Back to skill

Security audit

Remote Jobs Finder

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real remote-job search skill, but it needs Review because its server install can overwrite shared OpenClaw extension files and its ongoing monitoring/profile memory is under-scoped.

Install only if you are comfortable adding a server-side OpenClaw gateway extension. Back up any existing ~/.openclaw/extensions/openclaw.plugin.json and index.ts first, store RR_API_KEY as an admin-only secret, and require explicit user opt-in plus an easy stop/status command for monitoring. Treat returned job text and links as untrusted third-party content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T07 · Tool Hijacking and Spoofing

Warning
Location
install-server.sh:5
Finding

Installer Unconditionally Overwrites the Shared OpenClaw Extension

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi done ``` 4. If replacement is explicitly required, display a diff and require affirmative administrator confirmation. 5. Create timestamped backups before changing existing files and document a rollback procedure. 6. Validate package provenance or publish checksums/signatures for the extension files before deployment. 7. Update `README.md` and `INSTALL_SERVER.md` so they do not instruct administrators to perform unconditional overwrites. ]]>

T01 · Skill Instruction Hijacking

Note
Location
SERVER_EXTENSION_openclaw_extensions_root/index.ts:53
Finding

Unvalidated Remote Job Data Is Returned Directly to the Agent

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs the operator to set RR_API_KEY in a service environment, which involves handling sensitive credentials. The document provides the exact setup steps but does not include any warning about protecting the key, limiting access, or avoiding accidental disclosure in shared environments.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL_SERVER.md (reported line 29)May include surrounding context.

3) Set RR_API_KEY for the systemd service

bash
sudo systemctl edit openclaw-gateway.service

Add:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL_SERVER.md (reported line 40)May include surrounding context.

3) Set RR_API_KEY for the systemd service

bash
sudo systemctl edit openclaw-gateway.service

Add:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL_SERVER.md (reported line 41)May include surrounding context.

3) Set RR_API_KEY for the systemd service

bash
sudo systemctl edit openclaw-gateway.service

Add:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 92)May include surrounding context.

3) Set RR_API_KEY for the systemd service

bash
sudo systemctl edit openclaw-gateway.service

Add:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

3) Set RR_API_KEY for the systemd service

bash
sudo systemctl edit openclaw-gateway.service

Add:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 106)May include surrounding context.

3) Set RR_API_KEY for the systemd service

bash
sudo systemctl edit openclaw-gateway.service

Add:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 112)May include surrounding context.

3) Set RR_API_KEY for the systemd service

bash
sudo systemctl edit openclaw-gateway.service

Add:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes very broad natural-language examples such as job requests and follow-up phrases like 'Send me 20 more' without any visible scoping, confirmation, or namespace. In a conversational environment like WhatsApp, these generic phrases can overlap with ordinary chat and unintentionally trigger the skill or tool flow, causing unexpected queries or actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises recurring behavior via 'Check daily for new matches' but does not warn users that this may create ongoing checks, retained search state, or repeated outbound notifications. In messaging contexts, silent persistence increases the risk of surprise automation, spam-like behavior, and privacy issues around stored preferences.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

2. One-time server setup: deploy the rr_jobs_search gateway extension

bash
mkdir -p ~/.openclaw/extensions

cp SERVER_EXTENSION_openclaw_extensions_root/openclaw.plugin.json ~/.openclaw/extensions/openclaw.plugin.json
cp SERVER_EXTENSION_openclaw_extensions_root/index.ts ~/.openclaw/extensions/index.ts

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

cp SERVER_EXTENSION_openclaw_extensions_root/openclaw.plugin.json ~/.openclaw/extensions/openclaw.plugin.json cp SERVER_EXTENSION_openclaw_extensions_root/index.ts ~/.openclaw/extensions/index.ts

ls -la ~/.openclaw/extensions

text

If you’re inside the bundle folder, you can also run:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The optional monitoring commands 'Check daily' and 'Monitor hourly' are extremely underspecified and could be interpreted from normal conversation without clear target criteria, duration, or consent. In a persistent chat agent, ambiguous recurring commands can accidentally enable repeated background activity or notifications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SERVER_EXTENSION_openclaw_extensions_root/index.ts (reported line 44)May include surrounding context.

ts
includeJobDescription: params?.includeJobDescription ?? false,
      };

      const res = await fetch("https://www.remoterocketship.com/api/openclaw/jobs", {
        method: "POST",
        headers: {
          Authorization: `Bearer ${rrApiKey}`,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill explicitly relies on a server-side environment variable (RR_API_KEY) and a networked tool, but it does not declare any permissions or allowed-tools scope in the manifest. That creates an authorization gap where the runtime may grant broader capabilities than are visible to reviewers, making misuse of tools or secret-backed actions harder to govern and audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger guidance is broad enough to activate on general job-seeking language without clear exclusion criteria or confirmation boundaries. In a conversational agent, over-broad routing can cause unintended invocation of a networked, secret-backed tool, leading to unnecessary data disclosure to a third party or actions taken when the user did not clearly request external search.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
When the user wants real job listings, you MUST call the OpenClaw tool `rr_jobs_search`.

Hard rules:
- Do NOT ask the user to run any CLI.
- Do NOT claim you can’t fetch listings (you can).
- Do NOT attempt raw HTTP calls from the model.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
When the user wants real job listings, you MUST call the OpenClaw tool `rr_jobs_search`.

Hard rules:
- Do NOT ask the user to run any CLI.
- Do NOT claim you can’t fetch listings (you can).
- Do NOT attempt raw HTTP calls from the model.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

API key rules:

  • The Remote Rocketship API key is provided server-side via environment variable RR_API_KEY.
  • Never ask the user to paste secrets in WhatsApp.

Example call:

json

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
SERVER_EXTENSION_openclaw_extensions_root/index.ts:32