Back to skill

Security audit

Wip Branch Guard

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed defensive branch guard, but it installs machine-wide automatic hooks and has verified bypasses that weaken the protections users are asked to rely on.

Review before installing. Install only if you intentionally want a machine-wide Claude/OpenClaw hook that can deny tool calls and write local guard state. Do not rely on this as a strong access-control boundary until the Bash classifier, Glob onboarding behavior, and state cleanup imports are fixed. Keep a removal path for the ~/.claude hook and monitor ~/.ldm/state for retained audit/session data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
guard.mjs:377
Finding

Bash allowlist permits file-write bypasses on protected branches and paths

Content
View full analysis
openclaw.json" and "echo > ~/.openclaw/..." bypass // class Parker surfaced on 2026-04-19. /(>>?|\btee\b).*\.openclaw\/openclaw\.json\b/, // OpenClaw main config /(>>?|\btee\b).*\.openclaw\/agents\/[^\/\s|;&]+\/agent\/(auth-profiles|settings)\.json\b/, // agent auth/settings /(>>?|\btee\b).*\.openclaw\/(extensions|credentials|secrets)\/[^\s|;&]+/, // deployed exts, imessage pairing, SA token /(>>?|\btee\b).*\.ldm\/extensions\/[^\s|;&]+/, // LDM OS deployed extensions /(>>?|\btee\b).*\.ldm\/config\.json\b/, // LDM OS root config /(>>?|\btee\b).*\.ldm\/agents\/[^\/\s|;&]+\/config\.json\b/, // LDM OS agent configs ``` ```js // guard.mjs:377-388 function stripQuotedContent(cmd) { return cmd.replace(/"(?:[^"\\]|\\.)*"|'(?:[^'\\]|\\.)*'/g, '""'); } // Check each segment of a compound command independently. // "rm -f file ; echo done" splits into ["rm -f file", "echo done"]. // Each segment checked against blocked, then allowed. An allowed match // on one segment can't excuse a blocked match on a different segment (#232). function isBlockedCompoundCommand(cmd, blockedPatterns, allowedPatterns) { const stripped = stripQuotedContent(cmd); const segments = stripped.split(/\s*(?:&&|\|\||[;|])\s*/).filter(Boolean); for (const segment of segments) { ...[truncated 4539 chars]
Remediation
View remediation
relative-file` - `printf x >> relative-file` - `cat source > relative-file` - `curl -o relative-file URL` - Quoted absolute destinations - `$HOME` and tilde-expanded protected destinations - Redirections within pipelines and compound commands - Symlinks pointing from an allowed location to a protected destination ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
guard.mjs:1041
Finding

Glob events can satisfy the onboarding gate without reading required documentation

Content
View full analysis
' Read ' + f).join('\n'); deny(`BLOCKED: Onboarding required before first write to ${repoDir}. Read these repo docs first (they explain the expected workflow and known landmines): ${readList} Then retry the write.`, { kind: 'onboarding', path: repoDir, session_id: sessionId, tool: toolName, command_stripped: stripped, }); process.exit(0); } else { markOnboarded(sessionState, repoDir); stateDirty = true; } ``` ### Technical Analysis The onboarding control is documented as requiring the Agent to read re ...[truncated 2207 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (46)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
94% confidence
Finding

The installation instructions require modifying ~/.claude/settings.json to register a command hook that will execute automatically on SessionStart and PreToolUse. Any skill that persists code execution through an agent's global config and startup hooks has high security significance because it gains recurring execution in future sessions and across repositories, even if the stated purpose is defensive.

Content

Scanner excerpt · INSTALL.md (reported line 3)May include surrounding context.

wip-branch-guard Installation

The guard now registers on two hook events. Add BOTH to ~/.claude/settings.json:

json
{

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · INSTALL.md (reported line 75)May include surrounding context.

md
- It does not block session boot. The warning is informational only.
- It does not enumerate every possible worktree path; it caps at the first 10 to keep the boot context readable.
- It does not differentiate "main tree" from "worktree on main" — both trigger the warning. This is intentional: a worktree on main is just as dangerous.
- It does not fire for non-git directories. Agents outside a repo get no warning (there is nothing to warn about).

## Test

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 9)May include surrounding context.

md
## Install

See [INSTALL.md](INSTALL.md) for hook registration in `~/.claude/settings.json` (PreToolUse + SessionStart entries).

## What it does

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
## Install

See [INSTALL.md](INSTALL.md) for hook registration in `~/.claude/settings.json` (PreToolUse + SessionStart entries).

