Back to skill

Security audit

openclaw-pc-security

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed OpenClaw/Windows security self-check tool with optional authorized scanning, but users should treat its reports and test server carefully.

Install only if you want a local OpenClaw/Windows security audit tool. Run network scans and credential/leak checks only against systems you own or are explicitly allowed to test, keep generated output reports private, be aware that npm/MSRC lookup flags make external requests, and do not run the included mock server outside an isolated test environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/mock_server.py:8
Finding

Intentionally Vulnerable Mock Server Listens on All Network Interfaces

Content
View full analysis

Vulnerability Details

File Location: scripts/mock_server.py:8-13, 31-43, 54-58
Vulnerability Type: Externally reachable test service with predictable credentials and a fixed token
Risk Level: Medium

Complete Code Snippet

python
# Allow port to be configurable via command line
PORT = 18789
if len(sys.argv) > 1:
    try:
        PORT = int(sys.argv[1])
    except ValueError:
        pass

def do_POST(self):
    if self.path == '/login':
        content_length = int(self.headers['Content-Length'])
        post_data = self.rfile.read(content_length)
        try:
            data = json.loads(post_data.decode())
            # Default credentials simulation
            if data.get('username') == 'admin' and data.get('password') == 'openclaw':
                self.send_response(200)
                self.send_header('Content-type', 'application/json')
                self.end_headers()
                self.wfile.write(b'{"token": "secret_token_123"}')
            else:
                self.send_response(401)
                self.end_headers()
                self.wfile.write(b'{"error": "Invalid credentials"}')
        except:
            self.send_response(400)
            self.end_headers()

if __name__ == "__main__":
    # Allow address reuse
    socketserver.TCPServer.allow_reuse_address = True
    with socketserver.TCPServer(("", PORT), OpenClawHandler) as httpd:
        print(f"Mock OpenClaw server running on port {PORT}")
        try:
            httpd.serve_forever()

Technical Analysis

Passing an empty host string to socketserver.TCPServer binds the mock server to all available network interfaces rather than restricting it to the loopback interface. The server intentionally recognizes the predictable admin / openclaw credential pair and returns the fixed token secret_token_123.

This behavior is test infrastructure and is not invoked by ...[truncated 1728 chars]

Remediation
View remediation

Remediation Suggestions

  1. Bind the mock server to the loopback interface:
    python
    with socketserver.TCPServer(("127.0.0.1", PORT), OpenClawHandler) as httpd:
    
  2. Require an explicit test-only confirmation flag before starting the server.
  3. Print a prominent warning if a non-loopback bind address is requested.
  4. Avoid fixed token-like values. Generate an ephemeral value at startup or use an unmistakable placeholder that cannot be confused with a real credential.
  5. Move the server into a dedicated tests/ directory and document that it must not be used in production.
  6. Consider rejecting remote clients even when a caller accidentally changes the bind address.
  7. Validate that the selected port is within 1-65535 and fail closed on invalid input rather than silently retaining the default.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Runtime Dependency Is Not Pinned or Integrity-Verified

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1, requirements-audit.txt:1, requirements-scan.txt:1; installation instruction at README.md:50
Vulnerability Type: Non-reproducible dependency resolution without package hashes
Risk Level: Low

Complete Code Snippet

The three requirements files contain the same unbounded dependency declaration:

text
requests>=2.28

The README instructs users to install it directly:

bash
pip install -r requirements.txt

Technical Analysis

The lower-bound-only constraint permits pip to install any current or future release of requests. No lock file, upper bound, or package hash is provided. Consequently, two installations performed at different times can resolve to different package versions and dependency trees.

This is a supply-chain hardening weakness rather than evidence that the current dependency is malicious. If a future package release or one of its transitive dependencies is compromised, replaced, or unexpectedly incompatible, the installation process can retrieve that version without an integrity policy tied to an audited artifact.

The issue affects all declared dependency sets:

  • requirements.txt
  • requirements-audit.txt
  • requirements-scan.txt

Attack Path

  1. A user follows the documented installation command.
  2. pip resolves requests>=2.28 and its transitive dependencies from the configured package index.
  3. Because there is no exact version or approved hash, pip accepts any release satisfying the lower bound.
  4. If a resolved future artifact or transitive dependency has been compromised, the malicious or unsafe package is installed.
  5. The Skill imports requests from scripts/analyzer.py, scripts/scanner.py, and scripts/msrc.py.
  6. Package code therefore executes under the account running the Skill when the affected module is imported or used.

