Back to skill

Security audit

Consulting Agent Pipeline

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed file-based consulting workflow, but it asks agents to persist project lessons and copy research outside the project without enough user-controlled boundaries.

Review before installing. Use it only if you want a Chinese-language, file-based consulting workflow, and keep retrospectives and research copies inside the project unless you explicitly approve export to global OpenClaw memory or Obsidian. Fix or constrain init-project.sh input handling before accepting untrusted project names or types.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:171
Finding

Uncontrolled Persistent Agent Memory Modification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 171-176
Vulnerability Type: Persistent memory poisoning through untrusted project retrospectives
Risk Level: High

Vulnerable Code

markdown
**2. Project-level retrospective (after Phase 5)**
- Orion completes the final summary in `DECISION_LOG.md`
- Compare the project against the existing lessons and identify new lessons
- Append new lessons to the "Collaboration Reflections" section of `MEMORY.md`

Retrospective results do not modify this Skill's `SKILL.md`; they are appended to `~/.openclaw/workspace/memory/YYYY-MM-DD.md`.

Technical Analysis

The Skill instructs the agent to persist project-derived lessons in a global, cross-session memory directory. These lessons may be derived from project documents, handoff files, research outputs, or other content that is not necessarily trusted.

No mandatory human approval, provenance validation, content sanitization, or project-specific memory isolation is required before the persistent write. Consequently, attacker-controlled project content could be reframed as a retrospective lesson and stored as durable agent guidance.

This differs from ordinary project logging because the destination is the agent's long-term workspace memory rather than a file isolated to the current project. If later sessions automatically read that memory, the injected content can continue influencing the agent after the original project has ended.

Attack Path

  1. An attacker gains control over, or contributes content to, a project input, research result, handoff document, or deliverable.
  2. The attacker embeds misleading operational guidance designed to appear to be a reusable project lesson.
  3. During the Phase 5 retrospective, the agent identifies that content as a new lesson.
  4. Following the Skill instructions, the agent appends the lesson to ~/.openclaw/workspace/memory/YYYY-MM-DD.md.
  5. Future sessions l ...[truncated 804 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store retrospectives inside the current project directory by default, such as 00_pipeline/retrospectives/, rather than in global agent memory.
  2. Require explicit, informed human approval before writing any project-derived content to persistent cross-session memory.
  3. Present the exact proposed memory entry and destination to the human reviewer before committing it.
  4. Record provenance metadata, including the source project, source files, author, approval identity, and approval timestamp.
  5. Reject memory entries containing executable commands, agent-control instructions, permission changes, credential requests, or directives that override system and user policies.
  6. Separate factual lessons from behavioral instructions. Persistent behavioral rules should require a higher approval threshold.
  7. Use project-scoped namespaces and expiration periods so project-specific lessons do not automatically affect unrelated work.
  8. Provide a review and rollback mechanism for newly created memory entries.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init-project.sh:9
Finding

Unescaped User Input Interpolated into a Sed Program

Content
View full analysis

Vulnerability Details

File Location: scripts/init-project.sh, lines 9-11 and 42-44
Vulnerability Type: Sed expression injection
Risk Level: Medium

Vulnerable Code

bash
PROJECT_NAME="${1:-}"
PROJECT_ROOT="${2:-}"
PROJECT_TYPE="${3:-consulting}"
bash
# PROJECT_STATE.yaml
sed "s/PROJECT_NAME/$PROJECT_NAME/g; s/PROJECT_ID/$PROJECT_ID/g; s/PROJECT_TYPE/$PROJECT_TYPE/g" \
  "$TEMPLATE_DIR/PROJECT_STATE.yaml.template" > "$PROJECT_ROOT/00_pipeline/PROJECT_STATE.yaml"

Technical Analysis

PROJECT_NAME and PROJECT_TYPE are supplied by the caller and inserted directly into a double-quoted sed program. The script does not escape sed replacement metacharacters such as /, &, backslashes, semicolons, or newlines.

