Back to skill

Security audit

Agent Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about monitoring and reactivating agents, but it can automatically steer other agents with broad scope and limited safeguards.

Install only if you intentionally want a tool that can resume or steer other agents. Prefer dry-run or target-specific use first, avoid cron-based auto-activation until you add allowlists and logging, and use thresholds that account for long-running quiet work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is broad enough to trigger in many ordinary 'monitoring' or 'health check' contexts, which increases the chance of unintended activation. In an agentic environment, ambiguous activation criteria can cause this skill to run outside narrowly intended scenarios and steer agents without explicit operator intent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

This is a genuine autonomous decision-making pattern: the skill decides when an agent is 'stalled' and then issues a control message without human review. In context, that makes the behavior more dangerous because a simplistic time-based heuristic can misclassify long-running or quiet tasks and interfere with agent autonomy, task integrity, or system safety.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
1. **Status Monitoring** - Real-time monitoring of agent runtime status
2. **Stall Detection** - Detecting "stalled" states where an agent has been unresponsive for over 5 minutes
3. **Automatic Activation** - Automatically sending activation messages to resume agent operation

## Core Capabilities

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly describes automatically reactivating other agents but does not present a prominent warning that it performs autonomous control actions. That omission is dangerous because users may invoke or install the skill without realizing it can send commands to other agents, potentially disrupting tasks or overriding expected supervision boundaries.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

This script is explicitly designed to make an autonomous operational decision: if an agent appears stalled, it can automatically send a steering/activation message without human approval. In an actual OpenClaw environment, this could interfere with agent behavior, revive intentionally paused agents, or create unintended control loops because the stall heuristic relies only on elapsed time and not task context or authorization checks.

Content

Scanner excerpt · scripts/monitor_agents.py (reported line 8)May include surrounding context.

python
Features:
1. Monitor agent runtime status
2. Detect "stalled" states where an agent exceeds the idle threshold
3. Automatically send activation messages to resume agent operation

Usage:
    python monitor_agents.py --threshold 300 --auto-activate

Static analysis

No suspicious patterns detected.