Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

AgentShield is a disclosed security monitor, but its installer pulls mutable remote code and enables a persistent OpenClaw-integrated service that can observe and block agent activity.

Install only if you trust the AgentShield GitHub release process, Go module, and npm plugin publisher. Before using it on sensitive work, prefer pinned versions or verified release artifacts, review the OpenClaw plugin package being installed, and understand that it will run persistently, receive tool-call/lifecycle events, store alerts locally, and may send suspicious-event context to an LLM provider if triage is enabled.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:55
Finding

Remote Binary Retrieval Proceeds Without Mandatory Integrity Verification

Content
View full analysis
/dev/null 2>&1; then ACTUAL_HASH=$(sha256sum "$TEMP_FILE" | awk '{print $1}') elif command -v shasum >/dev/null 2>&1; then ACTUAL_HASH=$(shasum -a 256 "$TEMP_FILE" | awk '{print $1}') else warn "No sha256sum or shasum available — cannot verify binary integrity" fi if [ -n "$ACTUAL_HASH" ]; then if [ "$ACTUAL_HASH" != "$EXPECTED_HASH" ]; then error "Checksum misma ...[truncated 3212 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install.sh:35
Finding

Installer Executes Unpinned Go and OpenClaw Package Versions

Content
View full analysis
/dev/null 2>&1 || error "Go not found and no pre-built binary available" log "Installing via Go..." go install "github.com/$REPO/cmd/agentshield@latest" || error "Go install failed" GOBIN=${GOBIN:-$(go env GOPATH)/bin} mkdir -p "$INSTALL_DIR" cp "$GOBIN/agentshield" "$INSTALL_DIR/$BINARY_NAME" || error "Failed to copy Go binary" } ``` ```bash # Step 1: Install the published npm package so OpenClaw can load it. log "Installing @agentshield-ai/openclaw-plugin from npm..." if openclaw plugins install @agentshield-ai/openclaw-plugin 2>/dev/null; then log "OpenClaw plugin installed" else warn "openclaw plugins install failed — plugin may not load" fi ``` ### Technical Analysis The Go fallback explicitly installs `@latest`, while the OpenClaw plugin installation provides no version. Both references are mutable and can resolve to releases that did not exist when this Skill was reviewed. Consequently, the reviewed source does not establish the exact Go revision or npm package content installed on a user's system. The OpenClaw plugin is particularly sensitive because the documentation states that it registers hooks for tool calls and agent lifecycle events. A compromised plugin release could therefore execute in the OpenClaw environment and receive security-sensitive event data. This is a supply-chain weakness rather than evidence that the current upstream packages are malicious. ### Attack Path 1. An attacker compromises the Go module repository, npm publisher account, package publication pipeline, or another relevant upstream dependency. 2. The attacker publishes a newer malicious version under the legitimate package name. 3. For the Go path, binary download mus ...[truncated 1091 chars]
Remediation
View remediation
`. 3. Verify npm package integrity using a trusted lockfile, registry integrity digest, signature, or provenance attestation. 4. Record and review the complete dependency graph for the pinned Go module and npm package. 5. Reject installation if the requested immutable version or expected digest is unavailable. 6. Update pinned versions only through a controlled review process that re-audits upstream source and generated artifacts. 7. Include the plugin implementation in the audited package, or provide verifiable source-to-package provenance so its event access and token handling can be assessed. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill also documents uninstall behavior that stops services, removes files, and reverts plugin configuration, yet this destructive capability is not reflected in the declared purpose. Hidden teardown capabilities are dangerous because they can disable protections or remove local state unexpectedly if invoked under the guise of a monitoring tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also documents uninstall behavior that stops services, removes files, and reverts plugin configuration, yet this destructive capability is not reflected in the declared purpose. Hidden teardown capabilities are dangerous because they can disable protections or remove local state unexpectedly if invoked under the guise of a monitoring tool.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install.sh (reported line 118)May include surrounding context.

