Back to skill

Security audit

openclaw session inspector

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate session-monitoring purpose, but it can persistently reactivate OpenClaw agent sessions and tell them to inspect the host or continue work without a fresh user decision.

Install only if you want a persistent OpenClaw session watcher that can message existing sessions and potentially cause them to inspect local host state or continue prior work. Review the service files before enabling them, keep the runtime directory private, and avoid registering sessions tied to sensitive work unless you are comfortable with the stored session and delivery metadata.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
prompts/recovery.txt:1
Finding

Persistent watcher injects system-impersonating instructions that can reactivate agent execution

Content
View full analysis
2. If the task is clearly waiting for user input, approval, confirmation, a decision, or an external response, reply: STATUS: WAITING | 3. If the task is not yet complete, but work can still continue now, or you have resumed progress during this inspection turn, reply: STATUS: RUNNING | 4. If the task is not yet complete, and you truly cannot continue right now, and it is not simply waiting for the user, reply: STATUS: BLOCKED | Requirements: - Review recent messages, current workspace state, and existing outputs before deciding. - You may call necessary tools and continue the original task within this inspection turn. - Do not start unrelated new tasks. - Do not repeat unnecessary initialization. - If the status of background execution chains is unclear, or completion events seem unreliable, do not rely only on OpenClaw-managed status to judge task progress. You must immediately cross-check the real state from the host system using commands s ...[truncated 3472 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
scripts/inspector.js:212
Finding

Install command places a persistent KeepAlive launch agent in the macOS startup directory

Content
View full analysis
\n\n\n \n Label${serviceName}\n ProgramArguments\n \n ${nodeBin}\n ${watcherScript}\n \n EnvironmentVariables\n \n SESSION_INSPECTOR_HOME${runtimeHome}\n SESSION_INSPACTOR_HOME${runtimeHome}\n PATH${process.env.PATH || ''}\n \n RunAtLoad\n KeepAlive\n WorkingDirectory${runtimeHome}\n StandardOutPath${path.join(logsDir, 'launchd.stdout.log')}\n StandardErrorPath${path.join(logsDir, 'launchd.stderr.log')}\n \n\n`; fs.writeFileSync(plistPath, plist, 'utf8'); fs.writeFileSync(path.join(launchdDir, `${serviceName}.plist`), plist, 'utf8'); return { manager: 'launchd', unit: plistPath, next_steps: [ `launchctl unload ${shellQuote(plistPath)} 2>/dev/null || true`, `launchctl load ${shellQuote(plistPath)}`, ], }; } ``` ### Technical Analysis The `install` command does not execute `launchctl load`, and the documentation states that services should not be started or enabled without explicit user authorization. However, on macOS, installation writes the plist directly to `~/Library/LaunchAgents`, which is the standard per-user auto-start location. The generated definition contains both: ...[truncated 1836 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common.js:46
Finding

Session routing metadata and operational logs are written without enforced owner-only permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented purpose frames the skill as inspection and registration, but the behavior described by the findings includes autonomous notification dispatch, continuous watcher polling, and persistence/state tracking. That mismatch is dangerous because operators may invoke the skill expecting diagnostics while it can actually send messages, run ongoing monitoring logic, and create durable artifacts, which materially changes the trust and approval model.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
- `node scripts/inspector.js register ...`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- `scripts/watch-registered-sessions.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
- `scripts/watch-registered-sessions.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- `scripts/common.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
- `scripts/common.js`

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt authorizes the inspector to continue or resume the original task during the inspection turn instead of limiting it to status diagnosis. This creates privilege and scope expansion: a monitoring/recovery skill can become a general executor of prior instructions, potentially performing unintended file changes, network actions, or other sensitive operations without a fresh user request. Given the skill metadata says it should be used for monitoring, registration, and diagnosis, this mismatch makes the behavior especially risky.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to use environment/runtime metadata and perform operations that can affect external systems, but it declares no explicit tool scope or allowed-tools boundary. That increases the risk of overbroad execution, unintended data access, and misuse of session/account metadata because the agent is not constrained by least-privilege declarations in the skill interface.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill prepares platform-specific persistent service mechanisms such as systemd, launchd plists, and Task Scheduler helpers, which enables the watcher to survive beyond the current session. Persistence is security-relevant even if intended for reliability, because a long-running monitor with access to session identifiers, reply routing, and local state can continue operating, sending notifications, or exposing sensitive artifacts without ongoing user awareness.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
This creates runtime files and prepares the watcher for the current platform:
- Linux with `systemd` → user unit file
- macOS → `launchd` plist
- Windows → Task Scheduler helper files
- other environments → manual run instructions

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The prompt explicitly instructs the agent to cross-check task state by running host-level commands such as ps, pgrep, grep, tail, cat, journalctl, git diff, and build/test commands. That goes beyond passive session inspection and grants broad operational latitude on the host, increasing the chance of unauthorized access to sensitive logs, process data, repository contents, and side effects from diagnostic commands. In a recovery/inspection skill, this is more dangerous because the skill is supposed to diagnose session state, yet it authorizes general host interrogation tied to arbitrary prior tasks.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/common.js:102

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/inspector.js:286

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/watch-registered-sessions.js:298