Back to skill

Security audit

Agent Team Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed team-management tool, but it persistently injects mutable team data and workflow rules into privileged agent context in a way users should review carefully.

Install only if you want an OpenClaw plugin that can influence leader-agent behavior across sessions. Keep ~/.agent-team/team.json writable only by trusted users, avoid putting instructions or sensitive content in team fields, disable load_workflow when not needed, and back up team data before using reset.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
integrations/openclaw/agent-team/index.ts:208
Finding

Automatic Injection of Behavioral Instructions into Privileged System Context

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/team.py:137
Finding

Persistent Prompt Injection Through Unsanitized Team Metadata

Content
View full analysis
None: """Add or update a team member.""" data = load_data() is_new = agent_id not in data["team"] # Get existing member data for merge behavior existing_member = data["team"].get(agent_id, {}) # If setting this member as leader, remove leader status from others if is_leader: for existing_id, existing_member_data in data["team"].items(): if existing_id != agent_id and existing_member_data.get("is_leader"): existing_member_data["is_leader"] = False print(f"Note: Removed leader status from {existing_member_data.get('name', existing_id)}") member = { "agent_id": agent_id, "name": name, "role": role, "is_leader": is_leader, "enabled": enabled, "tags": [t.strip() for t in tags.split(",") if t.strip()], "expertise": [e.strip() for e in expertise.split(",") if e.strip()], "not_good_at": [n.strip() for n in not_good_at.split(",") if n.strip()], } # Preserve or update load_workflow if load_workflow is not None: member["load_workflow"] = load_workflow == "true" elif "load_workflow" in existing_member: member["load_workflow"] = existing_member["load_workflow"] # Preserve or update group if group is not None and group.strip(): member["group"] = group.strip() elif "group" in existing_member ...[truncated 4428 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description overstates capabilities such as delegation, expertise lookup, and workflow coordination while omitting important side effects like wiping team data and storing state under ~/.agent-team/team.json. In an agent ecosystem, such misrepresentation can cause unsafe automation decisions, unexpected persistence, and accidental data loss when the tool is used under false assumptions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill description overstates capabilities such as delegation, expertise lookup, and workflow coordination while omitting important side effects like wiping team data and storing state under ~/.agent-team/team.json. In an agent ecosystem, such misrepresentation can cause unsafe automation decisions, unexpected persistence, and accidental data loss when the tool is used under false assumptions.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CLAUDE.md (reported line 32)May include surrounding context.

md
## Key Patterns

- **Context-Aware Injection**: Plugin checks `ctx.agentId` and only injects "Leader Authority" section to the designated leader
- **Single-Leader Constraint**: Setting a new leader automatically removes leader status from all others
- **Graceful Degradation**: Both components handle missing/invalid data files gracefully (return empty state)

## Architecture

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
## Key Patterns

- **Context-Aware Injection**: Plugin checks `ctx.agentId` and only injects "Leader Authority" section to the designated leader
- **Single-Leader Constraint**: Setting a new leader automatically removes leader status from all others
- **Graceful Degradation**: Both components handle missing/invalid data files gracefully (return empty state)

## Architecture

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
## Key Patterns

- **Context-Aware Injection**: Plugin checks `ctx.agentId` and only injects "Leader Authority" section to the designated leader
- **Single-Leader Constraint**: Setting a new leader automatically removes leader status from all others
- **Graceful Degradation**: Both components handle missing/invalid data files gracefully (return empty state)

## Architecture

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes automatic injection of team data and collaboration rules into system context at session start, plus global sharing across sessions, without any privacy, trust-boundary, or integrity warning. Because this data influences agent behavior and authority delegation, untrusted or stale entries could leak sensitive metadata across sessions or manipulate task routing and completion approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README documents a destructive reset operation that clears all team data but does not warn users about data loss, backups, or any confirmation behavior. In a team-management skill that stores globally shared coordination data, this omission increases the likelihood of accidental or induced destructive use, causing loss of member, leader, and delegation configuration.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
- Understand requirements and clarify questions
- Define goals and success criteria
- Identify risks and determine ownership
- Create execution plan

### 2. Do — Execution Phase

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown output presents substantial content in both Chinese and English, including role names, expertise, and analysis, but does not indicate that the language choice is user-selectable or justified by a region-specific requirement. Under the policy, forcing or assuming a language/locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The grading expectations and evidence strings are written in Chinese, which imposes a specific language/locale in the skill artifact. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose, so this appears to violate the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The expectation texts and evidence are written in Chinese, including required output such as '成员名为 Bob' and '角色为 后端开发', which implies a fixed language/locale expectation. The file does not offer any user language choice or explain why a Chinese-only locale is required, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON file contains user-facing natural-language strings exclusively in Chinese, such as the expectation text and evidence descriptions. Because the file does not indicate that the skill is region-specific or that users can choose the language, it appears to enforce a specific language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file shows inconsistent state reporting about leadership: the command result says leader status was removed from 小Q, while the verification section still labels 小Q as Leader even though the summary later says Alice is the leader. In an agent-team management skill, contradictory verification can mislead downstream users or automation into assigning authority, routing tasks, or making approval decisions based on stale or incorrect team state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt text is written entirely in Chinese and provides no indication that users may interact in another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language policy concern because it imposes a locale/language constraint without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The evaluation text and evidence are entirely specified in Chinese, indicating a language-specific requirement in natural-language content. There is no indication that the user can choose the language or that the locale restriction is justified as region-specific, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · integrations/openclaw/agent-team/README.md (reported line 28)May include surrounding context.

Method 1: Link to Global Extensions Directory (Recommended)

bash
# Create symlink to OpenClaw global extensions directory
ln -s $(pwd) ~/.openclaw/extensions/agent-team

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to run python3 scripts/team.py reset, which appears to clear or overwrite team data, but it does not warn that this operation may delete existing configuration. For markdown files, destructive behaviors that could affect user data should include a warning so users understand the impact before running the command.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module comment states that team member information is injected into system context so AI agents always have access to it without invoking tools. However, the hook later checks whether the current agent is the leader and explicitly skips injection for non-leader agents, so the documentation overstates and contradicts the actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The reset command overwrites all stored team data immediately with an empty structure and provides no interactive confirmation, dry-run mode, or recovery mechanism. In an agent skill context, this increases the chance of accidental or unintended destructive actions triggered by a user, wrapper, or delegated workflow, causing loss of operational configuration and team metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The grading expectations are written entirely in Chinese, which implies a fixed language requirement in the skill's natural-language artifacts. There is no indication that users can choose their preferred language or that the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON file contains user-facing natural-language strings entirely in Chinese, including the evaluation expectations and evidence text. Because the file does not indicate that the skill is region-specific or provide any user opt-in for language choice, it may violate a language/locale policy requiring neutrality or user selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. This file presents core skill information primarily in Chinese while other sections are in English, but it does not state that the skill is Chinese-only or give the user an option to choose language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.