sh
if command -v git >/dev/null 2>&1; then
        git clone --depth 1 "https://github.com/$RULES_REPO.git" "$INSTALL_DIR/rules-tmp" 2>/dev/null && {
            cp -r "$INSTALL_DIR/rules-tmp/"* "$INSTALL_DIR/rules/" 2>/dev/null || true
            rm -rf "$INSTALL_DIR/rules-tmp"; log "Downloaded latest rules"; return
        }
    fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
title: Suspicious File Access
    logsource: {category: agent-tool}
    detection:
      selection: {tool: file_operation, path|contains: ['/etc/passwd', '/etc/shadow', '.ssh/']}
      condition: selection
    level: medium
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 132)May include surrounding context.

sh
title: Suspicious File Access
    logsource: {category: agent-tool}
    detection:
      selection: {tool: file_operation, path|contains: ['/etc/passwd', '/etc/shadow', '.ssh/']}
      condition: selection
    level: medium
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
title: Suspicious File Access
    logsource: {category: agent-tool}
    detection:
      selection: {tool: file_operation, path|contains: ['/etc/passwd', '/etc/shadow', '.ssh/']}
      condition: selection
    level: medium
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 132)May include surrounding context.

sh
title: Suspicious File Access
    logsource: {category: agent-tool}
    detection:
      selection: {tool: file_operation, path|contains: ['/etc/passwd', '/etc/shadow', '.ssh/']}
      condition: selection
    level: medium
EOF

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · uninstall.sh (reported line 67)May include surrounding context.

sh
log "Stopping AgentShield systemd service..."
        systemctl --user stop "$SERVICE_NAME" 2>/dev/null || true
        systemctl --user disable "$SERVICE_NAME" 2>/dev/null || true
        rm -f "$HOME/.config/systemd/user/$SERVICE_NAME.service"
        systemctl --user daemon-reload 2>/dev/null || true
        log "Systemd service stopped and disabled"
    else

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and documents shell-capable installation, service management, and configuration mutation behaviors but does not declare any tool scope restrictions such as permissions or allowed-tools. This increases the chance that an invoking agent can run broad shell commands without explicit user-visible guardrails, which is risky for a skill that installs binaries, edits config, and manages persistent services.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The documented installation flow creates persistent local state under ~/.agentshield and sets up ongoing monitoring components. Persistence is expected for this type of software, but without especially prominent disclosure and consent it still represents a security-relevant behavior because it survives the current session and may continue processing data in the background.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
# Build from source
go build ./cmd/agentshield/

# Create directory structure
mkdir -p ~/.agentshield/rules

# Clone rules

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill documents loading a launchd agent, which establishes automatic background execution on macOS across sessions. Persistence mechanisms are inherently high risk in an agent skill because they can continue running, monitoring, and modifying state after the immediate task ends.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

macOS (launchd):

bash
launchctl load ~/Library/LaunchAgents/ai.agentshield.engine.plist
launchctl unload ~/Library/LaunchAgents/ai.agentshield.engine.plist
tail -f ~/.agentshield/engine.log

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill documents loading a launchd agent, which establishes automatic background execution on macOS across sessions. Persistence mechanisms are inherently high risk in an agent skill because they can continue running, monitoring, and modifying state after the immediate task ends.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

macOS (launchd):

bash
launchctl load ~/Library/LaunchAgents/ai.agentshield.engine.plist
launchctl unload ~/Library/LaunchAgents/ai.agentshield.engine.plist
tail -f ~/.agentshield/engine.log

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill sends suspicious events to third-party LLM providers for triage, but the documentation does not clearly warn that event contents may contain sensitive commands, file paths, prompts, secrets, or user data leaving the local system. In a security-monitoring context, the analyzed telemetry is especially likely to be sensitive, so silent external transmission creates significant confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

Testing the Engine Directly

bash
curl -X POST http://127.0.0.1:8433/api/v1/evaluate \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · install.sh (reported line 50)May include surrounding context.

sh
return
    fi
    log "Downloading AgentShield binary..."
    LATEST_URL="https://api.github.com/repos/$REPO/releases/latest"
    DOWNLOAD_URL=$(curl -s "$LATEST_URL" | grep "browser_download_url.*${PLATFORM}" | cut -d'"' -f4)
    if [ -z "$DOWNLOAD_URL" ]; then warn "No pre-built binary found for $PLATFORM"; install_via_go; return; fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The script downloads and executes installable code based on the mutable latest release and only performs checksum verification if a SHA256SUMS file is available. Because both the artifact and checksum are fetched from the same remote source without cryptographic signature verification, a compromised release pipeline or repository could deliver a malicious binary that this installer would trust.

