Back to skill

Security audit

LookupMark Log Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed, local, read-only log analyzer with bounded source allowlists, though users should be aware it can reveal sanitized operational log content and has some availability-quality issues.

Install only if you want the agent to inspect the listed local OpenClaw and RAG logs. Treat redaction as helpful but not perfect, avoid using it in shared contexts with sensitive logs, and prefer narrowing triggers or confirming before broad requests like "any errors."

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyzer.py:160
Finding

Untrusted Regular Expression Enables Application Crash and CPU Denial of Service

Content
View full analysis
list[str]: results = [] for source in ALLOWED_SOURCES: logs = get_logs(source, lines) for line in logs: if re.search(pattern, line, re.IGNORECASE): results.append(sanitize(f"[{source}] {line}")) ``` The pattern originates directly from the command-line argument: ```python parser.add_argument("--search", help="Search pattern (regex)") ... results = search_logs(args.search, args.last) ``` ### Technical Analysis The value supplied through `--search` is passed directly to Python's backtracking regular-expression engine. There is no pattern validation, complexity restriction, length limit, compilation error handling, or execution timeout. An invalid expression, such as an unmatched parenthesis, raises an uncaught `re.error` and terminates the analyzer. A valid expression containing catastrophic backtracking can consume excessive CPU when evaluated against a sufficiently long log entry. Because log content can be influenced by applications and their external inputs, an attacker may be able to place a string in a whitelisted log that maximizes the cost of a malicious or inadvertently unsafe search expression. The pattern is evaluated separately against every retrieved line from every configured source, amplifying its resource consumption. ### Attack Path 1. An attacker or untrusted caller supplies a crafted pattern through `--search`, or induces an Agent to invoke the analyzer with that pattern. 2. For an immediate crash, the caller provides syntactically invalid regex input such as `(`. 3. For CPU exhaustion, the caller provides a catastrophic-backtracking expression and ensures or identifies a long, non-matching line in one of the whitelisted logs ...[truncated 531 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyzer.py:102
Finding

Unbounded Log File Loading Can Exhaust Process Memory

Content
View full analysis
list[str]: if not os.path.exists(path): return [f"(log file not found: {path})"] try: with open(path) as f: all_lines = f.readlines() return [l.rstrip() for l in all_lines[-lines:]] except Exception as e: return [f"(read failed: {e})"] ``` ### Technical Analysis Although the function returns only the requested trailing lines, `f.readlines()` first reads the entire log into an in-memory list. Consequently, memory consumption is determined by the complete file size rather than the requested `--last` value. The `--last` argument is also accepted as an unrestricted integer, with no positive lower bound or maximum. A large requested value may therefore retain and process a correspondingly large number of entries. Individual line lengths and total bytes are not bounded either. The source paths are fixed, which prevents arbitrary-file access, but it does not protect availability when a whitelisted application log becomes very large or contains unusually large lines. ### Attack Path 1. A whitelisted RAG log grows to a very large size through ordinary accumulation or attacker-influenced application activity. 2. A user or Agent invokes the analyzer for that source, or invokes its default all-source summary. 3. `read_file_log()` calls `readlines()`, causing the complete file to be loaded into memory. 4. Memory usage grows with the entire log size even when only a small number of trailing entries was requested. 5. The operating system may terminate the process, or the analyzer may degrade the availability of the surrounding Agent or host through memory pressure. ### Impact Assessment The issue can cause local denial of service, process termination ...[truncated 246 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes shell commands but does not declare any explicit tool scope or permissions boundary in the skill manifest. That creates ambiguity about what execution capabilities are intended and prevents policy enforcement from constraining shell access, which can increase the blast radius if the skill is triggered in an unexpected context or later modified to access broader resources.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad natural-language patterns such as 'show errors', 'any errors', and 'search logs', which are likely to match common user requests outside the narrow intended use case. Overbroad activation can cause the skill to run unexpectedly, leading to unintended log access or disclosure of operational details even if the underlying analyzer is read-only and attempts redaction.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/analyzer.py (reported line 86)May include surrounding context.

python
def read_journalctl(unit: str, lines: int = 100) -> list[str]:
    try:
        result = subprocess.run(
            ["journalctl", "--user", "-u", unit, "-n", str(lines), "--no-pager"],
            capture_output=True, text=True, timeout=10
        )

Static analysis

No suspicious patterns detected.