Back to skill

Security audit

Skill Guardian

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned but needs review because it sets up recurring agent jobs that broadly read installed skill files and write persistent registry, guide, README, and notification outputs with insufficient containment.

Install only if you intentionally want an administrator-level autonomous Skill inventory service. Before using the cron setup, restrict the scanned directories, run the scheduled agent with least privilege, pin or verify the approved SKILL.md hash before each scheduled run, add explicit rules that scanned Skill contents are untrusted data, and fix the guardian-check.sh path containment logic. Expect it to overwrite generated guides and README entries and to send change notifications when configured.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:17
Finding

Persistent Scheduled Agent Execution Through Cron Jobs

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:146
Finding

Indirect Prompt Injection Through Untrusted Skill Documents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
guardian-check.sh:38
Finding

Path Whitelist Bypass and Symlink Time-of-Check/Time-of-Use Race

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk is much narrower than the declared description. It implements only one supporting sub-function: hash-based change detection for already-registered skill files, plus path-whitelist safety checks. It does not scan all workspaces dynamically, does not discover new skills, does not detect functional overlap, does not write guides or README files, and does not perform notification logic. While the description mentions a V2 hash change detector and path whitelist hardening that align with this script, the overall declared purpose describes a broader lifecycle-management skill whose main capabilities are not present in this code chunk. Therefore the description does not accurately represent what this specific code actually does.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
>   "name": "skill-guardian-daily-scan",
>   "schedule": {"kind":"cron","expr":"0 6 * * *","tz":"Asia/Shanghai"},
>   "sessionTarget": "isolated",
>   "payload": {"kind":"agentTurn","message":"请读取 ~/.openclaw/workspace/skills/skill-lifecycle-guardian/SKILL.md,严格按「工作流程」章节执行每日扫描。","timeoutSeconds":300},
>   "delivery": {"mode":"announce"}
> }'
> ```

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
>   "name": "skill-guardian-daily-scan",
>   "schedule": {"kind":"cron","expr":"0 6 * * *","tz":"Asia/Shanghai"},
>   "sessionTarget": "isolated",
>   "payload": {"kind":"agentTurn","message":"请读取 ~/.openclaw/workspace/skills/skill-lifecycle-guardian/SKILL.md,严格按「工作流程」章节执行每日扫描。","timeoutSeconds":300},
>   "delivery": {"mode":"announce"}
> }'
> ```

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction '中文输出' requires all output to be in Chinese, which is a language policy constraint expressed in natural language. The file does not provide user opt-in, a language selection mechanism, or a documented justification that this skill is region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L113-L118声明“第零步:变更检测”仅在每日定时扫描时执行,手动触发跳过;但上文自动触发说明和 cron 配置明确将“每 3 小时变更检测”也用于检测是否有变更(L036-L043、L072-L073)。这不是信息缺失,而是文档内对同一流程适用范围的直接矛盾,可能导致执行代理错误跳过或重复执行检测逻辑。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.