Back to skill

Security audit

clawvision-ee

Security checks for vulnerabilities and agentic risk

Overview

This skill exports user-selected OpenClaw sessions into local summary files, and its sensitive access is disclosed and aligned with that purpose.

Install only if you are comfortable granting the skill access to selected OpenClaw session history and local export file creation. Review generated files before sharing them, especially if the source session may include secrets, personal data, or internal identifiers.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The documented behavior and the observed implementation capabilities do not match, which breaks the trust boundary users rely on when granting access to session history, local files, and code execution. If the skill actually performs unrelated file aggregation or omits the promised summarization/session-selection flow, users may expose sensitive local data or believe content was processed in a narrower, safer way than it really was.

Static analysis

No suspicious patterns detected.