T09 · Insecure Skill Coding Practices
- Location
scripts/bundle.cjs:7- Finding
Shell Command Injection Through Plugin Configuration Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears intended to install a security plugin, but its installer handles credentials and system configuration in ways that need careful review before use.
Review before installing. This skill is not judged malicious, but it will install a remote plugin, contact ClawSentry services, store login state, write service credentials into OpenClaw configuration, restart the OpenClaw gateway, and may log those credentials locally. Prefer a version-pinned installer that redacts logs, uses restricted file permissions, avoids shell-interpolated configuration commands, and clearly confirms post-authorization changes.
scripts/bundle.cjs:7Shell Command Injection Through Plugin Configuration Values
scripts/bundle.cjs:3Authentication Credentials Written to Polling Log
scripts/bundle.cjs:3Login Token and Device-Binding State Stored with Default Permissions
scripts/bundle.cjs:2Installation of an Unpinned Remote Plugin Package
The README states that after the user completes authorization, OpenClaw will automatically execute the remaining installation and configuration flow, but it does not clearly enumerate what actions will be taken, what permissions are involved, or whether system changes, network access, or plugin activation will occur. For a security-related skill that installs plugins and modifies an agent environment, this weakens informed consent and could enable users to authorize impactful actions they do not fully understand.
The script does substantially more than local plugin installation: it generates a device fingerprint, requests a remote login token from ClawSentry services, polls for identity, stores login state, writes received credentials into OpenClaw plugin config, and restarts the gateway. That expands the trust boundary from local setup to remote account enrollment and credential provisioning, which is sensitive behavior not clearly disclosed by the skill description.
The script hard-codes remote service endpoints under clawsentry.cn and automatically sends a device fingerprint and enrollment traffic there without user choice or documented justification. This creates privacy, compliance, and supply-chain risk because users cannot easily verify, redirect, or disable communication to a region-specific external service during what is presented as plugin setup.
The polling function logs the full GetLoginTokenIdentity API response with JSON.stringify(i), and downstream logic expects sensitive fields such as ApiKey, AccountId, and AppId. Logging these values can expose credentials or account identifiers to local logs, terminal history capture, CI runners, or support bundles, enabling unauthorized use of the provisioned security plugin.
The document is entirely written in Chinese and provides no indication that users may choose another language or that the skill is limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The manifest identifies the skill as ClawSentry, but the in-code package metadata and runtime banner call it 'ClawSentinel Combined'. This is active documentation/identity text inside the code that conflicts with the declared skill identity and can mislead operators about what is being executed.
The code redirects console output into a persistent log file under .state/poll_login.log and later logs operational status and remote API response content during login polling. Persistent local logs can capture account metadata, token-related workflow details, and troubleshooting output that may be readable by other local users or retained longer than necessary.
No suspicious patterns detected.