## What it does

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
## What it does

- **Layer 1 ... write gate.** Blocks Write/Edit/NotebookEdit/Bash-write on main branch or non-worktree feature branches. Shared-state paths (`~/.claude/plans/`, `~/.openclaw/workspace/`, `~/.ldm/extensions/`, etc.) are always allowed.
- **Layer 2 ... destructive-command block.** Always denies `git clean -f`, `git reset --hard`, `git stash drop/pop/clear`, `git checkout -- <path>`, `python -c "open().write()"`, `node -e "writeFile()"`, `--no-verify`, and `git push --force` without `--force-with-lease`.
- **Layer 3 ... session-level gates.**
  - Onboarding-before-first-write: requires Read of `README.md`, `CLAUDE.md`, and any `*RUNBOOK*.md` / `*LANDMINES*.md` / `WORKFLOW*.md` at repo root before the first write.
  - Recently-blocked-file tracking: catches `Edit X` denied → `cat > X` via Bash as an equivalent-action bypass.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
## What it does

- **Layer 1 ... write gate.** Blocks Write/Edit/NotebookEdit/Bash-write on main branch or non-worktree feature branches. Shared-state paths (`~/.claude/plans/`, `~/.openclaw/workspace/`, `~/.ldm/extensions/`, etc.) are always allowed.
- **Layer 2 ... destructive-command block.** Always denies `git clean -f`, `git reset --hard`, `git stash drop/pop/clear`, `git checkout -- <path>`, `python -c "open().write()"`, `node -e "writeFile()"`, `--no-verify`, and `git push --force` without `--force-with-lease`.
- **Layer 3 ... session-level gates.**
  - Onboarding-before-first-write: requires Read of `README.md`, `CLAUDE.md`, and any `*RUNBOOK*.md` / `*LANDMINES*.md` / `WORKFLOW*.md` at repo root before the first write.
  - Recently-blocked-file tracking: catches `Edit X` denied → `cat > X` via Bash as an equivalent-action bypass.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
- 1.9.78: hotfix, inlined `lib/*.mjs` into `guard.mjs` after an installer bug dropped the lib/ subdir

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 307)May include surrounding context.

install. v1.9.82 ignores it. Safe to delete:

text
rm -f ~/.ldm/state/guard-session.json

cleanupStaleStateFiles() does NOT touch it (the regex matches

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · _trash/RELEASE-NOTES-v1-9-82.md (reported line 142)May include surrounding context.

install. v1.9.82 ignores it. Safe to delete:

text
rm -f ~/.ldm/state/guard-session.json

cleanupStaleStateFiles() does NOT touch it (the regex matches

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · guard.mjs (reported line 1100)May include surrounding context.

js
}
  }

  // Block dangerous flags on ANY branch (these bypass safety checks)
  if (toolName === BASH_TOOL) {
    const cmd = (toolInput.command || '');
    if (/--no-verify\b/.test(cmd)) {

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · guard.mjs (reported line 1100)May include surrounding context.

js
}
  }

  // Block dangerous flags on ANY branch (these bypass safety checks)
  if (toolName === BASH_TOOL) {
    const cmd = (toolInput.command || '');
    if (/--no-verify\b/.test(cmd)) {

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · guard.mjs (reported line 1100)May include surrounding context.

js
}
  }

  // Block dangerous flags on ANY branch (these bypass safety checks)
  if (toolName === BASH_TOOL) {
    const cmd = (toolInput.command || '');
    if (/--no-verify\b/.test(cmd)) {

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · guard.mjs (reported line 1108)May include surrounding context.

js
process.exit(0);
    }
    if (/\bgit\s+push\b.*--force\b/.test(cmd) && !/--force-with-lease\b/.test(cmd)) {
      deny('BLOCKED: git push --force can destroy remote history. Use --force-with-lease or ask Parker.');
      process.exit(0);
    }

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
test_case "git stash drop" deny Bash "git stash drop"
test_case "git stash pop" deny Bash "git stash pop"
test_case "git stash clear" deny Bash "git stash clear"
test_case "git reset --hard" deny Bash "git reset --hard"
test_case "git restore file.txt" deny Bash "git restore file.txt"
test_case "python file write bypass" deny Bash "python3 -c \"open('f','w').write('x')\""
test_case "node file write bypass" deny Bash "node -e \"require('fs').writeFileSync('f','d')\""

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
test_case "git stash drop" deny Bash "git stash drop"
test_case "git stash pop" deny Bash "git stash pop"
test_case "git stash clear" deny Bash "git stash clear"
test_case "git reset --hard" deny Bash "git reset --hard"
test_case "git restore file.txt" deny Bash "git restore file.txt"
test_case "python file write bypass" deny Bash "python3 -c \"open('f','w').write('x')\""
test_case "node file write bypass" deny Bash "node -e \"require('fs').writeFileSync('f','d')\""

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · guard.mjs (reported line 349)May include surrounding context.

js
test_case "git stash drop" deny Bash "git stash drop"
test_case "git stash pop" deny Bash "git stash pop"
test_case "git stash clear" deny Bash "git stash clear"
test_case "git reset --hard" deny Bash "git reset --hard"
test_case "git restore file.txt" deny Bash "git restore file.txt"
test_case "python file write bypass" deny Bash "python3 -c \"open('f','w').write('x')\""
test_case "node file write bypass" deny Bash "node -e \"require('fs').writeFileSync('f','d')\""

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 74)May include surrounding context.