Content

Scanner excerpt · install.sh (reported line 59)May include surrounding context.

sh
curl -L -o "$TEMP_FILE" "$DOWNLOAD_URL" || { warn "Download failed"; install_via_go; return; }

    # I9: Checksum verification
    RELEASE_TAG=$(curl -s "https://api.github.com/repos/$REPO/releases/latest" | grep '"tag_name"' | cut -d'"' -f4)
    CHECKSUMS_URL="https://github.com/$REPO/releases/download/${RELEASE_TAG}/SHA256SUMS"
    CHECKSUMS_FILE=$(mktemp "${TMPDIR:-/tmp}/agentshield-checksums-XXXXXX")
    CLEANUP_FILES+=("$CHECKSUMS_FILE")

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 201)May include surrounding context.

sh
WantedBy=default.target
EOF
    systemctl --user daemon-reload
    systemctl --user enable "$SERVICE_NAME" >/dev/null 2>&1 || warn "Failed to enable service"
    log "Systemd service configured"
}

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 276)May include surrounding context.

sh
if [ "${AGENTSHIELD_E2E_MODE:-0}" != "1" ]; then
        log "Starting AgentShield..."
        if [ "$OS" = "darwin" ]; then
            launchctl load "$HOME/Library/LaunchAgents/ai.agentshield.engine.plist" 2>/dev/null || warn "Failed to load launchd service"
            sleep 2
        elif command -v systemctl >/dev/null 2>&1; then
            systemctl --user start "$SERVICE_NAME" || warn "Failed to start service"; sleep 2

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 310)May include surrounding context.

sh
if [ "${AGENTSHIELD_E2E_MODE:-0}" != "1" ]; then
        log "Starting AgentShield..."
        if [ "$OS" = "darwin" ]; then
            launchctl load "$HOME/Library/LaunchAgents/ai.agentshield.engine.plist" 2>/dev/null || warn "Failed to load launchd service"
            sleep 2
        elif command -v systemctl >/dev/null 2>&1; then
            systemctl --user start "$SERVICE_NAME" || warn "Failed to start service"; sleep 2

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · uninstall.sh (reported line 27)May include surrounding context.

sh
echo "The following will be deleted:"
    echo "  • AgentShield binary and configuration"
    echo "  • Security rules and database"
    echo "  • Systemd service (if installed)"
    echo "  • OpenClaw plugin configuration"
    echo

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
if [ "$os" = "darwin" ]; then
        log "Stopping AgentShield launchd service..."
        PLIST="$HOME/Library/LaunchAgents/ai.agentshield.engine.plist"
        launchctl unload "$PLIST" 2>/dev/null || true
        rm -f "$PLIST"
        log "Launchd service stopped and removed"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

md
if [ "$os" = "darwin" ]; then
        log "Stopping AgentShield launchd service..."
        PLIST="$HOME/Library/LaunchAgents/ai.agentshield.engine.plist"
        launchctl unload "$PLIST" 2>/dev/null || true
        rm -f "$PLIST"
        log "Launchd service stopped and removed"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 208)May include surrounding context.

sh
if [ "$os" = "darwin" ]; then
        log "Stopping AgentShield launchd service..."
        PLIST="$HOME/Library/LaunchAgents/ai.agentshield.engine.plist"
        launchctl unload "$PLIST" 2>/dev/null || true
        rm -f "$PLIST"
        log "Launchd service stopped and removed"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 212)May include surrounding context.

sh
if [ "$os" = "darwin" ]; then
        log "Stopping AgentShield launchd service..."
        PLIST="$HOME/Library/LaunchAgents/ai.agentshield.engine.plist"
        launchctl unload "$PLIST" 2>/dev/null || true
        rm -f "$PLIST"
        log "Launchd service stopped and removed"

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 213)May include surrounding context.

sh
if [ "$os" = "darwin" ]; then
        log "Stopping AgentShield launchd service..."
        PLIST="$HOME/Library/LaunchAgents/ai.agentshield.engine.plist"
        launchctl unload "$PLIST" 2>/dev/null || true
        rm -f "$PLIST"
        log "Launchd service stopped and removed"

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
manifest.json:30