Back to skill

Security audit

ClawGuard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent install guide for a security guardrail, but it gives a third-party plugin broad visibility into tool calls and includes risky credential-display troubleshooting.

Review the actual @capsulesecurity/clawguard package version before installing, pin a known version where possible, avoid printing gateway tokens, and disable or tightly control tool-call logging, metrics, and LLM providers in environments where prompts or tool arguments may contain secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:17
Finding

Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:76
Finding

Troubleshooting Commands Expose the Gateway Authentication Token

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

  1. Check the gateway token in your environment matches the config:
    bash
    # Check env var
    printenv OPENCLAW_GATEWAY_TOKEN
    
    # Check config token
    cat ~/.openclaw/openclaw.json | grep -A2 '"token"'
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly states that tool call JSON is logged and that tool context is sent to an LLM for security evaluation, but it does not clearly warn that prompts, tool arguments, session context, secrets, or other sensitive operational data may be transmitted to logs and potentially to external model providers. In a security-plugin installation guide, this omission is particularly risky because users may assume the guardrail improves security without realizing it also increases data exposure surfaces.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.