Back to skill

Security audit

smart-followups

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to generate follow-up suggestions as described, with some documentation and credential-handling cautions but no evidence of malicious behavior.

Installers should treat this as a normal follow-up suggestion skill, but should review the stale docs carefully: use /smart-followups as the primary command, avoid putting real API keys in shell startup files on shared or synced systems, and verify any uninstall path before running rm -rf. Do not use the standalone CLI with sensitive conversations unless you are comfortable sending recent exchanges to the selected provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (21)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The document instructs operators to run 'rm -rf /path/to/openclaw/skills/smart-followups' as part of complete removal. Although scoped to the skill directory, recursive forced deletion is dangerous because any path substitution error, variable expansion mistake, or copy/paste modification could delete unintended files, and deployment docs are often executed manually under time pressure.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 408)May include surrounding context.

3. Complete Removal

bash
rm -rf /path/to/openclaw/skills/smart-followups
openclaw daemon restart

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The document instructs operators to run 'rm -rf /path/to/openclaw/skills/smart-followups' as part of complete removal. Although scoped to the skill directory, recursive forced deletion is dangerous because any path substitution error, variable expansion mistake, or copy/paste modification could delete unintended files, and deployment docs are often executed manually under time pressure.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 408)May include surrounding context.

3. Complete Removal

bash
rm -rf /path/to/openclaw/skills/smart-followups
openclaw daemon restart

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · QUICKSTART.md (reported line 27)May include surrounding context.

inutes.

1⃣ Prerequisites

2⃣ Installation

bash
cd /path/to/workspace/skills/smart-followups/
npm install
chmod +x cli/followups-cli.js test.sh

3⃣ Set API Key

bash
export ANTHROPIC_API_KEY="sk-ant-your-key-here"

Or add to ~/.bashrc / ~/.zshrc for persistence:

bash
echo 'export ANTHROPIC_API_KEY="sk-ant-your-key-here"' >> ~/.bashrc
source ~/.bashrc

4⃣ Test It!

Quick Test

bash
./test.sh

This runs all output modes with sample data.

Manual Test

bash
# JSON output
cat test-example.json | node cli/followups-cli.js --mode json

# Text output (Signal/iMessage format)
cat test-example.json | node cli/followups-cli.js --mode text

# Telegram button format
cat test-example.json | node cli/followups-cli.js --mode telegram

Custom Test

bash
# Create your own conversation
echo '[{"user":"What is Rust?","assistant":"Rust is

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The core purpose mostly aligns: the code does generate three contextual follow-up suggestions. However, the declared description is not fully accurate about how it is invoked and what else it does. The biggest mismatch is triggers: the description says it runs when the user uses /smart-followups or asks for suggestions, while the code actually recognizes /followups, /fu, /suggestions, and /next. Also, the code includes an undeclared onMessage interceptor that watches all incoming messages, detects numeric replies, and rewrites them into stored questions using session state. That is a substantive behavioral capability beyond simply generating suggestions on demand. These are material enough to count as a description-behavior mismatch, even though the primary feature area is related.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk does not implement the declared end-user behavior of generating contextual follow-up questions. Its primary purpose is development/package validation: confirming files exist, checking executable bits, verifying dependencies, inspecting the ANTHROPIC_API_KEY environment variable, grepping documentation and package metadata, running node syntax checks, and reporting repository statistics. Those are materially different capabilities and resource accesses from the declared purpose, and they are not merely supporting implementation details for follow-up generation. Therefore, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
| `cli/followups-cli.js` | Standalone CLI for testing/scripting |

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · cli/followups-cli.js (reported line 363)May include surrounding context.

js
followups-cli --mode text '[{"user":"What is Docker?","assistant":"Docker is..."}]'

  # Custom model
  followups-cli --model claude-sonnet-4 --context context.json

ENVIRONMENT:
  OPENROUTER_API_KEY   Recommended: Your OpenRouter API key (OpenClaw default)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · handler.js (reported line 167)May include surrounding context.

js
const capabilities = ctx.capabilities || [];
        const useButtons = supportsButtons(channel, capabilities);
        
        // Return prompt that makes the agent generate follow-ups
        return {
          type: 'agent-prompt',
          prompt: FOLLOWUPS_PROMPT,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The initial-release notes describe handler.js as implementing /followups command support, auto-trigger mode, and channel-specific button behavior. Later changelog entries explicitly correct this, stating the real command is /smart-followups and that OpenClaw does not load handler.js as a command handler, so the earlier documentation actively contradicts actual behavior.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 105)May include surrounding context.

Or if using systemd:

bash
sudo systemctl restart openclaw

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rollback section includes a permanent deletion command but does not explicitly warn that it is destructive or advise operators to verify the path before execution. In deployment documentation, omission of such safeguards increases the risk of accidental data loss, especially during incident response or hurried rollback operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quick-start instructs users to place a live API credential directly into shell commands and persist it in ~/.bashrc or ~/.zshrc without warning about plaintext storage, file permissions, shared accounts, backups, or alternative secret-management approaches. While common in developer docs, this increases the chance of credential exposure through dotfile syncing, local compromise, or accidental disclosure when users inspect or share their shell config.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README describes the skill as something users can run via /smart-followups and says the main skill uses OpenClaw-native auth, implying an active runtime handler. But the project structure note explicitly says handler.js is 'not loaded by OpenClaw as a command handler,' which conflicts with the skill's stated operation and creates intent ambiguity about what code actually executes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language triggers are broad enough that ordinary conversation phrases like "give me suggestions" or "what should I ask next?" could unintentionally invoke the skill. In a chat agent, unintended invocation can cause context leakage into follow-up generation, confuse user intent, or create prompt-routing behavior the user did not explicitly request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI sends conversation context to OpenRouter or Anthropic, which may contain sensitive user or assistant content, without any explicit disclosure, consent prompt, or local-only fallback. In a follow-up suggestion tool, users may reasonably assume their conversation is processed locally, so silent transmission to third-party APIs creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents that when autoTrigger: true is enabled, follow-ups appear automatically after every assistant response. Because this changes behavior by injecting additional model-generated content without explicit user invocation, the description should include a clear warning or disclosure about the automatic behavior and how users can disable it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill passively intercepts any standalone '1', '2', or '3' message and rewrites it into a previously stored follow-up question. That changes ordinary user input semantics outside the explicit /followups invocation path, which can cause unintended prompts to be sent to the model and may surprise users who intended a literal numeric reply for some other purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Line L261 lists "Multi-language support (i18n)" as not included future work. For a user-facing conversational skill, this suggests the current implementation may effectively operate in a single language without documented opt-in or user choice, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The header comment says the supported slash commands are '/followups', '/fu', and '/suggestions'. The actual command-recognition list instead includes '/followups', '/fu', '/suggestions', and '/next', while the exported command aliases are 'fu', 'next', and 'suggest', creating active documentation inconsistency about what commands the skill responds to.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code rewrites user-visible input from a numeric response into stored session content without notifying the user at the time of interception. This hidden transformation can undermine user intent and auditability, especially in multi-skill or multi-channel contexts where a bare number may have another meaning.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
cli/followups-cli.js:92

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
BUILD_SUMMARY.md:146

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
CONTRIBUTING.md:108

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
QUICKSTART.md:21

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
UPDATE_SUMMARY.md:248