Back to skill

Security audit

Locker Vault

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent secrets-vault helper, but it documents unsafe installation and secret-handling patterns that warrant Review before use.

Review before installing. Require a verified, pinned Locker CLI installation path; remove examples that write secrets to .env, export all secrets, or place access keys in crontab; use read-only Locker keys by default; and avoid create/update paths that pass secret values in command-line arguments unless the CLI supports a safer stdin or file-descriptor mechanism.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:118
Finding

Unverified Remote Installer Is Piped Directly into a Shell

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/vault-client.js:249
Finding

Secret Values Are Exposed Through Child-Process Command-Line Arguments

Content
View full analysis
` argument. Depending on operating-system policy and monitoring configuration, process arguments may be visible through process inspection interfaces, endpoint monitoring, audit logs, crash reports, diagnostic tools, or process accounting. This is unnecessary exposure for the Skill's declared secret-management function. The read-only/read-write permission gate does not mitigate this issue. Any permitted call to `create()` or `update()` transports the sensitive value through the process argument vector. ### Attack Path 1. The vault client is initialized in `rw` mode. 2. An authorized caller invokes `create(key, value)` or `update(key, value)`. 3. The client starts the Locker CLI with the secret embedded in `--value=`. 4. A same-host observer, diagnostic agent, audit subsystem, or monitoring product captures ...[truncated 717 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/cli-reference.md:102
Finding

CLI Examples Encourage Plaintext Credential Exposure in Files, Environment State, Pipelines, and Crontab

Content
View full analysis
.env ``` ``` Secret pipeline example: ```bash Returns only the value (stdout), suitable for piping: ```bash locker secret get --name=MYSQL_PASSWORD | mysql -h db.example.com -u admin -p ``` ``` Broad environment-export example: ```bash ### Set / Export as System Variables ```bash # Loads all secrets as environment variables for the next command locker secret set && node app.js ``` This exports secrets as system variables, making them available to the spawned process. ``` Crontab example: ```bash # crontab entry 0 */6 * * * LOCKER_ACCESS_KEY_ID=ak_xxx LOCKER_SECRET_ACCESS_KEY=sk_xxx locker secret get --name=API_TOKEN | xargs -I{} curl -H "Authorization: Bearer {}" https://api.example.com/sync ``` ### Technical Analysis These examples conflict with the primary Skill instructions that prohibit writing credentials to `.env` files and require scheduled-task configuration to contain vault references rather than raw values. The documented patterns create several exposure channels: - The `.env` recommendation is described as exporting secrets to a plaintext local file. Such files may be readable by other users, copied into backups, included in container build contexts, or committed to source control. The documented `secret list` output is also described elsewhere as key names only, making this example internally inconsistent and unsafe to rely upon. - Exporting all secrets into the environment gives the spawned application access to every exported credential rather than only the credentials it needs. - Shell pipelines move decrypted secrets b ...[truncated 2035 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
Also use when creating cron jobs, scheduled tasks, integrations, or any process that requires
  credentials — the skill ensures vault item IDs are stored instead of raw values. Triggers:
  "secret", "credential", "API key", "token", "password", "vault", "locker", "access key",
  "env var", "environment variable", ".env", "sensitive", "connection string", "webhook secret".
---

# Locker Vault — Secrets Management for OpenClaw Agents

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill instructs users to install software by piping a remote script directly into bash. This is a classic supply-chain risk: if the remote server, transport, DNS, or published installer is compromised, arbitrary code will execute immediately on the agent host with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

bash
# Download and install (check locker.io/secrets/download for latest)
curl -fsSL https://locker.io/secrets/install.sh | bash

# Verify installation
locker --version

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The '| bash' pattern explicitly chains network retrieval to code execution without any verification boundary. In the context of a secrets-management skill intended for hosts with credential access, this is especially dangerous because compromise of the installer path could lead directly to theft of vault access keys or tampering with secret-handling behavior.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

bash
# Download and install (check locker.io/secrets/download for latest)
curl -fsSL https://locker.io/secrets/install.sh | bash

# Verify installation
locker --version

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
Copy `scripts/vault-client.js` into the agent's workspace. The script has zero npm dependencies — it uses only Node.js built-in modules (`child_process`, `util`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 270)May include surrounding context.

md
Copy `scripts/vault-client.js` into the agent's workspace. The script has zero npm dependencies — it uses only Node.js built-in modules (`child_process`, `util`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 351)May include surrounding context.

md
Copy `scripts/vault-client.js` into the agent's workspace. The script has zero npm dependencies — it uses only Node.js built-in modules (`child_process`, `util`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 407)May include surrounding context.

md
Copy `scripts/vault-client.js` into the agent's workspace. The script has zero npm dependencies — it uses only Node.js built-in modules (`child_process`, `util`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 365)May include surrounding context.

Never Store Credentials Locally

javascript
// ❌ WRONG: Writing to .env
fs.writeFileSync('.env', `API_KEY=${apiKey}`);

// ❌ WRONG: Hardcoding in config

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 366)May include surrounding context.

javascript
// ❌ WRONG: Writing to .env
fs.writeFileSync('.env', `API_KEY=${apiKey}`);

// ❌ WRONG: Hardcoding in config
const config = { token: 'sk-live-abc123' };

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Directing users to dump secrets into .env facilitates credential access by placing sensitive values in a plaintext file that is easy to exfiltrate, commit, or accidentally disclose. In the context of a secrets-management skill, this is a strong contradiction of the intended trust boundary and substantially increases exposure risk.

