Back to skill

Security audit

Deep Research for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent OpenClaw deep-research integration, but its install flow asks users to run code from an unpinned third-party repository without integrity checks.

Before installing, review the referenced repository, pin it to a trusted commit or release, and run the validation in a constrained environment. Only provide a Tavily API key when you intentionally want network-backed research, and assume queries or research context may leave your machine when that path is enabled.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:48
Finding

Unpinned Remote Repository Is Retrieved and Its Code Is Executed Locally

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48–60
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: Medium

Vulnerable Code

markdown
1. Clone the repository:
   - `git clone https://github.com/MilleniumGenAI/deep-research-openclaw-agent.git`

Followed by:

bash
python -m py_compile openclaw/workspace-researcher/scripts/*.py
python openclaw/workspace-researcher/scripts/init_research_run.py --workspace openclaw/workspace-researcher --topic "Smoke test" --language en --task-date 2026-03-10

Technical Analysis

The installation procedure clones the repository's mutable default branch without pinning a reviewed commit or release and without verifying a cryptographic checksum or signature. It subsequently directs the user to execute a Python script obtained from that repository.

Because the effective executable content can change after this skill is reviewed, the local SKILL.md audit cannot establish the safety of the code that users will eventually run. The py_compile command only validates Python syntax; it does not establish integrity or prevent malicious behavior when init_research_run.py is executed.

This is primarily a supply-chain weakness. It also creates a remote payload retrieval and execution channel because upstream changes directly determine the code executed by users.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or its default branch.
  2. The attacker modifies init_research_run.py, another imported Python module, or copied OpenClaw prompt/configuration content.
  3. A user follows SKILL.md and clones the current default branch.
  4. No commit pin, checksum, or signature check detects that the reviewed content has changed.
  5. The user executes the downloaded initialization script as instructed.
  6. The malicious code runs with the permissions and environmental access of that user.

...[truncated 718 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin installation to a specific, reviewed commit hash rather than cloning the mutable default branch.
  2. Publish expected SHA-256 hashes for all executable scripts and verify them before execution.
  3. Prefer signed release artifacts or signed commits/tags and document signature verification.
  4. Vendor the reviewed scripts into the skill package when practical, making the audited package the runtime source of truth.
  5. Review the entire Python import chain and all copied prompt/configuration files, not only the directly invoked script.
  6. Run initialization in a sandbox with minimal filesystem access, no unnecessary network access, and only the environment variables required for the smoke test.
  7. Do not expose TAVILY_API_KEY during local-only validation; inject it only when Tavily-backed research is explicitly requested.
  8. Replace syntax compilation as a security check with integrity verification and dependency/security scanning. Retain py_compile only as a separate correctness check.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The validation examples hard-code --language en and LANGUAGE: en, which imposes a specific language in the skill instructions. Because no user choice, opt-in, or justification for the locale restriction is provided in this file, this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to clone and wire a public third-party repository, run Python scripts, and optionally configure a Tavily API key, but it does not include an explicit warning to review the external code or understand that network-backed research may send data to outside services. This creates a supply-chain and data-exposure risk: users may execute unreviewed code or enable external API access in a trusted workflow without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.