sh
test_case "git stash drop" deny Bash "git stash drop"
test_case "git stash pop" deny Bash "git stash pop"
test_case "git stash clear" deny Bash "git stash clear"
test_case "git reset --hard" deny Bash "git reset --hard"
test_case "git restore file.txt" deny Bash "git restore file.txt"
test_case "python file write bypass" deny Bash "python3 -c \"open('f','w').write('x')\""
test_case "node file write bypass" deny Bash "node -e \"require('fs').writeFileSync('f','d')\""

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 83)May include surrounding context.

sh
test_case "git stash drop" deny Bash "git stash drop"
test_case "git stash pop" deny Bash "git stash pop"
test_case "git stash clear" deny Bash "git stash clear"
test_case "git reset --hard" deny Bash "git reset --hard"
test_case "git restore file.txt" deny Bash "git restore file.txt"
test_case "python file write bypass" deny Bash "python3 -c \"open('f','w').write('x')\""
test_case "node file write bypass" deny Bash "node -e \"require('fs').writeFileSync('f','d')\""

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · test.sh (reported line 90)May include surrounding context.

sh
echo "  (These only run when CWD is on main branch)"
test_case "rm with echo should still block" deny Bash "rm -f file ; echo done" true
test_case "safe compound (ls && echo)" allow Bash "ls -la && echo done" true
test_case "cd then rm should block" deny Bash "cd /tmp && rm -rf somedir" true

echo ""
echo "--- Safe commands (should ALLOW) ---"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 118)May include surrounding context.

sh
echo "--- Temp directory operations (Phase 12 audit) ---"
test_case "cp to /tmp" allow Bash "cp source.txt /tmp/test.txt"
test_case "mv to /tmp" allow Bash "mv source.txt /tmp/test.txt"
test_case "rm in /tmp" allow Bash "rm /tmp/test.txt"
test_case "mkdir in /tmp" allow Bash "mkdir -p /tmp/test-dir"
test_case "touch in /tmp" allow Bash "touch /tmp/test-file"
test_case "redirect to /tmp" allow Bash "echo hello > /tmp/test.txt"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 135)May include surrounding context.

sh
# covering mkdir. Now all the common bootstrap verbs work.
test_case "cp to .worktrees" allow Bash "cp src.txt .worktrees/repo--feat/ai/dest.md"
test_case "mv to .worktrees" allow Bash "mv src.txt .worktrees/repo--feat/ai/dest.md"
test_case "rm in .worktrees" allow Bash "rm .worktrees/repo--feat/ai/file.md"
test_case "touch in .worktrees" allow Bash "touch .worktrees/repo--feat/ai/file.md"
test_case "redirect to .worktrees" allow Bash "echo content > .worktrees/repo--feat/ai/file.md"
test_case "tee to .worktrees" allow Bash "cat src | tee .worktrees/repo--feat/ai/file.md"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 141)May include surrounding context.

sh
test_case "tee to .worktrees" allow Bash "cat src | tee .worktrees/repo--feat/ai/file.md"
# Regressions: on-main writes to non-.worktrees paths still deny
test_case "cp to main-tree path still denies" deny Bash "cp src.txt /some/repo/file.md" true
test_case "rm on main-tree path still denies" deny Bash "rm /some/repo/file.md" true

echo ""
echo "--- Plan files (should ALLOW Write/Edit) ---"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 337)May include surrounding context.

sh
#    denies with path=file) and then try to Bash-write the same file.
#    (main-branch tests only work when test runner is on main.)
if [[ "$ON_MAIN" == "true" ]]; then
  rm -f "$LAYER3_STATE/guard-session.json"
  # Pretend we're editing a main-tree file (uses the test runner's own repo)
  MAIN_TREE=$(git rev-parse --show-toplevel)
  TEST_FILE="$MAIN_TREE/tools/wip-branch-guard/this-file-does-not-exist.md"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · test.sh (reported line 373)May include surrounding context.

sh
#    denies with path=file) and then try to Bash-write the same file.
#    (main-branch tests only work when test runner is on main.)
if [[ "$ON_MAIN" == "true" ]]; then
  rm -f "$LAYER3_STATE/guard-session.json"
  # Pretend we're editing a main-tree file (uses the test runner's own repo)
  MAIN_TREE=$(git rev-parse --show-toplevel)
  TEST_FILE="$MAIN_TREE/tools/wip-branch-guard/this-file-does-not-exist.md"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 94)May include surrounding context.

md
### The bug

`wip-file-guard` protects identity files on Edit/Write. `wip-branch-guard` blocked Edit/Write + destructive git commands + `python -c "open().write()"` / `node -e "writeFile()"`. But Bash redirects (`>`, `>>`, `tee`) into the deployed extension directories, OpenClaw config, agent auth-profiles, credentials, and secrets were not pattern-matched. An agent blocked from `Edit ~/.openclaw/openclaw.json` could pivot to `echo '{...}' > ~/.openclaw/openclaw.json` or `jq '.' ... > ~/.openclaw/openclaw.json` and the guard would not notice.

Parker surfaced this class during the 2026-04-19 debugging session ... after `Edit` was denied, the agent attempted a `jq` + shell-redirect pivot to the same file. The guard did not catch that, and Parker called it out manually.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
guard.mjs:180