Content

Scanner excerpt · references/cli-reference.md (reported line 37)May include surrounding context.

Output: One key per line, or a formatted table depending on CLI version.

Export all secrets to .env file:

bash
locker secret list > .env

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly instructs users to export all secrets into a local .env file, which directly conflicts with the skill's stated anti-leakage purpose. Writing all secrets to disk materially increases the chance of credential disclosure through source control, backups, filesystem compromise, developer tooling, or accidental sharing.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This duplicate .env export finding is also a true issue because it promotes plaintext persistence of sensitive values in a commonly mishandled file format. Such files are frequently captured by tooling, backups, shell history workflows, or source control mistakes, making credential compromise more likely.

Content

Scanner excerpt · references/cli-reference.md (reported line 39)May include surrounding context.

Export all secrets to .env file:

bash
locker secret list > .env

Get a Secret

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example recommends exporting all secrets as system variables for a child process, which broadens secret exposure across process boundaries and runtime inspection surfaces. In a skill whose purpose is preventing leakage, this pattern is especially dangerous because it normalizes indiscriminate secret materialization into process environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The cron example embeds raw access keys directly in the crontab, creating persistent plaintext credentials in system configuration. This is highly inconsistent with the skill's promise to store vault identifiers instead of raw secrets, and cron entries may be readable through administrative tooling, backups, or misconfigured permissions.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The cron pipeline chains secret retrieval directly into xargs and curl, causing the secret to flow through multiple process invocations and command-line contexts. This increases exposure through process listings, shell debugging, wrapper logs, and operational observability systems, especially in unattended scheduled jobs.

Content

Scanner excerpt · references/cli-reference.md (reported line 105)May include surrounding context.

bash
# crontab entry
0 */6 * * * LOCKER_ACCESS_KEY_ID=ak_xxx LOCKER_SECRET_ACCESS_KEY=sk_xxx locker secret get --name=API_TOKEN | xargs -I{} curl -H "Authorization: Bearer {}" https://api.example.com/sync

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Piping a remotely fetched installer script directly into bash executes unverified code immediately and removes opportunities for inspection or integrity verification. This is a well-known supply-chain hazard, and in an agent-oriented skill it is especially risky because automation may perform the action without human review.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The instruction curl -fsSL https://locker.io/secrets/install.sh | bash is a classic remote-script execution pattern that can lead to arbitrary code execution if the host, transport, or distribution channel is compromised. Because this is documentation for agent use, the pattern is more dangerous: agents may execute it automatically without verifying provenance.

Content

Scanner excerpt · references/cli-reference.md (reported line 126)May include surrounding context.

bash
# macOS / Linux
curl -fsSL https://locker.io/secrets/install.sh | bash

# Verify
locker --version

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Chaining a network fetch directly into bash creates an execution path where untrusted remote content becomes shell code with no validation barrier. This materially increases supply-chain and compromise impact because any malicious change upstream immediately becomes local code execution.

Content

Scanner excerpt · references/cli-reference.md (reported line 126)May include surrounding context.

bash
# macOS / Linux
curl -fsSL https://locker.io/secrets/install.sh | bash

# Verify
locker --version

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/vault-client.js (reported line 94)May include surrounding context.

js
if (err.code === 'ENOENT') {
      const error = new Error(
        `VAULT_CLI_NOT_FOUND: The "${_config.cliPath}" binary was not found. ` +
        `Install Locker CLI: curl -fsSL https://locker.io/secrets/install.sh | bash`
      );
      error.code = 'VAULT_CLI_NOT_FOUND';
      throw error;

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes and encourages use of shell execution and environment-based secret bootstrapping, but it does not declare an explicit tool scope or permission boundary in its own metadata. In an agent ecosystem, undocumented capability assumptions can cause the skill to be invoked in contexts with broader-than-expected privileges, increasing the chance of unsafe secret access or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is extremely broad and includes common terms like 'secret', 'token', 'password', '.env', and 'sensitive', which can cause the skill to activate in many ordinary conversations. Because this skill is designed around credential handling and shell-backed vault access, accidental invocation expands the attack surface and raises the probability of unnecessary secret access workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The guidance says environment variables are preferred for agents, even though the skill claims to minimize raw secret exposure and promote vault-reference handling. Environment variables are often visible to subprocesses, crash dumps, diagnostics, and sometimes other local users or orchestration layers, so this advice weakens the stated security posture.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The secret export examples lack any caution that .env files and environment variables can expose credentials through logs, process inspection, backups, and accidental commits. In a secrets-management skill, omission of these warnings makes misuse more likely and increases the chance of downstream credential leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown documents locker secret delete --name=SECRET_KEY as a standalone command but provides no user warning about deleting a secret. Because deletion can remove access to configuration or credentials and may be irreversible depending on backend behavior, the description should disclose that risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.