Back to skill

Security audit

OpenClaw Smart Agent Hub

Security checks for vulnerabilities and agentic risk

Overview

This is a real multi-provider model-routing skill, but it needs Review because its local discovery and credential workflows are broader and less controlled than the docs make clear.

Install only if you are comfortable with the skill probing configured local model endpoints and writing local config/cache files. Before use, restrict discovery endpoints to trusted localhost addresses, avoid running provider_manager.py on configs from others, use environment variables instead of inline api_key values, add runtime config and cache files to your own .gitignore, and rotate any key ever committed or shared.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/provider_manager.py:143
Finding

Unrestricted Configurable Endpoint Requests Enable SSRF and Local-Network Probing

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
examples/add_openai.yaml:4
Finding

Plaintext API-Key Workflow Can Expose Provider Credentials

Content
View full analysis
bool: """添加新厂商""" if 'providers' not in self.config: self.config['providers'] = {} self.config['providers'][name] = config with open(MODELS_CONFIG, 'w', encoding='utf-8') as f: yaml.dump(self.config, f, allow_unicode=True) return True ``` The security notice at `SECURITY_NOTICE.md:9-13` claims ignore protection is already present: ```bash # 已自动添加到 .gitignore echo "config/models.yaml" >> .gitignore echo "skills/*/config/models.yaml" >> .gitignore ``` However, the audited project tree contains no `.gitignore`, and `config/models.yaml` is itself part of the distributed project. ### Technical Analysis The configuration format supports both an environment-variable name and an inline `api_key`. The supplied example di ...[truncated 2308 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY_NOTICE.md (reported line 21)May include surrounding context.

推荐方式

api_key_env: BAILIAN_API_KEY

在 .env 文件中设置(不要提交 .env 到 Git)

BAILIAN_API_KEY=sk-sp-xxx

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY_NOTICE.md (reported line 48)May include surrounding context.

推荐方式

api_key_env: BAILIAN_API_KEY

在 .env 文件中设置(不要提交 .env 到 Git)

BAILIAN_API_KEY=sk-sp-xxx

text

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose is model assignment/routing, but the described behavior also includes local endpoint scanning, provider management, and file/cache manipulation. This mismatch is dangerous because users may invoke the skill expecting passive routing logic while it performs broader discovery and system-affecting actions, undermining informed consent and increasing the attack surface.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/configure_openai.yaml (reported line 59)May include surrounding context.

yaml
local_first: false

# 环境变量设置说明
# 在 .env.local 文件中设置(不要提交到 Git):
# OPENAI_API_KEY=sk-proj-xxxxxxxxxxxxxxxxxxxxxxxx

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is written almost entirely in Chinese and labels some content as bilingual elsewhere, but this file itself does not offer a language choice or explain that it is intentionally region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and documents capabilities that imply network access, filesystem read/write, and possible environment use, but it does not declare any tool scope or permissions boundaries. In an agent ecosystem, missing explicit permissions increases the chance that a user or host system grants broader access than expected, making unintended local inspection or modification easier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly promotes automatic scanning of local model services but does not warn that it will inspect the local environment and contact localhost endpoints. Even if limited to local services, this can reveal installed tooling, enumerate internal services, and trigger unintended requests against sensitive local interfaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quick-start and management commands include a scan action without explaining that it will automatically discover and contact local model services. Users may run the command as a harmless inventory step, but it can perform active probing of local endpoints and create network or audit side effects on the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely written in Chinese, including headings and status text, with no indication that language selection is optional or that the file is intentionally region-specific. Per the policy criteria, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest contains user-facing natural-language instructions such as setup guidance and warnings entirely in Chinese. Under the language/locale policy, forcing a single language without user opt-in or justification is a policy concern because non-Chinese-speaking users may be unable to safely configure the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to configure API keys for third-party providers without clearly warning that prompts, metadata, and possibly sensitive agent data may be transmitted to external cloud services. In a multi-provider routing skill, this omission is more significant because the system can route tasks across several vendors, increasing the chance of unintentional data exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · config/models.yaml (reported line 72)May include surrounding context.

yaml
type: openai-compatible
    enabled: true
    priority: 2
    base_url: https://api.openai.com/v1
    api_key_env: OPENAI_API_KEY  # ✅ 推荐使用环境变量
    # api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX  # ⚠️ 或临时测试用(不要提交)
    timeout: 30

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/README_en.md (reported line 63)May include surrounding context.

md
type: openai-compatible
    enabled: true
    priority: 2
    base_url: https://api.openai.com/v1
    api_key_env: OPENAI_API_KEY  # ✅ 推荐使用环境变量
    # api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX  # ⚠️ 或临时测试用(不要提交)
    timeout: 30

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/README_zh.md (reported line 64)May include surrounding context.

md
type: openai-compatible
    enabled: true
    priority: 2
    base_url: https://api.openai.com/v1
    api_key_env: OPENAI_API_KEY  # ✅ 推荐使用环境变量
    # api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX  # ⚠️ 或临时测试用(不要提交)
    timeout: 30

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/add_openai.yaml (reported line 15)May include surrounding context.

yaml
type: openai-compatible
    enabled: true
    priority: 2
    base_url: https://api.openai.com/v1
    api_key_env: OPENAI_API_KEY  # ✅ 推荐使用环境变量
    # api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX  # ⚠️ 或临时测试用(不要提交)
    timeout: 30

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/configure_openai.yaml (reported line 11)May include surrounding context.

yaml
type: openai-compatible
    enabled: true
    priority: 2
    base_url: https://api.openai.com/v1
    api_key_env: OPENAI_API_KEY  # ✅ 推荐使用环境变量
    # api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX  # ⚠️ 或临时测试用(不要提交)
    timeout: 30

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. The module docstring presents the skill only in Chinese, with no indication that users may choose another language or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language descriptions, docstrings, and console output in Chinese, but does not indicate that the language is optional or limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file advertises 'Automatically scan and discover local model services' as a feature, but it does not warn users that invoking scanning will send requests to local endpoints and probe running services. For a markdown skill description, this is a user-visible behavior that can affect system/privacy awareness and should be disclosed more explicitly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to run the scan command directly, but provides no warning that this operation performs network requests to local services such as Ollama or LM Studio. Because this markdown serves as user guidance, omitting that disclosure can leave users unaware of the operation's effect on their local system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation promotes automatic scanning of local model services but does not clearly warn that this feature will actively send requests to localhost endpoints and may enumerate locally exposed services. In this skill context, that behavior is expected functionality, but the missing disclosure can still surprise users and reduce informed consent around local network probing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This manifest contains user-facing comments and instructions primarily in Chinese, with some English, but does not state that the file is intended only for Chinese-speaking users or offer a language/locale alternative. Under the natural-language policy rule, forcing a specific language without opt-in can be a policy concern even in configuration comments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This YAML file contains user-facing natural language comments entirely in Chinese, such as setup warnings and configuration guidance. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale policy issue when no alternative language or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.