Back to skill

Security audit

OpenClaw Tailnet TTS Endpoint

Security checks for vulnerabilities and agentic risk

Overview

This skill gives straightforward instructions for wiring OpenClaw to a local TTS backend, with only purpose-aligned local configuration and testing steps.

Install only if you want OpenClaw to use a local TTS backend. Review the OpenClaw config changes before applying them, run Docker commands with the least privilege available, avoid exposing the TTS port beyond trusted LAN or Tailscale users, and use a safer temporary output path for generated test clips.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:55
Finding

Predictable Temporary File Path Allows Local File Clobbering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 55–67
Vulnerability Type: Predictable temporary file and unsafe file creation
Risk Level: Low

Vulnerable code:

bash
curl -sS -X POST http://127.0.0.1:8880/v1/audio/speech \
  -H 'Content-Type: application/json' \
  -d '{
    "model":"tts-1-hd",
    "voice":"me",
    "input":"Quick cloned voice check.",
    "speed":1.25,
    "response_format":"mp3"
  }' \
  --output /tmp/clone-test.mp3

file /tmp/clone-test.mp3

Technical Analysis

The documented command writes its response to the fixed path /tmp/clone-test.mp3. Because /tmp is normally shared and writable by local users, an attacker may create that path before the command runs, including as a symbolic link to another file.

curl --output opens the supplied path for writing and may follow a pre-existing symbolic link. The linked target can therefore be truncated or overwritten with the TTS response under the permissions of the user executing the Skill. The predictable name also causes repeated executions to overwrite an existing test clip.

Attack Path

  1. A local attacker predicts that the Skill will use /tmp/clone-test.mp3.
  2. Before execution, the attacker creates a symbolic link at that path pointing to a file writable by the victim:
    bash
    ln -s /path/to/victim-writable-file /tmp/clone-test.mp3
    
  3. The victim or AI Agent runs the documented curl command.
  4. curl follows the symbolic link and opens the target for writing.
  5. The target is truncated or replaced with the generated audio response.

Exploitation requires local access to the same host and a target writable by the user running the command.

Impact Assessment

A successful attack can overwrite or corrupt files accessible to the executing user. It does not inherently grant additional privileges: the attacker cannot overwrite files that the executing user lacks permission ...[truncated 264 chars]

Remediation
View remediation

Remediation Suggestions

Create the output in a private, unpredictable temporary directory rather than using a fixed shared path:

bash
tmpdir="$(mktemp -d)" || exit 1
trap 'rm -rf -- "$tmpdir"' EXIT

output="$tmpdir/clone-test.mp3"

curl --fail-with-body -sS \
  -X POST http://127.0.0.1:8880/v1/audio/speech \
  -H 'Content-Type: application/json' \
  -d '{
    "model":"tts-1-hd",
    "voice":"me",
    "input":"Quick cloned voice check.",
    "speed":1.25,
    "response_format":"mp3"
  }' \
  --output "$output" &&
file -- "$output"

Ensure mktemp succeeds before proceeding, quote all path variables, and remove the temporary directory after use. Avoid running this workflow with elevated privileges. If a persistent output is required, require the user to select a destination and reject pre-existing symbolic links or unintended files.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Check voice map inside container:

bash
sudo docker exec openedai-speech sh -lc 'sed -n "1,220p" /app/config/voice_to_speaker.yaml'

If voice: me fails with KeyError, check whether:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Use direct POST to validate backend behavior independent of chat surface rendering.

bash
curl -sS -X POST http://127.0.0.1:8880/v1/audio/speech \
  -H 'Content-Type: application/json' \
  -d '{
    "model":"tts-1-hd",

Static analysis

No suspicious patterns detected.