Back to skill

Security audit

OpenClaw Model Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent cost-routing purpose, but its optional execution mode gives spawned agents broad file-writing authority and stores full task text locally without clear disclosure.

Install only if you specifically want model routing plus optional multi-agent execution. Avoid --execute on sensitive tasks or in important workspaces unless you are comfortable with spawned agents writing files, retained session state, and local storage of task text/errors. Review and periodically delete ~/.openclaw/workspace/swarm_memory.json and swarm_insights.json, and treat smart_find.py as a broad local file-content disclosure utility.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
manage_models.py:202
Finding

Persistent Plaintext Retention of Sensitive Task Content and Error Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
manage_models.py:118
Finding

Untrusted Task Text Is Delegated to File-Writing Agents Without Workspace Isolation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
smart_find.py:13
Finding

Undocumented Recursive File Finder Can Disclose Arbitrary Readable File Content

Content
View full analysis
0.2 if score > 0.2: matches.append((full_path, score)) except Exception as e: print(f"Error while searching: {str(e)}", file=sys.stderr) return [] matches.sort(key=lambda x: (-x[1], len(x[0]))) return matches ``` ```python def read_file_content(file_path): """Read and return file content safely.""" try: with open(file_path, 'r', encoding='utf-8') as f: return f.read() except UnicodeDecodeError: return "[ERROR] File appears to be binary or uses an unsupported encoding." except Exception as e: return f" ...[truncated 2207 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises plan ... --execute and describes spawning sub-agents, but it does not clearly warn that this mode will automatically launch multiple agents and may perform actions beyond passive planning. In an agentic tooling context, insufficient disclosure can lead users to trigger autonomous execution unintentionally, increasing the risk of unwanted commands, resource usage, or changes in the local environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill explicitly states it modifies the persistent user configuration file at ~/.openclaw/openclaw.json. Persistent configuration changes are security-relevant because they can outlive the current run, silently alter future model routing behavior, and potentially weaken trust boundaries or redirect later activity if the config is changed unsafely or without strong user consent.

Content

Scanner excerpt · SECURITY.md (reported line 9)May include surrounding context.

md
This skill performs the following operations to enable dynamic model routing:

1.  **Read/Write Configuration**: Modifies `~/.openclaw/openclaw.json` to update model fallbacks and enable new models dynamically. This is the core functionality.
2.  **Network Access**: Connects to `https://openrouter.ai/api/v1/models` (HTTPS only) to fetch current pricing and model lists. No user data is sent.
3.  **Process Execution**: Spawns sub-processes via `openclaw sessions spawn` to orchestrate multi-agent workflows (Planner/Executor/Reviewer).

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

Custom Routing Rules

python
# Create custom routing in ~/.openclaw/model-routing.json
{
  "patterns": {
    "translation": ["gemini-2.0-flash", "gpt-4o-mini"],

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · manage_models.py (reported line 45)May include surrounding context.

python
"""
    try:
        # Explicitly use shell=False for security (default, but explicit is better)
        result = subprocess.run(
            cmd_list, 
            capture_output=True, 
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · manage_models.py (reported line 475)May include surrounding context.

python
try:
        # Try to call model-benchmarks skill
        cmd = ["python3", "skills/model-benchmarks/scripts/run.py", "recommend", "--task", task_type, "--format", "json"]
        result = subprocess.run(cmd, capture_output=True, text=True, cwd=os.path.expanduser("~/.openclaw/workspace"))
        
        if result.returncode == 0:
            data = json.loads(result.stdout)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically prints the full contents of the highest-scoring matched file based solely on a fuzzy query. In a local workspace, this can unintentionally expose secrets, credentials, private documents, or other sensitive data if the match is unexpected or manipulated by naming, especially because there is no confirmation, preview-only mode, or path restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The document switches into a Chinese-language section beginning at L11, but it does not state whether language selection is optional or user-driven. This can create a natural-language policy issue if the skill assumes or prioritizes a specific language without explicit opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L74 states that the skill tracks success rates in swarm_memory.json, which means it persists operational data to disk. The README explains the feature but does not warn users that local state will be written and retained, which is relevant to user data and system integrity expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This README states that the skill fetches current OpenRouter pricing and integrates with benchmark data sources, which implies outbound network requests. The markdown does not warn users that using these commands may contact external services and transmit task or system-related data, which is the kind of disclosure SQP-2 expects for markdown skill descriptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The docstring says the function will 'Generate OpenClaw config patch to enable a model,' which suggests activation behavior, while the module-level documentation states the script modifies the local OpenClaw configuration file. In reality, this function reads config state and emits a patch to stdout without writing the configuration file itself, creating a documentation-to-code mismatch about the actual side effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.