or an attacker causes its import to fail. 2. The skill invokes `python -m pip install requests`. 3. Pip resolves the package and transitive dependencies using the environment's configured indexes. 4. A compromised index, malicious mirror, or unsafe future release supplies attacker-controlled package code. 5. Installation or subsequent import executes that code with the privileges of the OpenClaw process. ### Impact Assessment Malicious dependency code would run with the same operating-system permissions as the user running OpenClaw. It could access files a ...[truncated 363 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
model/scripts/veo_worker.py:75
Finding

Persistent Plaintext Logging of User Prompts and API-Key Fragments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (22)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly tells users to ensure network connectivity so the skill can automatically download missing Python dependencies at runtime. This creates an undocumented supply-chain and environment-modification risk: the skill may change the host system and fetch code from external sources without clear trust boundaries, version pinning, or operator approval. In the context of an agent skill with background automation and self-healing behavior, that is more dangerous because network access and automatic restarts can repeatedly trigger external downloads without close user oversight.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly describes persistent background monitoring, automatic task handling, scheduled execution, and writing results to local files, but it does not clearly warn users that it will make ongoing system changes and continue operating after the initial interaction. This is dangerous because users may unknowingly install a skill that creates persistence via Windows Task Scheduler and performs unattended actions or writes data to disk outside the immediate request context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code launches a detached Python subprocess to generate a video, but there is no confirmation prompt, comment explaining the safety impact, or user-visible disclosure before execution. Although a reply is returned afterward, it does not warn the user that an external process is being spawned in the background.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

The code automatically launches a URL returned from a remote API using the platform URL opener. Although it avoids shell injection by passing an argument list, it still causes untrusted remote content to be executed in the user's browser or associated handler without confirmation, enabling phishing, drive-by navigation, or abuse of custom URI schemes if a malicious or compromised service returns a crafted link.

Content

Scanner excerpt · model/scripts/veo_worker.py (reported line 44)May include surrounding context.

python
if platform.system() == 'Windows':
            os.startfile(url)
        elif platform.system() == 'Darwin':  # macOS
            subprocess.Popen(['open', url])
        else:  # Linux
            subprocess.Popen(['xdg-open', url])
    except Exception as e:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

On Linux, the script passes an untrusted URL directly to xdg-open, which will invoke the default handler for the supplied scheme. This is not command injection, but it is still unsafe automatic handling of attacker-controlled content and may trigger browser navigation, local app launch, or custom protocol handlers without user approval.

Content

Scanner excerpt · model/scripts/veo_worker.py (reported line 46)May include surrounding context.

python
elif platform.system() == 'Darwin':  # macOS
            subprocess.Popen(['open', url])
        else:  # Linux
            subprocess.Popen(['xdg-open', url])
    except Exception as e:
        log_exc("[!] 打开URL失败", e)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · model/scripts/veo_worker.py (reported line 60)May include surrounding context.

python
# 没有 psutil:Windows 用 tasklist 粗略判断;其他平台保守不删锁
        try:
            if platform.system() == 'Windows':
                res = subprocess.run(['tasklist', '/FI', f'PID eq {pid}'],
                                     capture_output=True, text=True)
                return str(pid) in res.stdout
        except Exception:

