Back to skill

Security audit

OpenClaw Security Auditor

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only skill is a coherent local OpenClaw configuration auditor with disclosed config reading and redaction guidance.

Before installing, confirm you are comfortable with the skill reading your OpenClaw config file. The artifact instructs the agent to strip secrets and report only metadata, but if your configured LLM is a hosted provider, the redacted findings may still be processed through that provider via your normal OpenClaw setup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
75% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · examples/report-sample.md (reported line 22)May include surrounding context.

md
1. Hard-coded API token in `config/dev.yml`
   - Risk: Token exposure in source control
   - Recommendation: Move secrets to local env vars or a secure store
2. Debug mode enabled in production config
   - Risk: Information disclosure
   - Recommendation: Disable debug mode and restrict verbose logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/INSTALLATION.md (reported line 64)May include surrounding context.

md
- Install jq:
  - macOS: `brew install jq`
  - Ubuntu/Debian: `sudo apt-get install jq`
  - Windows: install via Chocolatey or Scoop

### Config file missing

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · examples/average-setup.md (reported line 50)May include surrounding context.

md
allowFrom:
           - "user:123456789"

2. Tool policies allow elevated tools without confirmation
   - Why it matters: Elevated tools can modify files or run commands without oversight.
   - How to fix:
     1. Require approval for elevated tools.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · examples/critical-findings.md (reported line 73)May include surrounding context.

md
- "user:123456789"

2. No channel rate limits
   - Why it matters: Unbounded requests increase risk of abuse and denial of
     service.
   - How to fix:
     1. Add per-channel rate limits.

Static analysis

No suspicious patterns detected.