Back to skill

Security audit

G.workspace

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent G.workspace Discord file-space plugin, but it needs review because it exposes workspace/task mutations and permanent trash deletion without clear authorization or confirmation boundaries.

Install only in a controlled OpenClaw/Discord environment where the G.workspace backend enforces guild, user, and role authorization. Pin the backend to a reviewed commit, restrict who can invoke the slash commands and AI tools, and avoid enabling permanent trash emptying until it has an explicit confirmation and admin-only guard.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
plugin/index.ts:448
Finding

Agent tools accept caller-controlled guild and workspace identifiers without local authorization

Content
View full analysis
{ const data = await gwFetch("GET", `/api/guild/${guild_id}`); return JSON.stringify({ workspace_id: data.workspace_id, name: data.name, files: data.files, stats: data.stats }); }, }); api.registerTool({ name: "gworkspace_create", description: "Create a G.workspace for a guild", parameters: { type: "object", properties: { guild_id: { type: "string", description: "Discord guild ID" }, name: { type: "string", description: "Workspace name" }, }, required: ["guild_id"], }, handler: async ({ guild_id, name }: { guild_id: string; name?: string }) => { const data = await gwFetch("POST", `/api/guild/${guild_id}/create`, { name }); return JSON.stringify(data); }, }); api.registerTool({ name: "gworkspace_tasks", description: "Get pending annotation tasks for a workspace", parameters: { type: "object", properties: { guild_id: { type: "string", description: "Discord guild ID" } }, required: ["guild_id"], }, handler: async ({ guild_id }: { guild_id: string }) => { const data = await gwFetch("GET", `/api/guild/${guild_id}`); const tasks = await gwFetch("GET", `/w/${data.workspace_id}/api/tasks`); return JSON.stringify({ workspace_id: data.workspace_id, ...tasks }); }, }); api.registerTool({ name: "gworkspace_claim_task", description: "Claim an annotation task", parameters: { type: "object", properties: { workspace_id: { type: "string" }, tas ...[truncated 3517 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
plugin/index.ts:391
Finding

Permanent trash deletion lacks role verification and confirmation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Installation instructions execute an unpinned remote backend and dependency graph

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose emphasizes slash-command file-space management, but the skill also exposes agent-callable AI tools, task operations, and interactive handlers that expand its effective authority beyond the stated description. This mismatch is dangerous because reviewers may approve the skill under a narrower mental model while it can perform additional actions, including workflow/task manipulation, through paths not clearly disclosed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The annotation-task claim and completion tools add write capabilities unrelated to the stated file-sharing purpose, allowing an agent to alter task workflow state in the backend. Because these actions are available as tools without visible user interaction in this file, an AI agent could improperly claim or complete tasks, causing integrity loss and unauthorized workflow manipulation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares no explicit tool scope or permission boundary even though its documented behavior requires network access to a local REST API. Missing scope declarations make the trust boundary unclear to operators and agents, increasing the chance the skill is installed with broader capabilities than intended or used without informed consent about outbound/local HTTP access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description advertises /ws_delete <filename> as deleting files by moving them to trash, but the markdown does not include a clear caution about user data impact, retention, or whether trash recovery is guaranteed. For a skill that manages shared files, deletion-related behavior should be disclosed explicitly so users understand the risk to shared data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill advertises upload and link-sharing capabilities without any privacy, access-control, or data-sharing warning. In a shared Discord workspace context, users may expose sensitive files or generate access links without understanding who can retrieve the data, how long links persist, or whether uploads are restricted, making accidental data disclosure more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-facing error messages, command descriptions, and success responses throughout the plugin are hard-coded in Chinese, with no option for users to choose another language. This imposes a specific language/locale on all users and fits the policy's language-choice violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trash-empty operation permanently deletes all items after only a simple action string, with no confirmation step, dry-run preview, or secondary safeguard. In an agent-integrated environment, accidental or manipulated invocation can cause irreversible data loss across the workspace.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The plugin advertises itself as a Discord slash-command shared file-space integration, but it also registers undisclosed agent-only tools that expose workspace contents and task-management actions. This hidden expansion of capability violates least surprise and least privilege, and can enable AI agents to access or mutate data through interfaces that users and reviewers may not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The registered tools query workspace, file, and task data over HTTP and return potentially sensitive workspace contents, but these tool handlers contain no user-facing notice, logging, or inline disclosure about transmitting guild/workspace identifiers and retrieving shared data. In code-file scope, network calls that transmit user or system data should have some visible disclosure unless clearly covered elsewhere, which is not present in this file.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest description explains what the plugin does but does not specify any activation boundaries, command names, or exclusion conditions. For a manifest file, that makes the invocation scope overly broad and could lead to unclear or unintended activation expectations.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: openclaw has 16 known advisory(ies) (CVE-2026-53846 (OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency); CVE-2026-32064 (OpenClaw's andbox browser noVNC observer lacked VNC authentication); CVE-2026-32006 (OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallbac) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest declares a peer dependency on OpenClaw using a broad range (>=2026.3.0) instead of pinning or constraining to a known-safe version, so deployments may resolve to vulnerable releases affected by published advisories. In a plugin that runs inside the host bot framework, inherited framework vulnerabilities can directly affect the plugin's execution environment and increase supply-chain risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.