Back to skill

Security audit

dssb

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended to install a security plugin, but its installer handles credentials and system configuration in ways that need careful review before use.

Review before installing. This skill is not judged malicious, but it will install a remote plugin, contact ClawSentry services, store login state, write service credentials into OpenClaw configuration, restart the OpenClaw gateway, and may log those credentials locally. Prefer a version-pinned installer that redacts logs, uses restricted file permissions, avoids shell-interpolated configuration commands, and clearly confirms post-authorization changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:7
Finding

Shell Command Injection Through Plugin Configuration Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:3
Finding

Authentication Credentials Written to Polling Log

Content
View full analysis
typeof a=="object"?JSON.stringify(a):a).join(" "), r=`${o(new Date)} - INFO - ${i}\n`; n.write(r); c.apply(console,t) }; console.error=function(...t){ let i=t.map(a=>typeof a=="object"?JSON.stringify(a):a).join(" "), r=`${o(new Date)} - ERROR - ${i}\n`; n.write(r); l.apply(console,t) } } ``` The complete login response is subsequently logged: ```javascript async function Z(e,n){ let o=`${I}/OpenTOP/V1/Console/GetLoginTokenIdentity`, c={"X-Ai-Device-Fingerprint":n}, l={LoginToken:e}; console.log("[poll-login] Calling GetLoginTokenIdentity API..."); try { let {statusCode:t,data:i}=await U(o,c,l); console.log(`[poll-login] Response status code: ${t}`); console.log(`[poll-login] Response content: ${JSON.stringify(i)}`); return i } catch(t) { return {} } } ``` ### Technical Analysis Once polling begins, the script replaces `console.log` and `console.error` with wrappers that append all output to `.state/poll_login.log`. The login-status function logs the complete JSON response without redaction. After successful authorization, the response can contain credential material including `ApiKey` and `AppId`. The log stream is opened without an explicit restrictive mode. The parent process also opens the same log with `openSync(t, "a")`, likewise without a mode. Its resulting permissions therefore depend on the account's umask and may commonly be readable by other local users. Logging complete authentication responses unnecessarily expands the number of locations containing reusable secrets and increases exposure ...[truncated 989 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bundle.cjs:3
Finding

Login Token and Device-Binding State Stored with Default Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/bundle.cjs:2
Finding

Installation of an Unpinned Remote Plugin Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that after the user completes authorization, OpenClaw will automatically execute the remaining installation and configuration flow, but it does not clearly enumerate what actions will be taken, what permissions are involved, or whether system changes, network access, or plugin activation will occur. For a security-related skill that installs plugins and modifies an agent environment, this weakens informed consent and could enable users to authorize impactful actions they do not fully understand.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script does substantially more than local plugin installation: it generates a device fingerprint, requests a remote login token from ClawSentry services, polls for identity, stores login state, writes received credentials into OpenClaw plugin config, and restarts the gateway. That expands the trust boundary from local setup to remote account enrollment and credential provisioning, which is sensitive behavior not clearly disclosed by the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script hard-codes remote service endpoints under clawsentry.cn and automatically sends a device fingerprint and enrollment traffic there without user choice or documented justification. This creates privacy, compliance, and supply-chain risk because users cannot easily verify, redirect, or disable communication to a region-specific external service during what is presented as plugin setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The polling function logs the full GetLoginTokenIdentity API response with JSON.stringify(i), and downstream logic expects sensitive fields such as ApiKey, AccountId, and AppId. Logging these values can expose credentials or account identifiers to local logs, terminal history capture, CI runners, or support bundles, enabling unauthorized use of the provisioned security plugin.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is entirely written in Chinese and provides no indication that users may choose another language or that the skill is limited to a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest identifies the skill as ClawSentry, but the in-code package metadata and runtime banner call it 'ClawSentinel Combined'. This is active documentation/identity text inside the code that conflicts with the declared skill identity and can mislead operators about what is being executed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code redirects console output into a persistent log file under .state/poll_login.log and later logs operational status and remote API response content during login polling. Persistent local logs can capture account metadata, token-related workflow details, and troubleshooting output that may be readable by other local users or retained longer than necessary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.