Back to skill

Security audit

Subagent Collaboration

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its stated workflow-generation purpose, but its generated executable JavaScript can be injected through task text and it writes files to broad or hard-coded paths.

Review generated .js files before running them, avoid untrusted task descriptions, and always pass an explicit output directory. This is suitable only if you accept local file generation and Chinese-language tooling.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_workflow.py:287
Finding

Unescaped Task Input Allows JavaScript Injection in Generated Workflows

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/analyze_subagents.py:74
Finding

Unnecessary Full Read of Persistent Agent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/security_check.py:189
Finding

Security Checker Fails Open on Malformed Workflow Fields

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

If the skill's real function is static security checking plus local report generation, but that output behavior is not disclosed, users may invoke it in sensitive workspaces without understanding that new files will be created. Undeclared report writing can leak data into persisted artifacts, interfere with repositories, or create files that downstream automation mistakenly trusts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

If the skill's real function is static security checking plus local report generation, but that output behavior is not disclosed, users may invoke it in sensitive workspaces without understanding that new files will be created. Undeclared report writing can leak data into persisted artifacts, interfere with repositories, or create files that downstream automation mistakenly trusts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill's real function is static security checking plus local report generation, but that output behavior is not disclosed, users may invoke it in sensitive workspaces without understanding that new files will be created. Undeclared report writing can leak data into persisted artifacts, interfere with repositories, or create files that downstream automation mistakenly trusts.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/security_check.py (reported line 181)May include surrounding context.

python
try:
        if rule.get("is_batch_check"):
            return False  # 批量检查单独处理
        return rule["check"](agent)
    except Exception as e:
        return False

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/security_check.py (reported line 189)May include surrounding context.

python
try:
        if rule.get("is_batch_check"):
            return False  # 批量检查单独处理
        return rule["check"](agent)
    except Exception as e:
        return False

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no note offering an alternate language or clarifying that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and demonstrates shell execution and file read/write workflows, but the manifest does not declare any corresponding tool scope such as permissions or allowed-tools. This creates an authority mismatch where operators may trust the metadata while the skill content encourages broader capabilities, increasing the chance of unintended file or command access when integrated into an agent runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing natural-language content that effectively forces a specific language/locale for understanding and use. The policy allows language constraints only when the skill offers opt-in choice or clearly documents a justified regional limitation, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document states a hard concurrency safety rule of at most 3 subagents, yet the security-check output later says 4 concurrent agents are acceptable. Contradictory security guidance can cause operators or code generators to exceed intended safety limits, leading to resource exhaustion, monitoring blind spots, or policy bypass in multi-agent execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest promises automatic analysis of multiple sub-agents' capabilities, usage patterns, collaboration relationships, and intelligent recommendation of collaboration modes and workflow/security configuration. In code, analysis is limited to substring checks in one docs file, a simple MEMORY.md marker check, static role metadata, and generic model/category recommendations; it does not infer collaboration patterns, recommend parallel/serial/hierarchical modes, or generate workflow/security configurations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring describes the tool as scanning configured sub-agent roles, analyzing distributions and usage, and providing recommendations. However, the implementation also creates a new directory and persists a JSON report under the workspace, which is a state-changing file write not mentioned in the stated functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in the CLI description, argument help, headers, and generated task content are hardcoded in Chinese, which imposes a specific language on users. The policy allows locale constraints only when documented and justified or when the user can opt in, neither of which is present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The --output argument allows writing workflow and code files to an arbitrary filesystem path without confinement to a dedicated workspace. If this script is invoked by another agent or automation with attacker-controlled arguments, it can overwrite sensitive files or plant executable artifacts in unintended locations, which is broader access than needed for this skill’s stated purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script does more than generate analysis metadata: it also emits executable JavaScript workflow code and writes it to disk automatically. In a skill intended for collaboration analysis/design, producing runnable artifacts increases the chance that unsafe or unreviewed task content is operationalized directly, especially because the generated code spawns agent sessions from user-influenced prompts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script hard-codes a workspace path and, when no --output is provided, writes reports there automatically. For a security-checking skill, this expands behavior from analysis into persistent filesystem modification, which can leak workflow metadata into an unexpected location and create side effects outside the caller’s explicit intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The fixed path /Users/nanlin/.openclaw/workspace assumes access to a specific user’s local workspace and is unrelated to the minimal task of validating a workflow JSON. This can cause unauthorized writes, disclosure of sensitive task/report contents into a personal workspace, and unsafe behavior when run in other environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code creates parent directories and saves a report file automatically even when the user did not explicitly request persistence. In the context of an analysis skill, automatic filesystem writes broaden the operational scope and can leave sensitive artifacts or overwrite expected workspace state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

该段标题和前文规则都强调超时控制,且 L402 写明应满足 timeoutSeconds ≤300。可是在“❌ 超长超时”示例中,代码给出 3600 秒,而注释却写“>1000 秒”,这与文档其他位置使用的 300 秒基线不一致,容易混淆真正的禁止阈值。虽然这是注释层问题,但它直接影响安全规则理解。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese, which creates a language-specific user experience without any indication that users can choose another language or that the skill is intended only for a Chinese-speaking context. This is a natural-language policy concern because the file presents a fixed locale implicitly rather than offering opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow metadata records safety_check as pending, yet the script immediately writes both the workflow and executable JavaScript to disk. This creates a misleading trust signal that may cause downstream tooling or users to assume the artifact is awaiting validation when it already exists in runnable form.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and CLI description are primarily in Chinese, and later user-facing messages are also emitted in Chinese. Because the tool does not provide any opt-in or selection mechanism for language/locale, it effectively forces a specific language for users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.