Back to skill

Security audit

Coder for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill’s purpose is clear, but its install path asks users to clone a mutable GitHub branch, build a Docker image from it, and register retrieved agent prompts/configuration without pinning or verification.

Review the upstream repository contents, especially the Dockerfile, workspace-coder prompt pack, agent-config.template.json, and main-coder-prompt.md, before installing. Prefer checking out a specific reviewed commit and tagging the image with that revision instead of using the default branch and coder-sandbox:latest.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:42
Finding

Unpinned Remote Repository Is Retrieved and Executed During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42-51
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

markdown
## Install
1. Clone the repository:
   - `git clone https://github.com/MilleniumGenAI/coder-openclaw-agent.git`
2. Copy `openclaw/workspace-coder/` into your OpenClaw base directory, or point your agent config at that path directly.
3. Build the sandbox image from the repository root:
   - `docker build -f docker/coder-sandbox.dockerfile -t coder-sandbox:latest .`
4. Register the agent in `openclaw.json` using:
   - `openclaw/agent-config.template.json`
5. If your main agent delegates coding tasks, align it with:
   - `openclaw/main-coder-prompt.md`

Technical Analysis

The installation procedure clones the default branch of an external GitHub repository without selecting a reviewed commit, immutable release, or cryptographically verified artifact. It then builds a Docker image from the retrieved content and incorporates remote prompt and configuration files into OpenClaw.

Because the repository reference is mutable, the effective code and agent instructions executed by users can change after this skill has been reviewed. A compromised maintainer account, malicious upstream update, or repository takeover could alter the Dockerfile, build context, agent configuration, or prompt files. Docker build instructions can execute commands during image construction, while imported configuration and prompt content can subsequently influence agent behavior.

The mutable coder-sandbox:latest tag also provides no reliable association between the installed image and a specific audited source revision.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or the repository's default branch.
  2. The attacker modifies the Dockerfile or files included in the Docker build context. Alternatively, the attacker changes the agent con ...[truncated 1558 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the repository to a specific, reviewed full commit hash rather than cloning and using the default branch:
    bash
    git clone https://github.com/MilleniumGenAI/coder-openclaw-agent.git
    cd coder-openclaw-agent
    git checkout --detach <reviewed-full-commit-hash>
    
  2. Prefer signed, immutable releases and verify the maintainer's Git signature or release provenance before installation.
  3. Publish expected SHA-256 checksums for the Dockerfile, build context, agent configuration, and prompt files. Abort installation if verification fails.
  4. Replace the mutable coder-sandbox:latest tag with a version and source-revision-specific tag. Where images are distributed, reference them by immutable image digest.
  5. Review the Dockerfile and every file copied into the build context before running docker build. Use an explicit minimal build context and .dockerignore file.
  6. Build with an isolated, rootless builder where possible. Do not expose host sockets, credentials, SSH agents, secrets, privileged mode, or unrestricted host mounts to the build.
  7. Review agent-config.template.json, main-coder-prompt.md, and the workspace prompt pack before registering them. Enforce least-privilege tool and filesystem permissions independently of prompt instructions.
  8. Document the exact approved revision in SKILL.md and establish an explicit review process before updating it.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.