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function signature and logged input imply that the caller-provided model and seconds values influence video generation. However, the request payload hardcodes "veo3.1" and never includes or uses seconds, so the documented/advertised inputs do not match actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads an API key from a local configuration file and logs a fingerprint of it without any consent or warning. Even partial disclosure can aid secret correlation across logs and environments, and the more significant issue is that a hidden background worker accesses credentials from another tool's config and transmits them to a third-party API with little transparency.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-supplied prompt content is sent to an external API endpoint, and the script also logs the full prompt locally. In an agent-skill context, prompts may contain sensitive user data, secrets, or proprietary content, so silent exfiltration to a third party materially increases privacy and data-leak risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically opens a URL extracted from streamed remote output without validating its scheme, host, or safety. In this skill context, that is more dangerous because the URL is entirely controlled by an external service response and the launch is automatic, enabling phishing pages, malicious downloads, or invocation of custom URI handlers on the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Comments, status messages, and the function's returned user-facing text are written in Chinese, which can impose a fixed language experience on users without opt-in. Under the policy, a skill should not force a specific language or locale unless it is clearly justified or the user is given a choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill both installs packages at runtime and launches a separate worker process, giving it the ability to change its execution environment and then execute additional code outside the main flow. That combination materially expands attack surface and makes the skill more dangerous than a normal content-generation interface, especially since no stated purpose justifies these capabilities in the visible code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill silently installs a missing dependency without requiring confirmation or providing a meaningful warning about modifying the system environment. In agent or shared-host settings, this can violate operator expectations, introduce unreviewed code into the environment, and create reliability and supply-chain concerns.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The code automatically invokes pip at runtime to install a package into the current Python environment without explicit user approval or any integrity controls such as pinning, hashes, or an isolated virtual environment. Even though the package name is fixed, modifying the runtime environment from within a skill increases supply-chain and environment-tampering risk and can have unexpected side effects in shared deployments.

Content

Scanner excerpt · model/scripts/video_interface.py (reported line 13)May include surrounding context.

python
importlib.import_module("requests")
    except ImportError:
        print("[*] 正在安装缺失依赖: requests...")
        subprocess.check_call([sys.executable, "-m", "pip", "install", "requests"])

def trigger_veo_generation(prompt, model="veo3.1-fast", seconds=8):
    # 在触发前确保环境就绪

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code launches a background subprocess and only returns a generic success message, without clearly disclosing that execution is detached or what command is being run. This reduces informed consent and makes it harder for users or platform operators to monitor, cancel, or investigate the process if something goes wrong.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
81% confidence
Finding

This launches a detached background worker process while suppressing all stdout and stderr, which reduces visibility into what the child process is doing and makes misuse or failure harder to detect. While the command is passed as an argument list rather than a shell string, the hidden detached execution model is still risky in an agent skill because it can continue operating outside normal interaction controls and auditing.

Content

Scanner excerpt · model/scripts/video_interface.py (reported line 32)May include surrounding context.

python
if platform.system() == 'Windows':
        # 将输出重定向到 NUL 以防止 OpenClaw 报错
        with open(os.devnull, 'w') as devnull:
            subprocess.Popen(cmd, stdout=devnull, stderr=devnull, creationflags=subprocess.CREATE_NEW_PROCESS_GROUP)
    else:
        # Linux/macOS 上启动新进程
        with open(os.devnull, 'w') as devnull:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
81% confidence
Finding

This Unix/macOS path also spawns a detached worker session with output redirected to /dev/null, creating the same monitoring and control problem as on Windows. In a skill context, silent background execution is more dangerous because it can persist beyond the initiating request and conceal unwanted behavior in the worker script.

Content

Scanner excerpt · model/scripts/video_interface.py (reported line 36)May include surrounding context.

python
else:
        # Linux/macOS 上启动新进程
        with open(os.devnull, 'w') as devnull:
            subprocess.Popen(cmd, stdout=devnull, stderr=devnull, start_new_session=True)
        
    return f"[*] 任务已提交: {prompt},请在聊天窗口耐心等待结果通知。"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language instructions and trigger example are entirely Chinese, and the usage guidance at L28 only presents a Chinese invocation format. There is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The usage instructions only present the trigger phrase in Chinese (生成视频:[您的提示词]) and do not indicate that other languages are supported or that the language requirement is optional. This can constitute a language/locale policy issue because it implicitly forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The comment indicates a benign readiness check before generation, but ensure_dependencies can call pip to install requests, which changes the runtime environment. That goes beyond merely checking readiness and creates a mismatch between the documented intent and actual behavior.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified as requests>=2.25.1, which permits installation of many future and historical versions rather than a single reviewed release. This weakens supply-chain control and reproducibility, and can allow deployment of a vulnerable or incompatible version without the maintainer realizing it.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.25.1

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin an exact version, it is not possible to verify whether the installed version is affected. In practice, this means deployments may resolve to a vulnerable release, exposing the skill to known issues such as credential leakage or other request-handling flaws depending on the resolved version.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
hooks.js:11