A crafted value can terminate the intended replacement expression and inject additional sed commands. At a minimum, this permits corruption or unauthorized transformation of the generated YAML. On sed implementations that support command-execution extensions, such as GNU sed's e command, an injected sed command may execute an operating-system command.

Shell quoting does not eliminate this issue. The shell safely expands the variable as one argument, but sed subsequently interprets that argument as program syntax rather than inert replacement data.

The current project snapshot does not include templates/PROJECT_STATE.yaml.template. As shipped, initialization therefore fails when it reaches this operation. Command execution through this defect is conditional on the expected template being restored or supplied, but the unsafe construction remains present in the initialization code.

Attack Path

  1. An attacker persuades a user or automation process to initialize a project with an attacker-controlled project name or project type.
  2. The supplied value contains a sed delimiter followed by additional sed syntax.
  3. Shell variable expansion places the malicious valu ...[truncated 1306 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace sed-based YAML generation with a YAML-aware implementation that passes values as data rather than program text.
  2. Prefer a small Python or equivalent generator using a safe YAML library and explicit serialization.
  3. If sed must remain, validate project metadata against a strict allowlist and reject delimiters, control characters, newlines, and unexpected punctuation.
  4. Escape backslashes first, followed by & and the selected sed delimiter, before using values in a replacement expression.
  5. Pass untrusted values through environment variables or files and use a mechanism that does not interpret them as sed commands.
  6. Validate PROJECT_TYPE against the documented fixed set: consulting, research, or product.
  7. Validate generated YAML with a real YAML parser before accepting initialization as successful.
  8. Add adversarial tests covering /, &, backslashes, semicolons, embedded newlines, and sed command-injection payloads.
  9. Restore or correctly reference templates/PROJECT_STATE.yaml.template so the initialization path can be tested reliably.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是高层的多Agent协作工作流与治理协议,重点在跨平台协作、审核迭代、项目状态追踪、敏感信息控制和Human决策节点。实际代码并未实现这些工作流编排、Agent协调、审核流程、状态机或敏感信息检测/防泄漏能力,而只是对本地目录进行一次快照备份并写入元数据。虽然“状态追踪”在宽泛意义上可能与快照有关,但该脚本的主要功能仍是文件复制归档,和声明的核心用途存在实质性偏差,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个高层的多Agent咨询项目协作与治理框架,重点在流程编排、跨Agent平台协作、审核迭代、状态追踪、敏感信息防泄漏和人工决策控制。给出的代码却仅是一个交付物验证脚本,功能集中在检查目录内是否存在特定类型文件及若干配套文档,并对PPTX做简单结构检查。这与声明的核心目标和主要能力明显不一致。虽然‘交付’阶段的产物校验可以被视为整体流程中的一个辅助环节,但该代码只覆盖了很窄的文件完整性检查,既未体现多Agent协作协议,也未体现描述中强调的安全与流程治理能力,因此构成明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个面向咨询项目的多Agent协作协议/工作流系统,强调跨平台协调、审核迭代、状态追踪、敏感信息防泄漏和Human决策控制。而代码仅是一个本地 shell 校验器,针对 handoff Markdown 文档做静态结构检查。它没有任何Agent编排、跨平台交互、状态管理、审核流转、迭代控制或实际敏感词检测逻辑。虽然“交接文档校验”可被视为该类流程中的辅助组成部分,但其主功能与声明的核心能力明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
| `scripts/forbidden-terms-scan.sh` | 禁用词扫描(依赖yq可选) | 每轮交付前(all-rounds) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
| `scripts/forbidden-terms-scan.sh` | 禁用词扫描(依赖yq可选) | 每轮交付前(all-rounds) |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and document title present the skill entirely in Chinese/Chinese-first form, with no indication that users may choose another language. This creates a natural-language locale policy concern because the skill appears to impose a specific language by default rather than documenting a justified regional restriction or offering opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Writing retrospective results to a fixed home-directory path outside the shared project workspace can cause unintended data sprawl, inconsistent access controls, and leakage of project-sensitive metadata into a broader personal memory store. In a multi-agent workflow focused on preventing internal code-name leakage, exporting reflections to a user-global location weakens containment and auditability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The risk-expression notes prescribe specific Chinese replacement wording such as 标注'正式申报前待核' and 应改为'技术路径清晰,待XX确认', which imposes a single language for compliant output. Because the file does not provide a user opt-in or document a justified region-specific language constraint, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L003 states that all cross-Agent document transmission must use this specification, and the entire specification is written as a Chinese-language standard with no opt-in or alternative locale path. This effectively imposes a specific language/locale requirement on all users or agents, which matches the policy-violation category for forced language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file begins with a bilingual title but the operational instructions throughout the document are written in Chinese only, which imposes a specific language on users. The document does not offer an opt-in language choice or explain that this skill is limited to a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script