Back to skill

Security audit

Aws Cli

Security checks for vulnerabilities and agentic risk

Overview

This AWS CLI skill is purpose-aligned, but it installs an unverified executable that can automatically use AWS credentials, so users should review it before installing.

Install only if you trust the publisher and the release channel. Prefer a pinned version with published checksums or signatures, run it under a least-privileged AWS identity, and be aware that EC2/ECS metadata credentials may be used automatically inside the container.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:25
Finding

Unverified Remote Executable Retrieved from Maintainer-Controlled Releases

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/package.sh:37
Finding

Upstream AWS Installer Executed Without Cryptographic Verification

Content
View full analysis
&2 exit 1 fi echo "Download OK: $(numfmt --to=iec "$ZIP_SIZE")" echo "Extracting installer..." unzip -q "${WORK_DIR}/awscli.zip" -d "${WORK_DIR}" STAGING="${WORK_DIR}/staging" INSTALLER_DIR="${WORK_DIR}/aws" INSTALLER_DIST="${INSTALLER_DIR}/dist" if [[ "$AWS_ARCH" == "$HOST_ARCH" ]]; then echo "Native arch build, using official installer..." mkdir -p "${STAGING}/bin" "${INSTALLER_DIR}/install" \ --install-dir "${STAGING}/aws-cli" \ --bin-dir "${STAGING}/bin" \ ``` ### Technical Analysis The packaging script downloads a mutable AWS CLI archive and, for a native-architecture build, executes the extracted installer. It does not pin an upstream AWS CLI version or validate a cryptographic checksum or AWS signature. The minimum-size test only detects some truncated or obviously invalid responses. An attacker-controlled archive can readily exceed the 30 MiB threshold, so this check provides no authenticity assurance. HTTPS alone does not protect against upstream compromise, build-environment trust-store compromise, or unauthorized modification before or during release production. The packaging version supplied through `--version` controls only the output archive name; it does not select or validate a corresponding upstream AWS CLI release. Consequently, rebuilding the same Skill version at different times can silently package different upstream code. ### Attack Path 1. The upstream download source, DNS/TLS trust path, build runner, or relea ...[truncated 1315 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/package.sh (reported line 84)May include surrounding context.

sh
AWS_VER_DIR="${versions[0]}"

if [[ -L "${STAGING}/aws-cli/v2/current" ]]; then
  rm -f "${STAGING}/aws-cli/v2/current"
  ln -s "${AWS_VER_DIR}" "${STAGING}/aws-cli/v2/current"
fi
if [[ -L "${STAGING}/bin/aws" ]]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/package.sh (reported line 88)May include surrounding context.

sh
ln -s "${AWS_VER_DIR}" "${STAGING}/aws-cli/v2/current"
fi
if [[ -L "${STAGING}/bin/aws" ]]; then
  rm -f "${STAGING}/bin/aws" "${STAGING}/bin/aws_completer"
  ln -s ../aws-cli/v2/current/bin/aws "${STAGING}/bin/aws"
  ln -s ../aws-cli/v2/current/bin/aws_completer "${STAGING}/bin/aws_completer"
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states that the packaging script downloads and runs the AWS CLI installer, which is execution of a third-party binary obtained over the network. Even if this is the expected build mechanism for this skill, the absence of explicit integrity verification, provenance details, or a warning about the trust boundary creates a real supply-chain risk: a compromised download source, tampered artifact, or unsafe mirror could lead to arbitrary code execution during packaging.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly exposes shell-capable installation and usage flows but does not declare any tool scope or permissions boundary. In an agent ecosystem, missing scope metadata can cause the skill to be invoked without clear operator awareness of its ability to execute commands, perform network access, and interact with cloud resources.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

Download the release tarball for your architecture and extract:

bash
TAG=$(curl -fsSL "https://api.github.com/repos/PanthroCorp-Limited/openclaw-skills/releases" \
  | grep -o '"tag_name":"aws-cli/v[^"]*"' | head -1 | cut -d'"' -f4)
VERSION=${TAG#aws-cli/v}
ARCH=$(uname -m); [ "$ARCH" = "aarch64" ] && ARCH="arm64" || ARCH="amd64"

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

bash
aws s3 ls s3://my-bucket/
aws s3api list-objects-v2 --bucket my-bucket --prefix parsed/
aws s3 cp s3://my-bucket/key.json /tmp/key.json
aws sts get-caller-identity

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The authentication section states that credentials resolve automatically via the default provider chain and specifically highlights IMDS use in EC2/ECS, but it does not warn that invoking the CLI may silently reach the instance metadata service and acquire cloud credentials. In containerized or multi-tenant environments, this can unexpectedly expose role credentials and enable broader AWS access than the operator intended.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/package.sh (reported line 36)May include surrounding context.

sh
trap cleanup EXIT

echo "Downloading AWS CLI v2 for linux/${ARCH}..."
curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-${AWS_ARCH}.zip" -o "${WORK_DIR}/awscli.zip"

ZIP_SIZE=$(stat --format=%s "${WORK_DIR}/awscli.zip")
MIN_ZIP_SIZE=$((30 * 1024 * 1024))

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The installation instructions fetch release metadata and a tarball over the network, then immediately extract and symlink binaries into the user's tool path without any integrity verification or safety warning. This creates a supply-chain and local system modification risk if the release source, network path, or selected artifact is compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.