Back to skill

Security audit

Skill Father

Security checks for vulnerabilities and agentic risk

Overview

This is a guidance-only skill for creating other skills, with disclosed local configuration guidance but some secret-handling hygiene users should tighten.

Before installing or using this as a standard, require generated real config files to be excluded from version control, written with owner-only permissions, and kept out of logs and summaries. Prefer OS keychains or secret managers for tokens where practical, and review any child skill that follows this standard before allowing it to edit ~/.ssh/config, ~/.config/openclaw/env, or PATH symlinks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:37
Finding

Machine-specific configuration may expose plaintext credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37-52
Vulnerability Type: Insecure storage of sensitive configuration
Risk Level: Medium

Vulnerable Code Snippet

markdown
### 2) Configuration (portable)

Rules:

- Never hardcode machine/user-specific paths, usernames, tenant IDs, tokens, etc. inside `SKILL.md`.
- Prefer skill-local config files stored next to `SKILL.md`, e.g.:
  - `config.env` (dotenv-style KEY="VALUE")
  - `config.json` (structured)
- **Config must be split into two files**:
  - `config.env.example` (or `config.json.example`) — checked-in/shareable example; never mutated by onboarding
  - `config.env` (or `config.json`) — real machine-specific values written/updated during onboarding
- `SKILL.md` documents:
  - where config lives
  - required keys + defaults
  - which file is the example vs real
  - how to run onboarding to generate/update the real config

Technical Analysis

The standard directs child Skills to persist real machine-specific configuration in config.env or config.json beside checked-in Skill resources. Machine-specific values can include tokens, as indicated by the prohibition against placing tokens directly in SKILL.md.

Although separating example and real configuration files is appropriate, the guidance does not require:

  • Excluding real configuration files from version control
  • Creating them with restrictive permissions such as 0600
  • Using atomic writes that preserve restrictive permissions
  • Storing secrets in a credential manager instead of plaintext
  • Checking whether a real configuration file is already tracked
  • Preventing secret values from appearing in logs, diffs, backups, or error output

Consequently, child Skills implementing this authoritative standard may store credentials in plaintext within a source-controlled or broadly readable directory. The audited file does not itself contain credentials or executa ...[truncated 1399 chars]

Remediation
View remediation

Remediation Suggestions

Strengthen the configuration standard with mandatory controls:

  1. Require real configuration files to be excluded from version control, while keeping only example files tracked.
  2. Require onboarding to verify that real configuration files are not already tracked before writing secrets.
  3. Create sensitive files atomically with owner-only permissions, such as mode 0600, and verify permissions after writing.
  4. Prefer references to operating-system keychains or dedicated secret managers over storing plaintext token values.
  5. Prohibit printing secrets in logs, command output, diffs, exceptions, or onboarding summaries.
  6. Ensure backups and exported Skill packages exclude machine-specific configuration.
  7. Add an automated smoke test that rejects tracked real configuration files and warns about unsafe permissions.
  8. Document safe rotation and revocation procedures for credentials that may have been exposed.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
- Keep skills **portable/shareable**: do not bake machine-specific settings into `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
- Keep skills **portable/shareable**: do not bake machine-specific settings into `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
- Keep skills **portable/shareable**: do not bake machine-specific settings into `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- Keep skills **portable/shareable**: do not bake machine-specific settings into `SKILL.md`.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
- Generate/update the real config file from prompts and/or auto-discovery.
- If editing an existing system config file (e.g. `~/.config/openclaw/env`, `~/.ssh/config`):
  - detect whether the target file exists; create if missing
  - for each key/entry that would change, show current vs new
  - prompt the user per item: keep / override / skip
  - for secrets/tokens, mask values in prompts

Static analysis

No suspicious patterns detected.