Back to skill

Security audit

security-sweep

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed security scanner, but its optional Notion export can move discovered secrets through an unverified local helper into external storage.

Review this skill before installing if you plan to use --encrypt-found. The normal scan/report scripts are local and purpose-aligned, but the Notion export path handles real secrets, depends on an unverified helper outside the package, and may expose sensitive source lines to another process. Use the scanner without --encrypt-found unless you have independently reviewed the Notion helper and are comfortable with that storage model.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/full-scan.sh:107
Finding

Plaintext Secrets and Master Password Are Exposed to an Unverified External Helper

Content
View full analysis
/dev/null | grep -q "Stored"; then echo " 🔒 Encrypted to Notion as 'scan-${label}'" else echo " ⚠️ Failed to encrypt to Notion" fi } ``` ```bash if [[ "$ENCRYPT_FOUND" == "true" ]]; then local secret_line secret_line=$(grep -rEn "$secret_regex" "$file" 2>/dev/null | head -1 || true) [[ -n "$secret_line" ]] && encrypt_to_notion "${skill_name}-$(basename "$file")" "$secret_line" fi ``` ### Technical Analysis When `--encrypt-found` is enabled, the scanner extracts the first complete source line matching its secret-detection expression. It then passes that line as a command-line argument to `~/.openclaw/scripts/notion-secrets.js` while providing `NOTION_MASTER_PASSWORD` through standard input. The helper is outside the audited package. This project does not bundle it, pin its expected hash, verify its ownership or permissions, or otherwise establish its integrity before executing it. Consequently, the audit cannot verify the helper's claimed local encryption or its network destination. A malicious or replaced helper would receive both the plaintext finding and the master password. Passing the finding through `"$secret"` as an argument also exposes it ...[truncated 2419 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (12)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

md
| 🔴 CRITICAL | Hardcoded secret or unsafe eval | `const key = "sk-123..."` |
| 🟠 HIGH | Dangerous exec without sanitization | `exec(userInput)` |
| 🟡 MEDIUM | Shell injection surface or npm audit failure | `bash -c "${var}"` |
| 🟢 LOW | Overly broad file permissions | `chmod 777` |
| ℹ️ INFO | Expected network egress documented | External API call |

---

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The core declared purpose mostly matches the code: it does perform a security sweep for skills, including hardcoded secret detection, dangerous exec pattern detection, dependency vulnerability checks via npm audit, and network egress detection. However, there is a material undeclared capability: when invoked with --encrypt-found, the script takes discovered secret content and sends it to a separate Notion-secrets script using a master password from the environment. Even if framed as encryption/storage, this is a distinct data-handling capability involving sensitive findings and an external integration that is not disclosed by the description or declared permissions. Additionally, the code scans for shell injection surfaces, which is extra functionality beyond the stated categories, though this alone would be minor. The main reason for mismatch is the undeclared handling/export of found secrets to Notion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code is clearly security-audit related and does scan installed skill directories, so its general domain matches the description. However, the declared purpose claims broader coverage than the supplied code actually provides. This script only uses grep-based pattern matching over local files and checks for secret-like key/value assignments and dangerous exec-related patterns. There is no logic for dependency vulnerability analysis (e.g., parsing manifests/lockfiles, invoking advisory databases, or checking package versions) and no logic for detecting network egress patterns (e.g., HTTP clients, sockets, curl/wget usage). Therefore the description materially overstates the implemented behavior for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The code generally aligns with the declared purpose of auditing skills/plugins for security issues: it scans a target directory and reports findings for secrets, dangerous exec usage, and network/network egress indicators. However, the declared description explicitly includes dependency vulnerability scanning, and this code chunk contains no logic to inspect dependencies, lockfiles, package manifests, CVE data, or use a vulnerability database/tool. Conversely, the script includes a shell injection surface scan, which is not mentioned in the description. That extra check is related to the overall security-scanning purpose, so it is a minor mismatch, but the absence of the declared dependency-vulnerability capability is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The scanner includes an optional path to send discovered secrets to an external Notion-backed storage flow, which exceeds the expected behavior of a local auditing tool. Even though it is gated behind a flag and environment variable, transmitting captured secrets off the scanned host materially increases exposure and creates a second sensitive data store.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

When --encrypt-found is enabled, the code extracts matching secret lines and pipes them to an external Node script along with a master password from the environment. A security scanner should not export raw discovered secrets to external storage by default behavior extensions, because compromise of that external path or script would leak the exact credentials it was supposed to protect.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

md
| 🔴 CRITICAL | Hardcoded secret or unsafe eval | `const key = "sk-123..."` |
| 🟠 HIGH | Dangerous exec without sanitization | `exec(userInput)` |
| 🟡 MEDIUM | Shell injection surface or npm audit failure | `bash -c "${var}"` |
| 🟢 LOW | Overly broad file permissions | `chmod 777` |
| ℹ️ INFO | Expected network egress documented | External API call |

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs use of shell scripts and shell commands, but the manifest declares no tool scope such as permissions or allowed-tools. That creates an authorization/visibility gap where a reviewer or runtime may not understand that the skill needs shell execution, increasing the chance of overbroad or implicit command execution. In a security-auditing skill, shell access is contextually expected, but it still must be explicitly declared because the skill is designed to inspect many local files and invoke multiple scripts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/notion-encryption.md (reported line 34)May include surrounding context.

md
### 1. Get a Notion API Integration

1. Go to [notion.so/my-integrations](https://www.notion.so/my-integrations)
2. Create a new integration ("Security Sweep")
3. Copy the internal API token
4. Store it: `node ~/.openclaw/scripts/notion-secrets.js put notion_api_key "<your-token>"`
5. Share the "RhomBot Secrets" database with your integration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The optional secret export behavior is only lightly described in the help text and has no strong warning or runtime confirmation at the moment secrets are about to be transmitted. Users running a security scan may not appreciate that enabling the flag can move raw credential material into another system, increasing the chance of accidental disclosure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script claims to encrypt findings to Notion but actually delegates handling to ~/.openclaw/scripts/notion-secrets.js and merely checks for a 'Stored' string in output. Because the caller does not verify how encryption occurs, where data is sent, or whether plaintext is logged or retained, users may be given false assurance about the confidentiality of exported secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The script reads NOTION_MASTER_PASSWORD, which is a sensitive credential, to enable encryption/storage operations. While the code checks whether it is set, it does not include a user-facing warning or explanatory comment about handling this credential or that it will be used for external secret storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.