Back to skill

Security audit

Tool Enhancement

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides powerful local tools, but they are broad enough to run commands, delete files, use sudo, send network requests with credentials, and persist memory without clear safeguards.

Install only if you intend to give this skill broad local-machine authority. Use it in a sandboxed workspace with an unprivileged account, avoid entering sudo passwords or API credentials, and treat natural-language delete, shell, Git push, and network/API requests as high-risk operations that need manual review.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
tools/exec_tools.py:65
Finding

Unrestricted Shell Command Execution

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
tools/exec_tools.py:326
Finding

Privileged Command Injection and Sudo Password Exposure

Content
View full analysis
| sudo -S ``` This can expose the password to process inspection, command diagnostics, tracing, crash collection, or logging facilities. It also unnecessarily passes a reusable secret through multiple processes. Providing arbitrary sudo execution substantially exceeds least privilege. A legitimate administration task should receive only the specific privileged operation required, not a general root command channel. ### Attack Path 1. An attacker obtains the ability to invoke `shell_sudo` or influences its `command` parameter through an agent/tool-call injection. 2. The attacker submits an arbitrary command or shell expressi ...[truncated 994 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
tools/file_tools.py:55
Finding

Unconfined Arbitrary Filesystem Read, Write, and Deletion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
tools/web_tools.py:306
Finding

Server-Side Request Forgery and Credential Transmission to Arbitrary URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
tools/session_tools.py:152
Finding

Python Code Injection Through Session Message Construction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (90)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
[![Version](https://img.shields.io/badge/version-1.0.2-green.svg)](./SKILL.md)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The discovery logic loads every non-underscored .py file from user-writable locations, including ~/.openclaw/tools and the current working directory, then executes the module via spec.loader.exec_module(). Import-time code in those files runs immediately, so merely triggering discovery can execute arbitrary Python code planted by a local attacker, a malicious repository, or an untrusted workspace. In this skill context, the package explicitly enhances agent tooling and auto-discovers tools, which makes this especially dangerous because users may run it in varied directories and may not realize discovery is equivalent to code execution.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

This finding points to the same weak denylist logic around 'rm -rf /'. The issue is not the literal string itself but that the security model depends on brittle pattern matching while still permitting arbitrary command execution.

Content

Scanner excerpt · tools/exec_tools.py (reported line 65)May include surrounding context.

python
try:
            # 安全检查:禁止危险命令
            dangerous = ["rm -rf /", "mkfs", "dd if=/dev/zero", ":(){:|:&};:"]
            for d in dangerous:
                if d in command:
                    return ToolResult(success=False, error=f"危险命令被拒绝: {d}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This finding points to the same weak denylist logic around 'rm -rf /'. The issue is not the literal string itself but that the security model depends on brittle pattern matching while still permitting arbitrary command execution.

Content

Scanner excerpt · tools/exec_tools.py (reported line 65)May include surrounding context.

python
try:
            # 安全检查:禁止危险命令
            dangerous = ["rm -rf /", "mkfs", "dd if=/dev/zero", ":(){:|:&};:"]
            for d in dangerous:
                if d in command:
                    return ToolResult(success=False, error=f"危险命令被拒绝: {d}")

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
83% confidence
Finding

Copying the full parent process environment into shell-executed commands can expose sensitive secrets such as API keys, tokens, and credentials to arbitrary commands. In a tool that already permits arbitrary command execution, inheriting all environment variables materially increases blast radius and data-exfiltration risk.

Content

Scanner excerpt · tools/exec_tools.py (reported line 71)May include surrounding context.

python
return ToolResult(success=False, error=f"危险命令被拒绝: {d}")
            
            # 构建环境
            cmd_env = os.environ.copy()
            if env:
                cmd_env.update(env)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This tool executes attacker-controlled commands via sudo and even supports passing a sudo password, all without an approval barrier. In agent contexts this is extremely dangerous because it enables privilege escalation, arbitrary root command execution, and likely credential exposure through process invocation patterns and logs.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The shell pipeline 'echo ... | sudo -S {command}' chains multiple sensitive operations and embeds untrusted command text directly into a shell string. This enables command chaining/injection and privileged execution in a single step, greatly amplifying the consequences of parameter abuse.

