Back to skill

Security audit

Paw Chat

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Paw web chat frontend, but it needs Review because it handles a powerful Gateway token in unsafe ways while exposing agent editing and scheduled-task controls.

Install only in a trusted local or HTTPS-served environment, prefer wss:// for any non-local Gateway, do not paste the Gateway token into an untrusted or remote Paw page, and rotate the token if it may have been exposed. Treat the Paw UI as an admin surface: anyone who gets the token or executes script in this page may be able to read chats, change agent behavior, and manage scheduled tasks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
assets/paw-app.js:191
Finding

Stored Cross-Site Scripting Can Expose the OpenClaw Gateway Token

Content
View full analysis
`; }; renderer.link = function(token) { const href = token.href || ''; const text = token.text || href; return `${text}`; }; marked.setOptions({ renderer }); function renderMarkdown(text) { try { if (typeof marked !== 'undefined') { return marked.parse(text); } return escHtml(text).replace(/\n/g, '
'); } catch (e) { console.warn('[renderMarkdown error]', e); return escHtml(text).replace(/\n/g, '
'); } } ``` ```javascript if (role === 'assistant' || role === 'system') el.innerHTML = renderMarkdown(text); ``` ```javascript if (textStr) { const d = document.createElement('div'); d.innerHTML = renderMarkdown(textStr); wrapper.appendChild(d); } ``` ### Technical Analysis Assistant and system messages originate from a remote Gateway or agent and must be treated as untrusted content. The application passes this content to `marked.parse()` and assigns the resulting HTML directly to `innerHTML` without applying an HTML sanitizer. Raw HTML accepted by the Markdown parser can therefore introduce executable elements or event-handler attributes. The custom link and image renderers also interpolate `href` values d ...[truncated 1774 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/paw-app.js:385
Finding

Gateway Authentication Token Can Be Transmitted over an Unencrypted WebSocket

Content
View full analysis
{ ``` ### Technical Analysis The application accepts arbitrary user-supplied WebSocket URLs and does not require the secure `wss://` scheme. It also defaults to `ws://` for local operation and derives a plaintext WebSocket URL whenever Paw itself is served over HTTP. After receiving the Gateway challenge, Paw sends the bearer token inside a WebSocket request. When the connection uses `ws://`, neither the authentication token nor subsequent chat and control traffic is protected by TLS. Although plaintext loopback traffic has a narrower risk profile, the implementation does not enforce that `ws://` is limited to `127.0.0.1`, `::1`, or `localhost`. A user can therefore configure a remote plaintext endpoint. ### Attack Path 1. A user serves Paw over HTTP or manually enters a remote `ws://` Gateway URL. 2. Paw ...[truncated 1000 chars]
Remediation
View remediation

other

Note
Location
assets/paw-app.js:139
Finding

Remote Markdown Images Automatically Disclose Viewer Network Metadata

Content
View full analysis
`; }; ``` ### Technical Analysis Markdown image URLs in assistant content are converted into image elements. Despite the `lazy-img` name, `activateLazyImages()` immediately assigns the attacker-controlled URL to the image's `src` attribute after rendering. This causes the browser to contact arbitrary third-party servers without requiring the user to approve or click the image. The destination can observe the viewer's source IP address, request time, browser request headers, and repeated views. Unique image URLs can be used as per-message tracking pixels. This behavior supports the declared image-rendering feature, but automatic loading is not the minimum-privilege implementation because external requests can be deferred until explicit user consent. ### Attack Path 1. An attacker causes an agent or Gateway to return Markdown containing an image hosted on an attacker-controlled server. 2. Paw renders the assistant message. 3. `activateLazyImages()` copies the URL into the image's `src`. 4. The browser automatically requests the resource. 5. The attacker correlates the unique URL with the victim and records the victim's network metadata and viewing time. ### Impact Assessment The issue ...[truncated 447 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual skill provides far broader operational capabilities than the description suggests—such as direct Gateway interaction, session management, agent file editing, and cron control—users may grant trust or permissions based on an incomplete description. That creates a security transparency problem and can lead to unintended modification of agents, files, or scheduled tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual skill provides far broader operational capabilities than the description suggests—such as direct Gateway interaction, session management, agent file editing, and cron control—users may grant trust or permissions based on an incomplete description. That creates a security transparency problem and can lead to unintended modification of agents, files, or scheduled tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual skill provides far broader operational capabilities than the description suggests—such as direct Gateway interaction, session management, agent file editing, and cron control—users may grant trust or permissions based on an incomplete description. That creates a security transparency problem and can lead to unintended modification of agents, files, or scheduled tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the actual skill provides far broader operational capabilities than the description suggests—such as direct Gateway interaction, session management, agent file editing, and cron control—users may grant trust or permissions based on an incomplete description. That creates a security transparency problem and can lead to unintended modification of agents, files, or scheduled tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the actual skill provides far broader operational capabilities than the description suggests—such as direct Gateway interaction, session management, agent file editing, and cron control—users may grant trust or permissions based on an incomplete description. That creates a security transparency problem and can lead to unintended modification of agents, files, or scheduled tasks.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
cp assets/paw-app.js assets/marked.min.js assets/highlight.min.js assets/github-dark.min.css assets/logo.jpg /var/www/html/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
cp assets/paw-app.js assets/marked.min.js assets/highlight.min.js assets/github-dark.min.css assets/logo.jpg /var/www/html/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
cp assets/paw-app.js assets/marked.min.js assets/highlight.min.js assets/github-dark.min.css assets/logo.jpg /var/www/html/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

