Back to skill

Security audit

Gpt Image2

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed paid image-generation wrapper that uses ClawdChat through uno-cli, with no local executable code found.

Install only if you are comfortable using ClawdChat/uno-cli for paid image generation. Before each submit, confirm the prompt, size, style, image count, and 300-credit cost; avoid confidential prompts or sensitive signed reference-image URLs because they are sent to the external gateway. Consider the uno-cli dependency part of the trust boundary, since this package does not pin its exact version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Credential-Handling Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27–28 and 82–87
Vulnerability Type: Unpinned executable dependency with access to credentials and network transport
Risk Level: Medium

Complete Code Snippet:

yaml
openclaw:
  requires:
    bins: ["uno"]
  skills: ["uno-cli"]
markdown
1. Install `uno-cli` (skipping if already installed):

   ```bash
   clawhub install uno-cli
   ```

   On platforms that honour `metadata.openclaw.skills`, this dependency is installed automatically when this skill is installed.

Technical Analysis

The skill depends on the executable uno-cli companion skill but does not pin it to a reviewed version, immutable digest, verified publisher identity, or cryptographic signature. Installation therefore resolves whichever release the dependency source currently supplies, including automatic installation on supported platforms.

This dependency occupies a security-sensitive trust position. According to the skill documentation, it manages OAuth authentication, accesses the bearer credential stored at ~/.clawdchat/credentials.json, transports user prompts and reference-image URLs, and submits paid image-generation requests. Although the audited package does not directly open or transmit the credential file, its unpinned dependency is entrusted with those operations.

This is a supply-chain weakness rather than evidence that the current dependency is malicious. If the package source, publisher account, name resolution, or a future dependency release were compromised, attacker-controlled code could execute with the permissions granted to uno-cli.

Attack Path

  1. An attacker compromises the uno-cli publisher account or dependency repository, or causes the unqualified dependency name to resolve to a malicious release.
  2. A user installs this skill, and the platform automatically installs uno-cli, or the user follows `clawhub install uno-cli ...[truncated 1059 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin uno-cli to a specifically audited version and, where supported, an immutable package digest.
  2. Require cryptographic signature verification and validate the expected publisher identity before installation.
  3. Avoid automatic dependency installation when version and integrity enforcement are unavailable.
  4. Document the trusted package source and reject alternate or ambiguous registries.
  5. Apply least privilege to the companion process: restrict filesystem access to the required credential file and constrain network egress to the documented HTTPS gateway.
  6. Scope and rotate bearer credentials where supported, and provide clear revocation procedures.
  7. Preserve the existing explicit confirmation requirement for every paid submission or pre-authorized batch.
  8. Warn users that reference-image URLs may contain signed query credentials and recommend short-lived, narrowly scoped URLs without unrelated secrets.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
primary_credential:
      type: clawdchat_api_key
      managed_by: uno-cli skill
      stored_at: ~/.clawdchat/credentials.json
      obtained_via: interactive `uno login` command (delegates to ClawdChat OAuth, see https://clawdchat.cn)
      scope: "Used as Authorization Bearer token to call the ClawdChat tool gateway. The credential is acquired and stored by the uno-cli skill; this skill only reuses it via the `uno` CLI and never reads, prints, or transmits the file directly."
    config_paths:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
primary_credential:
      type: clawdchat_api_key
      managed_by: uno-cli skill
      stored_at: ~/.clawdchat/credentials.json
      obtained_via: interactive `uno login` command (delegates to ClawdChat OAuth, see https://clawdchat.cn)
      scope: "Used as Authorization Bearer token to call the ClawdChat tool gateway. The credential is acquired and stored by the uno-cli skill; this skill only reuses it via the `uno` CLI and never reads, prints, or transmits the file directly."
    config_paths:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
primary_credential:
      type: clawdchat_api_key
      managed_by: uno-cli skill
      stored_at: ~/.clawdchat/credentials.json
      obtained_via: interactive `uno login` command (delegates to ClawdChat OAuth, see https://clawdchat.cn)
      scope: "Used as Authorization Bearer token to call the ClawdChat tool gateway. The credential is acquired and stored by the uno-cli skill; this skill only reuses it via the `uno` CLI and never reads, prints, or transmits the file directly."
    config_paths:

Session Persistence

Medium
Category
Rogue Agent
Confidence
73% confidence
Finding

The skill is designed to rely on a persisted authenticated session managed by uno login, and the broad activation text increases the chance that the agent invokes a paid third-party action using an already-authorized account. In context, the main risk is unauthorized or insufficiently confirmed use of a standing session leading to unwanted charges and transmission of user content to the external gateway.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: gpt-image2
description: "Generate high-quality images with GPT Image 2 (OpenAI gpt-image-2) via the ClawdChat tool gateway. Use when the user asks to create / generate / draw / paint an image, mentions GPT image, gpt-image-2, OpenAI image generation, or needs accurate text rendering (posters, infographics, menu typography), strict multi-element prompt following, image-to-image with subject/identity preservation, or specific styles such as Ghibli / Pixar / LEGO / cyberpunk / claymation / Pop Mart figurine."
homepage: https://clawdchat.cn
metadata:
  emoji: "🖼️"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says to use the skill whenever the user asks to create, generate, draw, or paint an image, which are very broad phrases common in ordinary conversation. It does not provide exclusion conditions or clearer scope boundaries for when this specific skill should be invoked versus other image-related capabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.