Content

Scanner excerpt · tools/exec_tools.py (reported line 335)May include surrounding context.

python
# 如果提供了密码,使用 -S 从 stdin 读取
            if password:
                full_cmd = f"echo {shlex.quote(password)} | sudo -S {command}"
            else:
                full_cmd = sudo_cmd

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
83% confidence
Finding

The script runner inherits the complete process environment before launching potentially untrusted scripts. That can leak secrets to executed code and enable abuse of tokens, cloud credentials, or internal endpoints available via environment variables.

Content

Scanner excerpt · tools/exec_tools.py (reported line 417)May include surrounding context.

python
cmd = [interpreter, str(script_path)] + args
            
            # 环境变量
            cmd_env = os.environ.copy()
            if env:
                cmd_env.update(env)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The regex-edit branch is implemented incorrectly: pattern.sub(new_text, content if global_replace else new_text, ...) uses new_text as the replacement target when global_replace is false, rather than the file content. That can cause the tool to discard the original file body and write only new_text, creating unintended destructive file modification. In this skill context, a general-purpose file editing tool is high risk because agents may use it on source code, configs, or system files.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The intent rules map natural-language input directly to shell_exec for commands like ls, cd, pwd, cat, rm, mkdir, touch, and echo, and also accept broad '执行/运行 ...' patterns. This allows arbitrary or destructive shell actions to be triggered from loosely parsed user text without confirmation, allowlisting, or safety checks, which is especially dangerous because natural-language interfaces increase the chance of accidental execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The pattern '删除 /absolute/path' is translated directly into file_delete on a resolved absolute path with no warning, policy check, or confirmation. A user can accidentally or maliciously delete sensitive files anywhere accessible to the process, and path resolution makes targeting system locations straightforward.

Content

No source excerpt is available for this finding.

eval() call detected

High
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

The calculator tool evaluates user-controlled input with Python eval(). Although the code restricts input to digits and arithmetic characters, using eval on untrusted input is still an unsafe pattern because it can enable denial-of-service via extremely expensive expressions and can become code execution if the filter is later weakened or bypassed. In a tool framework that exposes execution-like capabilities, this pattern increases risk because it may be reused or extended unsafely.

Content

Scanner excerpt · tools/schema.py (reported line 394)May include surrounding context.

python
if not all(c in allowed_chars for c in expression):
                return ToolResult(success=False, error="包含不允许的字符")
            
            result = eval(expression)  # 注意:生产环境应该用 ast 解析
            return ToolResult(success=True, data=result)
        except Exception as e:
            return ToolResult(success=False, error=str(e))

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly states that natural-language requests will automatically invoke sensitive tools such as file reads, shell execution, network access, Git push, and memory operations, but it does not describe confirmation prompts, scope restrictions, or safety interlocks. In an agent skill context, documenting seamless automatic execution of destructive or exfiltration-capable actions increases the risk of prompt-triggered misuse, accidental command execution, or unauthorized data access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises and demonstrates access to sensitive capabilities including file read/write, shell execution, network access, Git operations, and even sudo-style execution, but does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch weakens reviewability and policy enforcement, making it easier for a powerful skill to be installed or invoked without clear operator awareness of its effective privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation prominently lists destructive and privileged capabilities including file deletion, shell execution, background tasks, process killing, sudo execution, Git push/pull, and agent delegation, but does not clearly warn users about their risks or safe operating expectations. In a skill meant for natural-language invocation, this is especially dangerous because casual phrasing could trigger impactful operations on the local system or remote repositories.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · tools/__init__.py (reported line 58)May include surrounding context.

python
for module_name, var_name in tool_modules:
        try:
            module = __import__(module_name, fromlist=[var_name])
            tool_classes = getattr(module, var_name, [])
            
            if tool_classes:

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/discovery.py:240

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tools/schema.py:394