presents its description, usage instructions, warnings, and status output entirely in Chinese, including user-facing help and runtime messages. The policy for natural-language violations applies to all file types, and there is no opt-in, fallback language, or documented reason that this skill must be Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script's informational and warning messages shown during execution are only emitted in Chinese, which forces a specific language on users at runtime. Because no user choice or explicit region-specific justification is provided, this is a natural-language policy issue rather than a code-security issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language comments, usage text, and examples that force a specific language/locale for users. Under the policy, language constraints should either offer user choice or be explicitly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script prints usage/help text exclusively in Chinese, and later operational guidance is also Chinese-only. This is a natural-language policy issue because it imposes a locale on all users without offering a language choice or documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The main execution output and follow-up steps are user-facing natural language, but they are fixed to one language. Because the file does not indicate that the script is region-specific or allow language selection, this violates the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's description, usage/help output, and error messages are written in Chinese, which imposes a specific language on users. There is no indication that the tool is intentionally region-specific or that users can opt into another language, which conflicts with the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document is primarily written in Chinese, including the title and all operational guidance, with no indication that users may choose another language or that the skill is intended only for a Chinese-language context. This can violate the stated language/locale policy requirement because it imposes a specific language by default rather than through user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s comments, forbidden terms, and risk-expression guidance are entirely written for Chinese-language content, and several rules are language-specific expressions such as '立即可行|马上|立刻' and '唯一|绝对|必然'. There is no indication that this locale restriction is optional, user-selected, or justified as a region-specific compliance requirement, which can constitute a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown template is entirely structured in Chinese and prescribes section headings and instructions in that language, which effectively enforces a specific language/locale. The file does not offer an opt-in choice or explain that the template is intended only for a Chinese-language or region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown template uses Chinese throughout field comments, section headings, and instructions, which imposes a specific language on users. Under the policy, forcing a language without user opt-in or documented justification is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire template structure and instructional text are written exclusively in Chinese, including required section headings and reviewer instructions such as the final evaluation and remediation sections. This imposes a specific language/locale on downstream use without any opt-in, alternative language option, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template contains user-facing instructions and comments almost entirely in Chinese, which effectively imposes a specific language/locale on users. The file does not indicate that Chinese is optional, configurable, or limited to a documented region-specific context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The template explicitly instructs agents to write a copy of research output into an external Obsidian project directory in addition to the primary project path. In a multi-agent workflow handling research and potentially sensitive internal material, this expands the data boundary and can cause unintended duplication or leakage of confidential content into a separate knowledge base outside the main project controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template consistently instructs users in Chinese, including operational checklist items and section guidance, but does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking context. That can violate language/locale policy when users have not opted into this locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly instructs an agent to directly write output files and copy them into another project location, but provides no user-visible confirmation, approval gate, or safety constraints around filesystem modification. In a multi-agent pipeline handling client research and internal reference material, this increases the risk of unauthorized file changes, accidental overwrites, propagation of sensitive content into synced knowledge bases, and unintended writes outside the user's immediate awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.