Back to skill

Security audit

Openclaw Agent Optimize

Security checks for vulnerabilities and agentic risk

Overview

This is a documented advisory OpenClaw optimization skill with user-gated persistent changes and no embedded executable payload.

Install only if you want OpenClaw optimization advice. Review any proposed config, cron, heartbeat, memory, or skill-surface change before approving it, and prefer a pinned or verified installer path if you are concerned about npm supply-chain risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:31
Finding

Unpinned Package Execution in Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 31–33
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

bash
npx clawhub install openclaw-agent-optimize

Technical Analysis

The recommended installation command invokes clawhub through npx without specifying a package version or integrity constraint. If the package is not already available locally, npx can retrieve the currently published version from the configured package registry and execute its CLI code with the invoking user's privileges.

Because the resolved package is mutable and is not tied to a reviewed version, the code executed by this command may differ from the code available when this Skill was audited. Exploitation depends on a supply-chain event such as compromise of the package publisher, registry account, package distribution infrastructure, or local registry configuration.

This issue exists in the documented installation workflow rather than in an automatically executed script shipped by the Skill.

Attack Path

  1. An attacker compromises the package publisher, registry account, distribution channel, or a registry trusted by the user.
  2. The attacker publishes or serves a malicious version of the unpinned clawhub package.
  3. A user follows the README and runs npx clawhub install openclaw-agent-optimize.
  4. npx resolves and downloads the attacker-controlled package version.
  5. The malicious package executes with the privileges of the invoking user.
  6. It may read accessible workspace or user data, modify files, install altered Skill content, access user-level credentials available to the process, or establish additional persistence.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account running the installation command. The accessible scope could include the OpenClaw workspace, user-owned files, environment variables, package-man ...[truncated 233 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the installer to a specific reviewed version, for example npx clawhub@<reviewed-version> install openclaw-agent-optimize.
  • Document the expected package registry, publisher identity, package version, and release provenance.
  • Prefer an installation process backed by a lockfile, verified checksum, signed release, or package-manager integrity metadata.
  • Advise users to inspect and verify the resolved package before first execution.
  • Avoid running the installer with administrator or root privileges.
  • Consider making the manual copy-based installation the preferred high-assurance option.
  • Establish a process for reviewing and updating the pinned installer version when security fixes are released.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
## Notes

- Some runtimes snapshot skills/config per session. If you install/update skills and do not see changes, start a new session.
- Prefer short `SKILL.md` + `references/` for long runbooks.
- If context bloat is the main complaint, pair this skill with `context-clean-up` (audit-only).

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
- Prefer short `SKILL.md` + `references/` for long runbooks.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states the skill auto-triggers for broad requests like optimizing an agent, improving setup, or following best practices, which can match many ordinary conversations. Overly broad trigger scope can cause the skill to activate unexpectedly, inject unrelated guidance into sessions, and increase the chance that users are steered by the skill outside the narrow context they intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger "agent best practices" is generic and could match many unrelated conversations about agents, not specifically OpenClaw workspace optimization. Although the description narrows intended use, the trigger list itself does not constrain this phrase or provide exclusions, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.