Back to skill

Security audit

Phoenix Shield

Security checks for vulnerabilities and agentic risk

Overview

PhoenixShield is presented as a safety system for updates and rollback, but the package does not include the executable that would provide those protections while its docs encourage high-impact unattended system updates.

Review carefully before installing. Do not rely on the advertised rollback, encryption, or monitoring protections unless the missing executable and its implementation are supplied and audited. Avoid the cron example and any production use of unpinned latest updates; require explicit approval, staging validation, backups, and least-privilege execution for any system-modifying command.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
docs/examples.md:50
Finding

Persistent Unattended Global Software Updates Through Cron

Content
View full analysis
> /var/log/phoenix-daily.log 2>&1 ``` ``` ### Technical Analysis The documentation recommends adding PhoenixShield to crontab so that it executes every day and performs a global npm installation. A cron entry survives the current Skill invocation and therefore establishes cross-session persistence. The task may execute as root because it uses `/usr/local/bin`, writes to `/var/log`, and performs a global npm installation. No least-privilege account, sandbox, version constraint, approval gate, or execution restrictions are specified. Persistent scheduling is not necessary for the Skill's core on-demand backup and protected-update functionality. If automated monitoring or updates are optional features, they should require explicit informed consent and use tightly constrained permissions. ### Attack Path 1. A user follows the documentation and adds the entry to a user or root crontab. 2. Cron invokes `/usr/local/bin/phoenix-shield` every day at 03:00. 3. PhoenixShield passes `npm install -g openclaw@latest` to its deployment command. 4. npm retrieves the package version currently associated with the mutable `latest` tag. 5. Package installation or lifecycle scripts execute with the privileges of the cron owner. 6. If the package, a dependency, the registry account, or the local `phoenix-shield` executable is compromised, attacker-controlled code is repeatedly executed. 7. The cron entry continues operating across sessions and system reboots until explicitly removed. ### Impact Assessment When installed in root's crontab, successful e ...[truncated 510 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:167
Finding

Unpinned Global Installation From a Mutable Package Release

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
install.sh:21
Finding

Installer References an Executable Missing From the Distributed Artifact

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file presents PhoenixShield as a mature self-healing backup and rollback system, but the documented behavior is largely aspirational and includes examples that primarily execute arbitrary update commands such as apt and npm operations. This mismatch can mislead users into trusting nonexistent safety controls, causing them to run high-risk system changes under the false assumption that monitoring, canarying, integrity verification, and rollback protections actually exist.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and demonstrates shell-based operational capabilities but does not declare any tool scope such as permissions or allowed-tools. In agent environments, this can cause the skill to run with broader-than-expected command execution privileges, making destructive update, backup, or rollback commands easier to invoke without clear governance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs users to perform system updates, deployments, and automatic rollback actions that can change packages, restart services, or revert system state, but it does not provide an explicit warning about service disruption, compatibility breakage, or data/state loss. In a production-update skill, omission of such warnings increases the chance of unsafe execution by operators who assume the process is harmless or fully reversible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The backup section states that PhoenixShield collects configuration files, database dumps, system state, process lists, network connections, and health metrics, all of which may contain credentials, secrets, user data, or sensitive operational metadata. Without a privacy and data-handling warning, users may unknowingly collect and retain highly sensitive information in backups or monitoring artifacts, expanding exposure if those artifacts are accessed or exfiltrated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The cron example performs unattended package installation and deployment on a fixed schedule without documenting safeguards such as approval gates, environment scoping, staging validation, or alerting. In an ops skill focused on automated updates, readers may copy this directly into production, increasing the chance of unexpected changes, supply-chain issues, or service disruption even if rollback is enabled.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 28)May include surrounding context.

sh
# Create config directory
echo "📁 Creating config directories..."
mkdir -p /var/backups/phoenix 2>/dev/null || mkdir -p "$HOME/.phoenix/backups"

# Check if in PATH
if [[ ":$PATH:" != *":$INSTALL_DIR:"* ]]; then