Back to skill

Security audit

clawSecurityTest

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but its installer handles credentials and shell commands in unsafe ways that warrant review before use.

Install only if you trust the publisher and are comfortable with a bundled script modifying OpenClaw configuration, installing an unpinned plugin, sending a device fingerprint to the ClawSentry service, and storing authentication material locally in plaintext/logs. Prefer a reviewed, pinned installer that avoids shell-string execSync, redacts logs, and protects credentials with restrictive permissions or OS secret storage.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:7
Finding

Shell Command Injection Through Untrusted Plugin Configuration Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:5
Finding

Authentication Tokens and API Credentials Stored or Logged in Plaintext

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/bundle.cjs:7
Finding

Unpinned Third-Party Plugin Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/bundle.cjs:3
Finding

Persistent Machine Fingerprint Collected, Stored, and Sent to an External Service

Content
View full analysis
/dev/null || hostname ) | head -n 1 || :", freebsd:"kenv -q smbios.system.uuid || sysctl -n kern.hostuuid" }; ``` ```js function Ln(){ return machineIdSync(); } ``` ```js let g=Ln(), o=`${hn}/OpenTOP/V1/Console/CreateLoginToken`, a={"X-Ai-Device-Fingerprint":g}; let {statusCode:t,data:i}=await wn(o,a,{}); ``` ```js vn({ loginToken:r, deviceFingerprint:g, expiredAt:c, loginUrl:l, enable:false }); ``` ### Technical Analysis The bundled `node-machine-id` implementation runs platform-specific commands or reads system machine-ID sources. It hashes the resulting identifier with SHA-256, but hashing does not make a stable identifier anonymous: the value remains persistent and suitable for correlating activity from the same device. The resulting fingerprint is stored in `.state/login_state.json` and transmitted to `https://openclaw.sdk.access.clawsentry.cn` in the `X-Ai-Device-Fingerprint` header during token creation and login polling. The collection is disclosed in `SKILL.md`; however, it still creates a privacy and access-scope risk because a persistent host identifier is collected for an installation and authorization workflow. ### Attack Path 1. The user runs the bundled installer. 2. The script executes an operating-system-specific machine-identifier query. 3. The identifier is normalized and hashed. 4. The stable fingerprint is written to local state. 5. The fingerprint is sent to the external ClawSentry authorization servic ...[truncated 653 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
The bundled script (`bundle.cjs`) performs the following operations:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
The bundled script (`bundle.cjs`) performs the following operations:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is written entirely in Chinese and provides no indication that other languages are supported or that the user can choose their preferred language. Under the policy, a skill that effectively forces a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to run a bundled Node.js script and perform environment/shell-capable actions, but it declares no explicit tool scope or permissions boundary in the manifest. This creates an authorization gap where consumers may invoke code execution without clear least-privilege constraints or reviewable limits.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
97% confidence
Finding

The skill explicitly directs execution of a bundled script that performs system queries, network communication, local state writes, background process spawning, and plugin configuration changes. Even if presented as installation logic, bundled third-party code with shell/system access is dangerous because it can conceal additional behavior, exfiltrate host identifiers or tokens, or persist beyond the initial run.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
- **Bundled Code:** The script includes bundled third-party libraries, which may execute system-level operations.
- __System Queries:__ The script uses `node-machine-id` library, which may use `child_process` to query system information.
- **Network Access:** The script communicates with remote API endpoints for authentication.
- **Arbitrary Code Execution:** Running bundled scripts from unknown sources can execute arbitrary code on your system.

### Security Measures

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script collects a stable device fingerprint via machineIdSync() and transmits it in the X-Ai-Device-Fingerprint header during login-related API calls, but there is no explicit user consent prompt or clear warning before collection/transmission. In a security-plugin installer context, this creates privacy and tracking risk because a persistent hardware-derived identifier can be used to correlate activity across sessions and services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script writes sensitive login state to .state/login_state.json, including loginToken, deviceFingerprint, expiredAt, loginUrl, and later marks enable=true, without any access control hardening, encryption, or user warning. It also logs API responses and polling activity to poll_login.log, increasing the chance that credentials or account identifiers are exposed to other local users, backup systems, or log collectors.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
2. **Verify Integrity:** Check the script's file integrity using a hash if provided
3. **Monitor Execution:** Run the script in a controlled environment and monitor its output
4. **Ensure Trust:** Only run the script if you trust the source of this skill
5. **Check Permissions:** Ensure the script has appropriate file permissions

### Alternative Installation

Static analysis

No suspicious patterns detected.