Back to skill

Security audit

openclaw-skill-manager

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate OpenClaw skill manager, but it can install skills from arbitrary URLs into active skill folders without integrity checks.

Install only if you trust the operator and will use it with trusted skill sources. Avoid arbitrary URL installs unless you independently verify the archive and publisher, and review the exact target directory and side effects before confirming installs, updates, moves, or gateway restarts.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:177
Finding

Arbitrary Remote Skill Retrieval and Activation Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 177–185
Vulnerability Type: Unverified remote payload retrieval and archive extraction
Risk Level: High

Vulnerable Code

bash
# Download/copy to the target path
if [[ "<source>" =~ ^https?:// ]]; then
  curl -L "<source>" | tar -xz -C "<target-skills-dir>/"
else
  cp -r "<source>" "<target-skills-dir>/<skill-name>"
fi

# Mark as manually installed
touch "<target-skills-dir>/<skill-name>/.manual-install"

Technical Analysis

The documented installation workflow accepts an arbitrary HTTP or HTTPS URL, follows redirects with curl -L, and streams the response directly into tar. The resulting files are extracted into a configured Skill directory without:

  • Restricting downloads to trusted domains or registries.
  • Requiring HTTPS after redirects.
  • Pinning an expected version or cryptographic digest.
  • Verifying a publisher signature.
  • Staging and reviewing the archive before installation.
  • Validating archive entries for absolute paths, symbolic-link abuse, or ../ path traversal.
  • Disabling the newly installed Skill until explicit approval.

Because the destination is a Skill-loading directory, attacker-controlled Skill instructions or executable content can become available to OpenClaw after installation. The broader workflow also enables directory watching and instructs the operator to restart the gateway after adding a Skill space, increasing the likelihood that newly imported content will be loaded.

Directly piping network input into an archive extractor also prevents meaningful verification before files are written. A malicious archive may attempt to place files outside the intended Skill directory if archive-path and link validation are not enforced.

Attack Path

  1. An attacker supplies or recommends an attacker-controlled URL as the manual Skill installation so ...[truncated 1343 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove support for arbitrary URL installation where possible and require installation through a trusted, authenticated registry.
  2. If URL installation is necessary, enforce an allowlist of trusted HTTPS origins and reject redirects to origins outside that allowlist.
  3. Download the archive to a newly created, permission-restricted temporary directory instead of piping it directly into tar.
  4. Require a pinned SHA-256 or stronger digest and a verified publisher signature before extraction.
  5. Enumerate and validate every archive entry before extraction. Reject:
    • Absolute paths.
    • Paths containing .. components.
    • Device nodes and other special files.
    • Symbolic or hard links that resolve outside the staging directory.
  6. Extract into an isolated staging directory using restrictive ownership and permissions.
  7. Review the manifest, SKILL.md, scripts, binaries, links, and requested capabilities before activation.
  8. Move reviewed content into the final Skill directory atomically and keep it disabled until explicit approval.
  9. Run Skills under least privilege with filesystem, command, credential, and network isolation.
  10. Record the source URL, final redirected URL, verified digest, signature identity, and installed files in an audit log.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:162
Finding

Unpinned Third-Party Skill Installation Through ClawHub

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 162–174
Vulnerability Type: Unpinned and unverified third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
# Method A - clawhub:
clawhub install <skill-name> --dir <parent-dir-of-skills>

Technical Analysis

The workflow installs a third-party Skill solely by a user-provided package name. It does not specify an immutable version, content digest, trusted publisher identity, signature-verification requirement, or pre-installation review.

Name-only resolution allows the content associated with a package to change between review and installation. It also creates exposure to registry compromise, malicious package updates, dependency confusion, namespace takeover, and typosquatting. A deceptively similar package name could therefore resolve to attacker-controlled content and be installed into an active Skill location.

Although user confirmation is requested elsewhere in the workflow, confirmation of a package name and target directory does not establish the integrity or authenticity of the resolved package.

Attack Path

  1. An attacker publishes a malicious Skill under a typo-similar, confused, transferred, or otherwise attacker-controlled ClawHub package name.
  2. The attacker persuades a user to request that name, or the user enters it accidentally.
  3. The workflow runs clawhub install without an immutable version or digest.
  4. ClawHub resolves and installs the current package contents into the selected Skill directory.
  5. The package becomes discoverable by OpenClaw.
  6. When loaded or invoked, malicious instructions or code execute within the capabilities granted to the Agent or OpenClaw process.

Impact Assessment

Exploitation can compromise the integrity of the local Skill environment and introduce attacker-controlled instructions or executable components. The installed package may influence ...[truncated 409 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require an exact immutable package version and cryptographic content digest for every installation.
  2. Verify registry metadata and publisher signatures against a trusted key or certificate policy.
  3. Display the canonical package identity, publisher, resolved version, digest, and requested capabilities before confirmation.
  4. Detect typosquatting and namespace confusion by warning about similar names and requiring explicit approval for unknown publishers.
  5. Download packages into quarantine and inspect all Skill instructions, scripts, binaries, links, and dependencies before activation.
  6. Maintain an organization-approved package allowlist and reject packages or versions that have not been reviewed.
  7. Generate and retain a lockfile or installation manifest containing the exact resolved package and digest.
  8. Re-verify package integrity at load time and before updates.
  9. Prevent automatic updates to unreviewed versions; treat each changed digest as a new artifact requiring approval.
  10. Execute third-party Skills with least-privilege filesystem, process, network, API, and credential access.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad everyday management language such as 管理技能, 安装skill, 查询skill, 更新skill, and /skill, which increases the chance of accidental invocation during unrelated conversation. Because this skill can modify configuration, restart services, and install content from remote or local sources, unintended activation materially raises the risk of unauthorized or surprising state changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented manual install path allows a user-supplied URL to be fetched and piped directly into tar for extraction into a live skills directory, with no origin allowlist, integrity verification, archive inspection, or path traversal protections. In the context of a skill manager, this effectively enables arbitrary untrusted code/content installation into locations that OpenClaw will later load, making remote compromise of the local agent environment plausible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L334-L337 明确规定“中文用途提取规则”并要求“转换为简洁中文描述”,这构成了固定语言/locale 约束。文档中没有说明用户可选择其他语言,也没有给出该中文限制的合规或区域性理由。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The expected output explicitly requires a concise Chinese description, which imposes a language choice in the skill behavior. This is a natural-language policy concern because the file provides no indication that users can choose their preferred language or that the skill is limited to a Chinese-only context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The stated purpose is skill management via OpenClaw spaces and CLI-based viewing. Direct filesystem scanning of every configured extraDir is an additional capability that bypasses the declared CLI-centric workflow and can enumerate directory contents from user-configured paths unrelated to normal CLI output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.