Back to skill

Security audit

vault-data-governance

Security checks for vulnerabilities and agentic risk

Overview

This skill is a data-cleanup workflow, but it tells agents to move files across all team workspaces and commit/push all repository changes without a clear review checkpoint.

Install only if you intend agents to perform cross-team cleanup and repository publication. Before use, require a dry-run report, owner review for moved files, explicit allowlisted paths, secret scanning of staged content, and separate confirmation before commit or push.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:57
Finding

Unreviewed Whole-Repository Staging and Remote Push

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 57
Vulnerability Type: Unrestricted repository staging and publication
Risk Level: High

Evidence

text
5. Submit: git add -A && git commit && git push

The source instruction has been translated into English without changing the command.

Technical Analysis

The workflow instructs the agent to execute git add -A, which stages all tracked modifications, deletions, and untracked files under the repository. It then commits and pushes the staged content to the configured remote repository.

There are no documented safeguards requiring:

  • Explicit path allowlisting
  • Review of the staged diff
  • Detection of credentials or other secrets
  • Separation of unrelated concurrent changes
  • Verification of the destination remote
  • User confirmation before committing or pushing

The command does not itself bypass repository authentication or obtain additional operating-system privileges. However, when executed by an agent that already possesses valid repository credentials, it can publish content beyond the files legitimately affected by the governance task.

Attack Path

  1. A sensitive, unrelated, or attacker-controlled file is created inside the repository.
  2. The file remains untracked, or an existing tracked file contains unrelated modifications.
  3. The governance workflow is invoked.
  4. git add -A stages all repository changes, including the unrelated content.
  5. git commit records those changes without a required staged-diff review.
  6. git push transmits the resulting commit to the configured remote.
  7. Users with access to the remote repository can retrieve the unintentionally published content.

Impact Assessment

Successful exploitation can disclose any file located within the repository that the executing agent can read and stage. It can also publish unrelated modifications or deletions made by other processes or users.

The affected scope is limited ...[truncated 386 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace git add -A with explicit staging of an allowlisted set of files produced by the current audit.
  2. Capture the exact moved-file list and stage only those paths, using path separators and safe quoting.
  3. Run git diff --cached --name-status and git diff --cached before committing.
  4. Abort if the staged set contains files outside the approved archive and audit-report directories.
  5. Run secret scanning against all staged content.
  6. Verify the repository root and configured remote before any write or network operation.
  7. Require explicit user approval before git commit and especially before git push.
  8. Avoid combining staging, committing, and pushing into a single unconditional command chain.
  9. Perform the push with a narrowly scoped repository identity that cannot modify unrelated repositories or protected branches.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:15
Finding

Cross-Team Filesystem Modification Without Least-Privilege Boundaries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-19 and 30-33
Vulnerability Type: Overly broad filesystem access and mutation scope
Risk Level: Medium

Evidence

Translated scope declaration from lines 15-19:

text
## Scope
- All agents: main, side_research, technical_team, export_team, aron, vicky,
  marcy, lynn, research_lead, whois_agent, company_agent, quality_inspection
- All collection directories: by-country/, computing-power-electricity/,
  special-research/, daily-audit/
- All task directories: .agent-coordination/tasks/
- All team workspaces: /root/.openclaw/workspace_teams/*

Translated cleanup rule from lines 30-33:

text
### 1. Audit Means Cleanup
During every audit, statistics, or optimization operation:
- Expired, invalid, or disproven collected information must be reported
  immediately, removed from the active directory, and archived.
- Garbage data must not accumulate, and the audit report must include cleanup actions.

The execution procedure further directs the agent to scan with find and grep and move files with mv.

Technical Analysis

The Skill grants a governance operation blanket scope over every listed agent, coordination-task directory, and team workspace under /root/.openclaw/workspace_teams/*. It also requires cleanup to occur as part of an audit rather than making modification a separately approved operation.

The terms used to authorize file movement—such as “expired,” “invalid,” “disproven,” and “garbage data”—do not have deterministic validation criteria. The Skill does not require:

  • Restriction to the invoking team's workspace
  • Confirmation from the file owner
  • A dry-run or review stage
  • Path canonicalization and boundary validation
  • Detection of symbolic-link traversal
  • Archive collision handling
  • Transactional rollback
  • Concurrency controls for files in active use

This design breaks least-privilege boundaries at the application-workflow level. It does not indepen ...[truncated 1690 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require each invocation to specify one canonical, allowlisted workspace root.
  2. Reject paths that resolve outside that root, including paths reached through symbolic links.
  3. Limit each agent to its own workspace unless a separately authorized cross-team audit is approved.
  4. Separate scanning from mutation: generate a dry-run report first and require owner approval before moving files.
  5. Define objective classification criteria for expired, invalid, disproven, temporary, and duplicate files.
  6. Use content hashes and validated metadata rather than filenames or titles alone for duplicate detection.
  7. Record source path, destination path, reason, owner, timestamp, and content hash for every proposed move.
  8. Detect destination collisions and never overwrite an existing archive file.
  9. Add locking or concurrency checks before moving files used by active tasks.
  10. Provide a tested rollback manifest capable of restoring every moved file to its original location.
  11. Run the workflow under a service identity with write access only to the explicitly selected workspace and archive directory.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly directs agents to move files, stage all changes, commit, and push repository modifications as part of a routine workflow, but it provides no requirement for explicit user approval, scope limitation, or review checkpoint before changing persistent state. In an agent context, this is dangerous because broad file movement plus git add -A && git commit && git push can archive or overwrite valuable data, propagate mistakes to remote repositories, and operationalize unintended destructive changes at scale across many directories and teams.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The title and description present the skill exclusively in Chinese, and the file does not indicate that users may choose another language or that the locale restriction is required for a specific regional purpose. This can violate language/locale policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.