Back to skill

Security audit

Agent Create Config

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed OpenClaw agent setup guide, but it creates persistent agents, stores credentials, and tells generated agents to trust mutable files without enough user control.

Review this skill before installing. Use it only in an OpenClaw environment where you intend to create or modify persistent agents. Confirm every filesystem write, OpenClaw config change, account binding, and gateway restart. Do not paste real Feishu tokens or app secrets into shell commands unless you have controlled shell history and logs; prefer a secret manager or masked prompt. Treat BOOTSTRAP.md and memory files as untrusted until reviewed, and avoid administrator-level bindings unless they are necessary.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
references/MERGED_PROCESS.md:84
Finding

Untrusted bootstrap instructions are automatically executed and deleted

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
references/MERGED_PROCESS.md:71
Finding

Persistent memory can store and replay unvalidated instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/MERGED_PROCESS.md:206
Finding

Feishu credentials are passed through command-line arguments

Content
View full analysis
openclaw config set channel.feishu.app_id openclaw config set channel.feishu.app_secret ``` ### Technical Analysis The documented setup procedure places the Feishu bot token and application secret directly in command-line arguments. After users replace the placeholders with real values, those secrets may be retained in shell history, terminal recordings, Agent transcripts, diagnostic output, or process-monitoring data. On some operating systems, another local process may also be able to inspect process arguments while the command is running. The documentation does not instruct users to disable history, use masked input, protect the resulting configuration file, or store the values in a dedicated secret manager. Consequently, otherwise valid credentials can be exposed through routine operational artifacts. ### Attack Path 1. An operator substitutes real Feishu credentials into the documented commands. 2. The shell records the complete command in its history, or an Agent, terminal recorder, process monitor, or logging layer captures the arguments. 3. A local user, support operator, compromised process, or party with access to collected logs reads the exposed values. 4. The attacker uses the bot token or application credentials to authenticate to the Feishu integration. 5. The attacker performs operations allowed by the compromised application's configured scopes until the credentials are revoked or rotated. ### Impact Assessment A successful attacker may impersonate the configured Feishu bot or application and exercise permissions granted to those credentials. Depending on th ...[truncated 452 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/MERGED_PROCESS.md (reported line 144)May include surrounding context.

USER.md 模板

markdown
# USER.md - 用户信息

- **Name:** 薛总
- **称呼:** 哥哥
- **Pronouns:** 他
- **Timezone:** Asia/Shanghai
- **Notes:** 35岁程序员,技术专家,喜欢研究新技术,对 AI Agents 感兴趣

3.4 IDENTITY.md 模板

markdown
# IDENTITY.md - 我是谁

- **名字:** 大叔
- **类型:** OpenClaw Agent(编程专家)
- **Emoji:** 👨‍💻
- **称呼:** 大叔
- **年龄/风格:** 35岁资深程序员
- **风格:** 严谨、专业、有原则、可信赖

3.5 TOOLS.md 模板

markdown
# TOOLS.md - 工具配置

## 已安装技能

- github - GitHub 操作(issues, PR 等)
- gh-issues - GitHub Issues 管理
- Code review 相关能力

## 常用工具

- Git - 代码版本控制
- 代码分析 - 代码审查和优化建议
- 问题诊断 - Bug 定位和修复建议

## 注意事项

- coder Agent 专注于编程任务
- 不知道就说不知道
- 三思而后行

阶段 4:注册 Agent

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

All user-facing natural-language instructions in the file are written exclusively in Chinese, and the skill does not indicate that language choice is optional or user-selectable. Under the language/locale policy, a skill should not effectively force a specific language unless the constraint is clearly documented and justified or the user is given a choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition '当用户需要创建新 Agent、创建新的机器人、制作一个新 Agent 时触发' is broad enough to match many ordinary user requests without clear scope boundaries. This can cause unintended skill activation and route users into a configuration-changing workflow that creates files, updates openclaw.json, and performs bindings, increasing the risk of unauthorized or accidental system modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick-start example '当用户说"创建一个 xxx Agent"时' provides a vague invocation pattern with no environmental, authorization, or platform constraints. In practice, this makes accidental activation more likely and can push the system toward operational changes based on ambiguous user phrasing rather than verified intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The workflow explicitly creates persistent workspace files under ~/.openclaw, including identity, memory, and user-context artifacts. Persistent state can retain sensitive data across sessions and can be abused for unauthorized context injection, privacy leakage, or long-lived manipulation if later consumed automatically by the agent.

Content

Scanner excerpt · references/MERGED_PROCESS.md (reported line 49)May include surrounding context.

bash
# 创建工作区目录
mkdir -p ~/.openclaw/workspace-coder

# 创建基础配置文件
touch ~/.openclaw/workspace-coder/SOUL.md

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The communication rules are written as fixed instructions, including a required reply format and implicitly Chinese-language interaction context, without offering the user a language preference choice. This can violate language/locale policy when a skill forces a specific language or locale without user opt-in.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

Creating persistent agent registration under ~/.openclaw/agents/coder/config.yaml establishes durable runtime behavior and trusted configuration that may be loaded automatically. If tampered with, these files can redirect workspaces, enable risky skills/channels, or preserve malicious configuration across future sessions.

Content

Scanner excerpt · references/MERGED_PROCESS.md (reported line 184)May include surrounding context.

bash
# 创建 Agent 配置目录
mkdir -p ~/.openclaw/agents/coder

# 创建 Agent 配置文件
cat > ~/.openclaw/agents/coder/config.yaml << 'EOF'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs operators to set Feishu bot credentials directly on the command line without any guidance on secret handling. This is risky because credentials may be exposed through shell history, process inspection, screenshots, logs, or copied config files, leading to bot/account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown instructs the agent to follow BOOTSTRAP.md and then delete it, which is a destructive action affecting user or system data. No warning is provided about the irreversible nature of deletion or checking that the file is no longer needed before removing it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.