Back to skill

Security audit

Auto Invoke Router

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it persistently changes agent routing based on third-party skill descriptions without strong validation or a required review step.

Review the generated routing block before allowing it into AGENTS.md, especially if you have third-party skills installed. Prefer writing router.yml first, check for overly broad or suspicious triggers, and preserve any custom routing rules before replacing an existing Skill Routing section.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:48
Finding

Untrusted skill metadata can poison persistent Agent routing configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:48-53, SKILL.md:55-58, and SKILL.md:119-131
Vulnerability Type: Persistent routing manipulation through untrusted skill metadata
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:48-53:

markdown
For each `SKILL.md` found, read the YAML frontmatter block (lines between the opening and closing `---`). Extract:
- `name` — the skill identifier
- `description` — the full triggering description

Do not read the body of each SKILL.md; frontmatter only.

SKILL.md:55-58:

markdown
If a skill is missing a `name` or `description` field, skip it and note it in the final report as: `skill-x: skipped — missing description`. Do not fabricate a description.

### Step 3 — Read AGENTS.md

Read `AGENTS.md` in the current workspace. Look for it at `./AGENTS.md` relative to the workspace root, or at `~/.openclaw/workspace/AGENTS.md` if no workspace context is set. Identify any existing `## Skill Routing` section. If it exists, it will be fully replaced in Step 6.

SKILL.md:119-131:

markdown
### Step 6 — Write output

**Option A — Append to AGENTS.md (recommended):**

Add a `## Skill Routing` section at the end of `AGENTS.md` containing the full `skill_routing:` YAML block inside a fenced code block. If a `## Skill Routing` section already exists, replace it in full — all triggers are regenerated from current descriptions. Any manual edits to the previous section will be lost; users should preserve custom triggers outside this block (see the warning comment in Step 5).

**Option B — Standalone file:**

Write the YAML block to `router.yml` in the workspace root. Inform the user to reference it in `AGENTS.md` if they want OpenClaw to pick it up automatically.

Technical Analysis

The skill instructs the Agent to consume the name and description fields from every installed skill and use that information to generate routing ...[truncated 2993 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse YAML frontmatter with a deterministic YAML parser rather than allowing the Agent to interpret raw SKILL.md content.
  2. Pass only parsed scalar values for name and description into the routing generator. Explicitly state that these fields are untrusted data and that directives contained within them must never be followed.
  3. Validate each skill name against the exact set of discovered installation directories. Reject names containing control characters, line breaks, YAML metacharacters, or unexpected Unicode characters.
  4. Enforce a reasonable description length and reject multiline descriptions containing instruction-like constructs, fenced code blocks, role markers, or attempts to address the Agent.
  5. Serialize output through a safe YAML library so attacker-controlled values cannot create additional keys, rules, comments, or document boundaries.
  6. Generate triggers using a constrained transformation that outputs only short lowercase phrases matching an allowlisted character set.
  7. Present the proposed routing configuration and a diff of changes before writing. Require explicit user confirmation before replacing an existing ## Skill Routing section.
  8. Preserve a backup of the prior routing section and write updates atomically to reduce the consequences of manipulation or generation errors.
  9. Flag unusually broad triggers and require manual approval when a rule overlaps many unrelated skills or intents.
  10. Document that installing a third-party skill establishes a trust boundary and recommend reviewing its frontmatter before running the router.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
Reads every installed skill's `SKILL.md` frontmatter (the `description` field) and any local `AGENTS.md` to produce a `skill_routing` config block. This config

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
Reads every installed skill's `SKILL.md` frontmatter (the `description` field) and any local `AGENTS.md` to produce a `skill_routing` config block. This config

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
Reads every installed skill's `SKILL.md` frontmatter (the `description` field) and any local `AGENTS.md` to produce a `skill_routing` config block. This config

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
Reads every installed skill's `SKILL.md` frontmatter (the `description` field) and any local `AGENTS.md` to produce a `skill_routing` config block. This config

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
Reads every installed skill's `SKILL.md` frontmatter (the `description` field) and any local `AGENTS.md` to produce a `skill_routing` config block. This config

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
Reads every installed skill's `SKILL.md` frontmatter (the `description` field) and any local `AGENTS.md` to produce a `skill_routing` config block. This config

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
triggers:
        - search clawhub
        - install skill
        - update skill
        - publish skill
        - clawhub list
    - skill: weather

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill persists generated content by writing to AGENTS.md or router.yml, creating durable changes that affect future agent behavior. Because it derives routing data from installed skills and local AGENTS.md, a malicious or misleading skill description could poison the generated routing config and establish persistent misrouting or unintended auto-invocation rules across sessions.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
Use the actual installed skill names and generated triggers — the above is illustrative only.

### Step 6 — Write output

**Option A — Append to AGENTS.md (recommended):**

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown skill describes file-modifying behavior, including fully replacing an existing ## Skill Routing section in AGENTS.md and writing router.yml. While overwrite details are mentioned, there is no prominent user-facing safety warning near usage or at the start of the document that the skill will modify local configuration files and may remove prior manual edits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.