Back to skill

Security audit

Openclaw

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Skytale MCP integration for encrypted agent messaging, with the main caution that it installs an unpinned external Python SDK.

Install only if you trust the Skytale SDK and service, and prefer pinning a reviewed skytale-sdk version in an isolated Python environment. Keep SKYTALE_API_KEY out of messages and logs, and review the MCP configuration before enabling it for agents that handle sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
setup.sh:20
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: setup.sh:20
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

bash
$PYTHON -m pip install "skytale-sdk[mcp]"

The same unsafe installation command is also documented in SKILL.md:35:

markdown
1. Install: `pip install skytale-sdk[mcp]`

Technical Analysis

The setup script installs skytale-sdk[mcp] without an exact version constraint, dependency lockfile, or package hashes. Consequently, installation resolves the latest compatible package and its transitive dependencies from the user's configured Python package index.

Although the skill metadata and documentation refer to version 0.5.1 or later, the installation command does not enforce an audited release. Package installation may also execute package build hooks. This creates a supply-chain risk because the code installed and run can change after this skill has been reviewed.

Attack Path

  1. An attacker compromises the skytale-sdk distribution, one of its transitive dependencies, its publisher account, or a package index used by the victim.
  2. The attacker publishes a malicious release or otherwise causes dependency resolution to select attacker-controlled content.
  3. A user runs setup.sh or follows the installation command in SKILL.md.
  4. pip retrieves and installs the mutable package set; malicious build or installation logic may execute immediately.
  5. The installed package is subsequently launched as an MCP server through python -m skytale_sdk.integrations._mcp.
  6. The compromised process inherits the configured SKYTALE_API_KEY and can act with the operating-system privileges of the user running it.

Impact Assessment

Successful exploitation could result in arbitrary code execution with the installing user's privileges. The affected scope includes files, credentials, environment variables, and network resources accessibl ...[truncated 420 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the SDK to a specifically reviewed version, such as skytale-sdk[mcp]==0.5.1, after verifying that version is appropriate.
  • Generate and distribute a lockfile containing exact versions for all transitive dependencies.
  • Record cryptographic hashes for every required distribution and install with pip --require-hashes.
  • Prefer prebuilt, verified wheels to reduce exposure to arbitrary source-build hooks.
  • Explicitly document and constrain the trusted package index rather than relying on ambient pip configuration.
  • Verify package publisher provenance and monitor pinned dependencies for security advisories.
  • Update both setup.sh and SKILL.md so the documented installation procedure applies the same integrity controls.
  • Run installation and the MCP server under a dedicated, least-privileged account or isolated environment, exposing only the credentials and resources required for operation.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents the skill as a trust/security layer implementing substantial security and federation capabilities. However, the supplied code chunk is only an installer/setup script. Its actual function is limited to checking for Python, installing the skytale-sdk[mcp] package, and printing setup instructions. While installation is a supporting detail, this chunk does not itself implement or expose the described trust-layer behaviors. Therefore, the description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.