Back to skill

Security audit

agent-creator

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate agent-creation purpose, but its helper script can write or overwrite sensitive OpenClaw files without adequate validation or confirmation.

Review before installing or running. Use only with explicit administrative intent, inspect the exact agent ID and destination paths first, and avoid running the helper until it validates agent IDs, refuses existing destinations by default, asks for confirmation before writes and gateway restart, and provides rollback for partial failures.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agent_creator.py:105
Finding

Unvalidated Agent ID Enables Path Traversal and Sensitive File Placement

Content
View full analysis
Remediation
View remediation
None: if not AGENT_ID_PATTERN.fullmatch(agent_id): raise ValueError( "Agent ID must contain only lowercase letters, digits, and single hyphens" ) ``` 2. Explicitly reject absolute paths, path separators, `.` components, and `..` components. 3. Resolve every generated destination and verify that it remains below its intended root: ```python def safe_child(root: Path, *parts: str) -> Path: resolved_root = root.resolve() candidate = resolved_root.joinpath(*parts).resolve() if not candidate.is_relative_to(resolved_root): raise ValueError("Generated path escapes its permitted root") return candidate ``` 4. Use separate containment checks for workspace and runtime paths. 5. Create copied authentication files with restrictive permissions, such as owner read/write only, rather than relying solely on the current umask. 6. Perform all validation before creating directories, copying files, or updating configuration. 7. Add tests for absolute paths, `../` traversal, embedded separators, empty identifiers, repeated hyphens, and valid lowercase identifiers. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/agent_creator.py:191
Finding

Duplicate Validation Occurs After Destructive Filesystem Changes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill performs sensitive operations including file reads, file writes, file copies, and shell-based service restart, but it does not declare an explicit tool scope or permissions boundary. This creates a mismatch between what the skill can cause an agent to do and what a reviewer or runtime policy can easily constrain, increasing the chance of over-privileged execution or unsafe invocation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

This skill is explicitly designed to create persistent artifacts: agent directories, workspace files, peer bindings, and long-lived configuration updates. While persistence is core to the feature, it still expands attack surface because an unintended or maliciously influenced invocation could establish durable agent behavior and chat bindings that remain active beyond the session.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: agent-creator
description: "Full workflow for creating an OpenClaw Agent. Use when the user says 'create an agent', 'make a new agent', 'add a bot', or needs to set up a new AI assistant. Covers the complete setup process including (1) adding agent config and peer bindings to openclaw.json, (2) creating workspace directory with SOUL.md persona, (3) scaffolding required folders and files, (4) copying agent runtime configs from main, (5) restarting gateway to apply changes."
---

# Agent Creator - OpenClaw Agent Setup Tool

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, generic, and overlap with ordinary conversational requests like 'create an agent' or 'add a bot,' which can cause the skill to activate unintentionally. Because the skill performs configuration changes and service restarts, accidental activation can lead to unintended system modification from an ambiguous user request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description advertises system-impacting actions such as modifying openclaw.json, copying runtime configs, and restarting the gateway, but it does not prominently require a user warning or explicit consent before making those changes. In practice, this can cause disruptive or persistent environment changes without sufficient operator awareness.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/agent_creator.py (reported line 44)May include surrounding context.

python
def create_workspace(agent_id: str):
    """Create workspace directory with all required files."""
    workspace_dir = OPENCLAW_DIR / f"workspace-{agent_id}"
    workspace_dir.mkdir(parents=True, exist_ok=True)
    (workspace_dir / "memory").mkdir(exist_ok=True)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/agent_creator.py (reported line 188)May include surrounding context.

python
def restart_gateway():
    """Restart the OpenClaw gateway."""
    print("\nRestarting gateway...")
    result = subprocess.run(["openclaw", "gateway", "restart"], capture_output=True, text=True)
    if result.returncode == 0:
        print("Gateway restarted successfully")
    else:

Static analysis

No suspicious patterns detected.