T09 · Insecure Skill Coding Practices
- Location
cleaner.py:64- Finding
Automatic Global Output Hook Can Silently Corrupt Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not evidently malicious, but it automatically rewrites every agent response and can change commands, URLs, and code before you see them.
Review carefully before installing. This skill should only be enabled if you are comfortable with a session-wide output filter that may rewrite commands, code snippets, paths, and URLs before display. Prefer an opt-in version with a disable switch, scoped transformations, and a way to compare original versus cleaned output; use a pinned installer version where possible.
cleaner.py:64Automatic Global Output Hook Can Silently Corrupt Agent Responses
SKILL.md:67Installation Instructions Execute an Unpinned Mutable npm Package
Referenced artifact was not completely inspected
| `SKILL.md` | `SKILL.md` | This documentation | 本文档 |
The README instructs users to run npx clawhub@latest install ..., which fetches and executes the latest package code rather than a pinned, reviewed version. This creates a supply-chain risk: if the upstream package is compromised or changed unexpectedly, users may execute attacker-controlled code during installation.
The README states that all agent output is automatically cleaned after install, but does not prominently warn that displayed commands, paths, and URLs may be altered before the user sees them. Silent output rewriting is security-relevant because it can change operational instructions or links in ways that obscure the original model output and reduce user ability to validate content.
This section documents an auto-registered hook that intercepts all agent output on load and modifies it, yet provides no safety warning, consent step, or limitation on scope. An on-load global hook is more dangerous than a manual utility because it affects every response transparently, potentially rewriting security-sensitive commands, filesystem paths, or repository URLs without visibility.
The documented design auto-executes hook registration on import, meaning merely loading the module changes runtime behavior without an explicit user action. Autonomous activation increases the chance of unexpected or unauthorized behavior and makes the skill context more dangerous because it modifies agent output globally rather than acting as a user-invoked helper.
# In cleaner.py - Auto-executed on import | 导入时自动执行
def _auto_register_hook():
from openclaw import get_current_agent
agent = get_current_agent()
The skill advertises automatic hook registration that modifies all agent output on load, but does not provide a strong warning about the full scope and security implications of intercepting every response. This is dangerous because global output rewriting can silently alter commands, code, URLs, or security-relevant text, reducing user visibility and potentially enabling deceptive or unsafe behavior.
The installation command uses npx clawhub@latest, which fetches and executes the latest remote package without pinning to a specific version. This creates a supply-chain risk: if the package is compromised or a breaking/malicious update is published, users may unknowingly install and run untrusted code.
The documented implementation auto-executes code on import and immediately registers a lifecycle hook against the current agent. Import-time side effects are risky because merely loading the skill causes autonomous behavior changes without user approval, and in this case the hook gains control over all outgoing agent output.
# cleaner.py - Auto-executed on import | 导入时自动执行
def _auto_register_hook():
from openclaw import get_current_agent
agent = get_current_agent()
The module is presented as a harmless text-cleaning utility, but importing it triggers hidden global behavior by registering a before_output hook. That mismatch is dangerous because users or downstream systems may load the skill expecting a pure helper while it silently alters all agent output, creating an integrity and transparency problem.
The module description states in Chinese that it automatically checks and cleans spaces in code and URLs, and the file predominantly presents behavior/documentation in Chinese without offering a language choice. Per the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified.
Automatically registering an output-modifying hook on import creates an undisclosed side effect that changes agent behavior globally without user consent. In a skill ecosystem, this can be exploited to tamper with responses, hide content changes, or introduce subtle output corruption that is difficult to trace back to the imported module.
In the exception path, the comment says 'will auto-register when loaded', implying deferred successful registration. The actual behavior is only to return False, with no deferred registration mechanism beyond the current import attempt, so the comment materially misstates what the code does.
No suspicious patterns detected.