Back to skill

Security audit

Compliance & Legal Pack: 4-Guide Collection for Agent Governance and Regulatory Compliance

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only bundle does not run code, but it unnecessarily asks for sensitive API, signing, wallet, and Stripe credentials.

Treat this as a documentation bundle only. Do not provide the listed API, signing, wallet, or Stripe values unless the publisher supplies a clear, reviewed executable feature that needs narrowly scoped credentials and explains how they are used and protected.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:12
Finding

Unnecessary Declaration of Sensitive Credential Requirements

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12–21
Vulnerability Type: Excessive credential access violating least privilege
Risk Level: Medium

Vulnerable Code

yaml
executable: false
install: none
credentials: [GREENHELIX_API_KEY, AGENT_SIGNING_KEY, WALLET_ADDRESS, STRIPE_API_KEY]
metadata:
  openclaw:
    requires:
      env:
        - GREENHELIX_API_KEY
        - AGENT_SIGNING_KEY
        - WALLET_ADDRESS
        - STRIPE_API_KEY
    primaryEnv: GREENHELIX_API_KEY

Technical Analysis

The package identifies itself as non-executable and contains only a manifest advertising four compliance guides. No scripts, installation actions, network operations, or other implementation capable of using these credentials are present.

Despite this, the manifest requires a GreenHelix API key, agent signing key, wallet address, and Stripe API key. A compatible host may consequently expose those values to the Skill context even though its documented and implemented behavior does not require them. Requiring signing and payment credentials without a demonstrated operational purpose violates least privilege and unnecessarily expands the secret-exposure boundary.

The reviewed package contains no code that accesses or transmits these values, so active credential theft or exfiltration is not established. The risk arises from unnecessary credential provisioning and possible access by future, external, or host-integrated components operating in that context.

Attack Path

  1. A user installs or enables the bundle.
  2. The host reads metadata.openclaw.requires.env.
  3. To satisfy the manifest, the host makes the listed environment values available to the Skill context.
  4. That context receives sensitive signing and payment credentials despite having no corresponding executable functionality.
  5. Any subsequently introduced component, externally resolved included guide, or other process able to inspect that context could attempt to read and m ...[truncated 750 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the credentials field and all entries under metadata.openclaw.requires.env because the current package is documentation-only and non-executable.
  2. If future executable features genuinely require authentication, request only the minimum credential necessary for each specific operation and only at the time of use.
  3. Avoid requesting high-impact credentials such as agent signing keys or payment API keys unless the implementation demonstrably performs an authorized operation requiring them.
  4. Document each required credential's purpose, destination, required permission scope, retention behavior, and revocation procedure.
  5. Use narrowly scoped and revocable tokens rather than broad account-level secrets.
  6. Ensure the host does not expose credentials to included or externally resolved components unless each component has been independently reviewed and explicitly authorized.
  7. Add automated manifest validation that rejects credential requirements for non-executable packages unless a documented exception is approved.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill is explicitly marked as a non-executable documentation bundle, yet it declares multiple highly sensitive credentials including API, signing, wallet, and Stripe secrets. Requesting these secrets without code-backed need creates unnecessary secret exposure risk during installation or review, and the combination of financial and signing credentials increases the blast radius if a user provides them.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.