Back to skill

Security audit

Scopecheck

Security checks for vulnerabilities and agentic risk

Overview

ScopeCheck is a local analyzer for SKILL.md files, and the flagged credential and network examples are documentation/test patterns rather than hidden data access.

Install and run this in a normal isolated Python environment, and prefer pinned dependency versions or a lockfile for production use. Only submit SKILL.md content you intend the local service to analyze.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code:

yaml
metadata: {"openclaw":{"emoji":"🔬","requires":{"bins":["python"]},"install":[{"id":"pip","kind":"uv","packages":["fastapi","uvicorn","pydantic","pyyaml"]}]}}

Technical Analysis

The installation metadata requests fastapi, uvicorn, pydantic, and pyyaml without exact version constraints, integrity hashes, or a committed lockfile. Consequently, identical installations performed at different times may resolve to different package versions.

The listed package names do not appear to be typosquatted or intentionally malicious. Nevertheless, unconstrained resolution means that a compromised upstream release, malicious registry response, or unexpectedly incompatible future version could enter the execution environment without a corresponding change to the reviewed Skill source.

These dependencies are imported by the application and therefore execute within the server process. For example, scopecheck/app.py imports FastAPI, while scopecheck/models.py imports Pydantic and scopecheck/extractors.py imports PyYAML.

Attack Path

  1. An operator installs the Skill using its declared uv installation configuration.
  2. The resolver queries the configured package registry for the current versions of the four unpinned packages and their transitive dependencies.
  3. A compromised or otherwise unsafe release is selected because no reviewed version or artifact hash is enforced.
  4. The package is downloaded and installed.
  5. Attacker-controlled code may execute through package installation behavior, module import, or application startup.
  6. The code runs with the permissions and accessible resources of the account or container hosting the Skill.

This is a supply-chain exposure rather than evidence that any dependency currently named by the project is ...[truncated 656 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, security-reviewed version.
  2. Generate and commit a lockfile that also fixes all transitive dependency versions.
  3. Require cryptographic hashes for downloaded artifacts where the installation system supports them.
  4. Resolve packages only from a trusted, authenticated registry or an internally controlled mirror.
  5. Add automated dependency vulnerability and provenance scanning to the release process.
  6. Review and deliberately update the lockfile on a controlled schedule rather than resolving unrestricted current versions during deployment.
  7. Run installation and the API service as an unprivileged user in an isolated environment with minimal filesystem, environment-variable, and network access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
## Undeclared access format

Each undeclared item is prefixed with its type: `env:SECRET_KEY`, `bin:curl`, `fs:/etc/passwd`, `net:https://example.com`.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Check a skill's scope

bash
curl -s -X POST http://localhost:8002/v1/check-scope \
  -H "Content-Type: application/json" \
  -d "{\"skill_content\": $(cat path/to/SKILL.md | jq -Rs)}" | jq

Static analysis

No suspicious patterns detected.