删除 Gateway 目录中的文件:

bash
rm -f ~/.openclaw/control-ui-static/chat.html
rm -f ~/.openclaw/control-ui-static/paw-app.js
rm -f ~/.openclaw/control-ui-static/marked.min.js
rm -f ~/.openclaw/control-ui-static/highlight.min.js

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

bash
rm -f ~/.openclaw/control-ui-static/chat.html
rm -f ~/.openclaw/control-ui-static/paw-app.js
rm -f ~/.openclaw/control-ui-static/marked.min.js
rm -f ~/.openclaw/control-ui-static/highlight.min.js
rm -f ~/.openclaw/control-ui-static/github-dark.min.css

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

bash
rm -f ~/.openclaw/control-ui-static/chat.html
rm -f ~/.openclaw/control-ui-static/paw-app.js
rm -f ~/.openclaw/control-ui-static/marked.min.js
rm -f ~/.openclaw/control-ui-static/highlight.min.js
rm -f ~/.openclaw/control-ui-static/github-dark.min.css
rm -f ~/.openclaw/control-ui-static/logo.jpg

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

rm -f ~/.openclaw/control-ui-static/chat.html rm -f ~/.openclaw/control-ui-static/paw-app.js rm -f ~/.openclaw/control-ui-static/marked.min.js rm -f ~/.openclaw/control-ui-static/highlight.min.js rm -f ~/.openclaw/control-ui-static/github-dark.min.css rm -f ~/.openclaw/control-ui-static/logo.jpg

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

rm -f ~/.openclaw/control-ui-static/paw-app.js rm -f ~/.openclaw/control-ui-static/marked.min.js rm -f ~/.openclaw/control-ui-static/highlight.min.js rm -f ~/.openclaw/control-ui-static/github-dark.min.css rm -f ~/.openclaw/control-ui-static/logo.jpg

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

rm -f ~/.openclaw/control-ui-static/marked.min.js rm -f ~/.openclaw/control-ui-static/highlight.min.js rm -f ~/.openclaw/control-ui-static/github-dark.min.css rm -f ~/.openclaw/control-ui-static/logo.jpg

text

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 547)May include surrounding context.

html
</head>
<body>
<div id="app">
  <!-- Main chat area -->
  <div id="main">
  <div id="header-wrap">
  <div id="header">

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · assets/paw-app.js (reported line 1415)May include surrounding context.

js
saveConfig();
    newSessionDialog.classList.remove('show');
    closeSessionDropdown();
    // Reset state
    streamingEl = null;
    streamBuf = '';
    resetTurnState();

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file goes well beyond a chat frontend and exposes agent file editing plus cron-job administration over the same web UI. That materially expands the attack surface: any XSS, token theft, or unauthorized UI access now grants persistent modification of agent behavior and scheduled autonomous actions, not just chat access.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · assets/paw-app.js (reported line 1751)May include surrounding context.

js
result.pronouns = kv.pronouns || '';
    result.timezone = kv.timezone || '';
    result.notes = kv.notes || '';
    // Extract Context section
    const ctxMatch = content.match(/##\s*Context\s*\n([\s\S]*?)(?=\n##|\n---|\s*$)/i);
    if (ctxMatch) {
      result.context = ctxMatch[1].replace(/^_.*_\s*\n?/gm, '').replace(/^\s*\n/, '').trim();

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The UI provides broad remote administrative RPCs such as agents.files.set, cron.add, cron.update, cron.run, and cron.remove, which exceed the stated purpose of installing/managing a web chat frontend. In context, that means the skill can remotely alter agent identity/persona files and create or trigger scheduled tasks, enabling persistence, misuse, or policy bypass if the UI or stored token is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx @openclaw/paw without pinning a specific version. This makes executions non-reproducible and allows a compromised or newly published package version to be fetched and run at invocation time, which is a meaningful supply-chain risk for an install/setup skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly tells users how to retrieve the OpenClaw Gateway authentication token and paste it into the web UI, but does not clearly warn that this token is a sensitive credential that must not be shared, logged, screenshotted, or exposed to untrusted hosts. In the context of a web chat frontend connecting to a gateway, mishandling this token could enable unauthorized access to the user's gateway and associated capabilities.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs users to run shell commands and use network-connected functionality, but it declares no explicit tool scope or permissions boundaries. In an agent setting, missing scope increases the chance that the skill will be invoked with broader-than-necessary capabilities and without clear review of shell/network use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The substantive skill instructions are written in Chinese, which imposes a specific language on users without opt-in or an alternative locale option. This can violate language or locale policy when the skill does not document that it is region-specific or provide a language choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell the user to retrieve an authentication token from a config file and enter it into the web frontend without any credential-handling warning, scoping guidance, or recommendation to protect the token. Exposing long-lived gateway credentials in documentation raises the risk of accidental disclosure, reuse in insecure environments, or phishing via lookalike frontends.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.