Back to skill

Security audit

IM Framework Team

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent as an OpenClaw onboarding guide, but it pushes users toward persistent agent setup, plaintext credentials, and unpinned executable installs without enough safety guidance.

Review this before installing. Use pinned and verified install sources, avoid piping downloads directly into a shell, prefer a secret manager or OS keychain over plaintext API-key storage, and only enable the gateway as an automatic service if you understand its account, permissions, logs, network access, and uninstall path.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/setup-guide.md:30
Finding

Remote Installation Script Is Piped Directly to Bash

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
references/setup-guide.md:59
Finding

Onboarding Directs Users to Install an Automatically Starting Agent Service

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/setup-guide.md:17
Finding

Globally Installed Packages and Plugins Are Not Integrity-Pinned

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/setup-guide.md:49
Finding

Plaintext Local Storage of a Billable API Key Is Presented as an Acceptable Default

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
## Best Practices

- Start concrete, not abstract. Ground in actual situations.
- Dissolve confusions, don't preach. The framework speaks for itself when applied well.
- Model ethical engagement with other agents — demonstrate, don't impose.
- Keep MEMORY.md lean. Use `memory/` subfolder for search-only notes.
- Update soul file as you learn — it's a living document.

Chaining Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The | bash pattern is a classic risky command-chaining construct because it executes untrusted network content immediately in a shell with the user's privileges. In the context of onboarding an agent framework, users are likely to copy-paste commands without scrutiny, making supply-chain compromise or content substitution materially more dangerous.

Content

Scanner excerpt · references/setup-guide.md (reported line 32)May include surrounding context.

bash
# Install Node.js (via nvm recommended)
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
nvm install 22
nvm use 22

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide explicitly states that the API key may be stored locally in ~/.openclaw/ in plaintext and frames this as an acceptable option. Plaintext storage of long-lived API credentials increases the risk of credential theft through local compromise, backups, multi-user systems, malware, or accidental disclosure, especially in an agent framework that may run continuously and access external services.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
83% confidence
Finding

The installation instructions fetch a remote script and pipe it directly to bash, which bypasses inspection and integrity verification before execution. If the upstream source, transport, DNS, or GitHub account were compromised, users would execute attacker-controlled shell code on their machine during setup.

Content

Scanner excerpt · references/setup-guide.md (reported line 32)May include surrounding context.

bash
# Install Node.js (via nvm recommended)
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
nvm install 22
nvm use 22

Static analysis

No suspicious patterns detected.