This exploitation path depends on compromise ...[truncated 760 chars]

Remediation
View remediation

Remediation Suggestions

  1. Generate a reviewed lock file containing exact direct and transitive versions.
  2. Add cryptographic hashes and install with hash verification:
    bash
    pip install --require-hashes -r requirements.lock
    
  3. Use a dependency-management workflow such as pip-tools to maintain reproducible lock files.
  4. Keep the abstract dependency constraint separate from the deployment lock file if broad compatibility is required.
  5. Apply an upper bound where appropriate and test upgrades before updating the lock file.
  6. Run automated dependency vulnerability scanning in continuous integration.
  7. Install from the official package index or an authenticated internal mirror.
  8. Apply the same locked and hashed policy to the audit and scan dependency sets.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

HTTP/HTTPS fingerprinting of arbitrary targets without clear implementation of the advertised local report features indicates the manifest is not trustworthy. The security context makes this more dangerous because users may assume defensive self-audit while actually performing active reconnaissance.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
python scripts/run_scan.py <target-ip> --ports 18789,18790,18792 --out-dir output

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
python scripts/run_scan.py <target-ip> --ports 18789,18790,18792 --out-dir output

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

text

## Notes
- The server configuration checks are performed locally and do not send data to external services.
- The HTML report supports CN/EN toggle and Simple/Detailed mode.
- Active network checks must ONLY be used on systems you own or have explicit authorization to test.
- **DO NOT** upload tokens, credentials, or reports (output/) to public repositories.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as a local self-check producing a local report, but this function queries the public npm registry using 'npm view'. That creates external network egress, leaks that npm and the package name were queried from the host, and violates the user's reasonable expectation that the audit is fully local.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code introduces unnecessary capability to contact the public npm registry from a security-checking tool. Even if the current query is limited, the capability expands the trust boundary, can expose metadata about installed tooling or user behavior, and is inconsistent with the stated local-only function of the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a local Windows/OpenClaw security self-check focused on password protection, port, and exposure, producing a local report. This file instead implements remote retrieval of Microsoft Security Response Center CVRF and SUG vulnerability data over HTTPS, which is a materially different capability than a local configuration/exposure audit.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares broad operational behavior involving shell, file I/O, environment access, and network activity, but does not declare any explicit tool scope or permissions boundaries in the manifest. That makes review and enforcement harder and increases the risk that a caller or agent will execute higher-risk capabilities than expected.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

text

## Notes
- The server configuration checks are performed locally and do not send data to external services.
- The HTML report supports CN/EN toggle and Simple/Detailed mode.
- Active network checks must ONLY be used on systems you own or have explicit authorization to test.
- **DO NOT** upload tokens, credentials, or reports (output/) to public repositories.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON file is a manifest-like evals file, so vague-trigger review applies. Inputs such as "Check my Windows security posture and see if I need any updates" and "Detect if my OpenClaw version is outdated and check for any security risks" are broad natural-language requests that overlap with ordinary user speech and do not define clear invocation boundaries or exclusions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Several eval inputs are written in Chinese while earlier inputs are in English, but the file provides no indication that the user can choose language or that the skill is intentionally locale-specific. This can violate language/locale policy by implicitly forcing or assuming a language without opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code performs active authentication attempts against the target service using a hardcoded default credential pair rather than limiting itself to passive inspection. Even though the stated purpose is a local security self-check, this behavior crosses into active security testing and can have side effects such as account lockouts, unintended access attempts, noisy logs, or policy violations if pointed at anything beyond the user's own instance.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/audit.py (reported line 68)May include surrounding context.

python
if shell and sys.platform == "win32":
            cmd = ["powershell", "-Command", cmd] if isinstance(cmd, str) else cmd
            
        result = subprocess.run(
            cmd, 
            capture_output=True, 
            text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The audit messages explicitly embed Chinese and English text in the output rather than offering a user-selectable language or locale. This is a natural-language policy issue because the skill forces a specific multilingual presentation without documented user choice or clear region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

These user-facing detail strings hardcode Chinese and English text together, which enforces a language/locale presentation choice in the skill output. The file does not show any opt-in, locale negotiation, or documented justification for this fixed bilingual behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file implements an HTTP server with status and login endpoints, including simulated default credentials and a token response, which is unnecessary for a self-check skill. In the skill context, adding server functionality is more dangerous because it contradicts the stated purpose and could expose a reachable service that normal users would not expect, increasing the chance of misuse, probing, or accidental deployment as an insecure listener.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification, suspicious.install_untrusted_source

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/scanner.py:99

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
output/scan_report.json:12