Back to skill

Security audit

Claude Code Openclaw Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Claude Code integration, but it recommends a high-risk remote installer and broad coding-agent authority without enough scoping or safety guidance.

Review this skill carefully before installing. Use official, verifiable Claude Code installation instructions instead of blindly piping a remote script into a shell; run it only in trusted repositories; keep tokens least-privileged; understand that Claude Code, MCP servers, hooks, and sub-agents may read code, run commands, change files, and persist configuration or sessions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:17
Finding

Unverified Remote Installation Script Executed Directly by Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–21
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code:

markdown
1. **Install Claude Code CLI**:
   ```bash
   curl -fsSL https://claude.ai/install.sh | bash
   ```

Technical Analysis

The installation instructions pipe content retrieved from an external URL directly into bash. This makes the code that ultimately executes mutable after the Skill has been reviewed. No version is pinned, and no checksum, cryptographic signature, or trusted package metadata is verified before execution. The command also provides no opportunity to inspect the downloaded script separately.

HTTPS protects the connection in transit but does not establish that every future version of the hosted script is safe. Compromise of the hosting account, deployment pipeline, DNS or delivery infrastructure could cause attacker-controlled shell commands to execute. While installing Claude Code is relevant to the declared functionality and the URL appears associated with the named service, immediate execution of unverified network content exceeds the minimum-risk installation process.

Attack Path

  1. An attacker compromises the remote script, its publishing pipeline, hosting infrastructure, or another component of its delivery path.
  2. A user follows the prerequisite command in SKILL.md.
  3. curl retrieves the attacker-controlled content from the mutable remote endpoint.
  4. The pipe sends the response directly to bash without local review or integrity verification.
  5. The malicious commands execute with all privileges available to the user running the installation command.
  6. The payload can access or alter resources available to that account, potentially including repositories, environment credentials, authentication material, shell configuration, and user-level startup mechanisms.

Impact Assessment

Succ ...[truncated 577 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the curl | bash workflow with an official package-manager installation method that verifies signed repository metadata and supports pinned versions.
  2. If a standalone installer is required, download a version-specific artifact to disk without executing it immediately.
  3. Publish and verify a cryptographic signature from a trusted signing key. At minimum, verify a SHA-256 digest obtained through an independently authenticated channel.
  4. Present the downloaded script for inspection before execution and run it as a separate, explicit command.
  5. Avoid sudo or administrator execution unless a documented installation step strictly requires it. Prefer a user-scoped installation directory with minimal filesystem permissions.
  6. Pin the installer or release version rather than relying on a mutable endpoint such as install.sh.
  7. Document the files, network access, and configuration changes the installer is expected to make so users can validate its behavior.

A safer conceptual workflow is:

bash
curl -fSLo claude-installer.sh "https://trusted.example/claude/<pinned-version>/install.sh"
echo "<trusted-sha256>  claude-installer.sh" | sha256sum --check -
less claude-installer.sh
bash claude-installer.sh

The actual download URL, digest, and signature-verification procedure must come from authenticated official release documentation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching and executing a remote installation script in one command is a classic arbitrary code execution risk. Because this skill targets developer environments with likely access to source code, credentials, and SSH keys, exploitation could lead to full workstation or CI compromise.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

  1. Install Claude Code CLI:

    bash
    curl -fsSL https://claude.ai/install.sh | bash
    
  2. Authenticate:

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash chaining pattern removes the user's opportunity to inspect downloaded content before execution, turning a network fetch directly into shell execution. In this skill's context, that is especially risky because the target audience is likely to run it in privileged development environments where compromise has broad downstream impact.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

  1. Install Claude Code CLI:

    bash
    curl -fsSL https://claude.ai/install.sh | bash
    
  2. Authenticate:

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

Use OpenClaw's exec tool to run Claude Code commands:

bash
claude -p "What files were changed in the last commit?"

Method 2: Session Management

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly advertises capabilities to edit files, run terminal commands, and create commits/PRs, but it does not warn users that invoking it can cause real, potentially destructive changes to their repository or local environment. In an agent-skill context, omission of these safety boundaries increases the chance of unsafe delegation and unintended code execution or source-control actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions tell users to pipe a remotely fetched script directly into bash without any caution, verification, or integrity check. This is dangerous because compromise of the remote host, network path, or script content could result in immediate arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The MCP integration examples encourage connecting external servers/tools but omit any warning that repository contents, prompts, secrets, or environment-derived data may be sent to third-party systems. In a coding-agent workflow, these integrations can materially expand data exposure and trust boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.