Back to skill

Security audit

ODSH-Interop

Security checks for vulnerabilities and agentic risk

Overview

This skill is disclosed as an OpenClaw-to-DSH bridge, but it gives broad automatic delegation guidance for an always-on execution layer that can run files, commands, network work, and enabled desktop automation.

Install only if you intentionally want OpenClaw to act as a router to an always-ready DSH execution layer. Confirm the shared bridge directory, notification channel, DSH daemon, and any Cua/desktop automation setup are trusted, and prefer asking for explicit confirmation before relaying sensitive, account, credential, financial, or desktop-control tasks.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
97% confidence
Finding
The skill explicitly states it should run 'for every incoming operator request,' making its routing and relay behavior globally applicable rather than narrowly scoped to explicit bridge/interoperability tasks. An overly broad activation scope increases the chance that unrelated user prompts are intercepted, re-routed, or transformed into cross-container execution requests, expanding the blast radius for prompt injection, unintended delegation, and data exposure to the DSH layer.

Static analysis

No suspicious patterns detected.