Back to skill

Security audit

imesh

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed local mesh/gateway operator, with manageable risk around enabling authentication before exposing execution endpoints.

Install only from a source you trust, keep the gateway bound to 127.0.0.1 for testing, set a strong OPENCLAW_PSK, and enable OPENCLAW_AUTH_REQUIRED=true before exposing execution endpoints beyond a private single-user local environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

Check gateway health

bash
curl http://127.0.0.1:8000/api/v1/health

List available skills

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
93% confidence
Finding

The documented default OPENCLAW_AUTH_REQUIRED=false leaves gateway execution endpoints unauthenticated unless the operator explicitly enables API-key enforcement. Even though the skill advises using 127.0.0.1 and disabling WAN by default, this remains risky because users may later bind to 0.0.0.0, expose the port through container/VM networking, or run on multi-user systems where unauthenticated local access is still meaningful.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
export OPENCLAW_DEFAULT_PORT=8765
export OPENCLAW_MDNS_ENABLED=true
export OPENCLAW_WAN_ENABLED=false
export OPENCLAW_AUTH_REQUIRED=false          # set true to enforce API keys
export OPENCLAW_GATEWAY_DB_PATH=./openclaw_gateway.db
export OPENCLAW_IDENTITY_KEY_PATH=./.openclaw_identity.pem
export OPENCLAW_PEER_TTL_SECONDS=120

Static analysis

No suspicious patterns detected.