Back to plugin

Security audit

Agent Knock Knock

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local terminal-control plugin for Codex and Claude Code; it has powerful access, but that access is purpose-aligned and bounded by explicit terminal, approval, and policy checks.

Install this only if you want OpenClaw to control visible local Codex or Claude Code terminals. Run it under an unprivileged OS account, keep tmux/Herdr sockets private, review approval prompts manually, and leave autoApprove disabled unless rules are narrowly scoped to safe commands and exact workspaces.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · templates/openclaw-skills/agent-knock-knock/SKILL.md (reported line 69)May include surrounding context.

md
- Explicit requests to diagnose an ambiguous current Codex foreground: call `agent_knock_knock_identify_foreground({terminal_id})` only from that row's current action. Explain that it types one `/status` command, changes no Store state, and returns a non-authorizing 30-second observation. Never use the result as authority for a later mutation.
- Explicit requests to identify an ambiguous Codex foreground and send one task atomically: use the row's exact `agent_knock_knock_identify_and_send({terminal_id,request})` action. Do not synthesize this path for an ordinary Send or split it into identify-then-send calls.
- Requests to list resumable native threads for an exact terminal: call `agent_knock_knock_list_resumable_threads` with the terminal row's prefilled `terminal_id`.
- Explicit requests to start a new thread or clear context: call `agent_knock_knock_new_thread({terminal_id})` only from an advertised `new_thread` action.
- Explicit requests for low-level recovery of a listed binding conflict: after explicit user confirmation, call only the advertised `agent_knock_knock_reconcile_binding({terminal_id,conflicting_session_id})`. AKK derives its revision and binding fences privately, detaches the stale/conflicting binding without adopting the live thread, and requires a fresh list afterward. Do not use it in place of an advertised follow-current send.
- Explicit requests to resume prior native context: first call `agent_knock_knock_list_resumable_threads`; then call `agent_knock_knock_resume_thread({terminal_id,native_thread_id})` for one `resumable=true` candidate using its complete UUID. For “previous” / “刚才那个”, proceed only when the fresh result advertises `previous.available_actions.resume_thread`; use that exact semantic-ID action and never substitute the newest row. Human-facing numbers and short IDs are resolved privately and are never structured tool arguments.
- Requests to inspect current output or ask what a task is doing: call `agent_knock_knock_status`.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · templates/openclaw-skills/agent-knock-knock/SKILL.md (reported line 41)May include surrounding context.

md
- `/akk respond <turn-selector>: <answer>`: answer a coding-agent question inside a `waiting_for_openclaw` Turn.
- `/akk cancel <turn-selector>`: interrupt the exact Turn without closing its terminal pane.

For human-facing ordinary-send slash forms, a selector may be `codex`, `claude`, `only`, `latest`, or an `@short-ref` returned by `AKK list`. These selectors are only a resolution layer and fail closed when the target is missing or ambiguous. The v30 structured-tool contract never exposes a selector or opaque authority value: the model supplies semantic IDs only. The agent-neutral `terminal_user_explicit_composer_policy` advertises `replace_current_composer_and_submit`; the old Codex-named field is a v28 compatibility alias only. `send({session_id,request})` is strict `session_exact`; `send({terminal_id,request})` is either managed `terminal_follow_current` or user-priority `terminal_user_explicit`, exactly as advertised; the two target fields are mutually exclusive, and both may be omitted only when AKK must prove one unique send-ready pane. Codex and Claude Code `terminal_user_explicit` depend on the exact live terminal/process, a scanned non-blocked approval state, and no proven input-owning questionnaire, editor, menu, history search, or read-only viewer—not ordinary main-Composer visibility, stability, exactness, parsed working activity, existing draft contents, or AKK Store, Turn, Session, transfer, transition, ledger, or ownership. An unreviewed Codex frontend is the narrower exception: physical Send requires a recognized styled Composer before clearing and a fresh empty styled Composer before task text. Profiled Codex 0.154.0/0.155.1 exact collapsed async-question summaries leaves the main Composer sendable; an expanded, clipped, or ambiguous async editor and an active-writer resume viewer remain zero-input boundaries. Both advertise `replace_current_composer_and_submit`: Codex physical fallback sends `C-u` once; Claude Code physical fallback uses a senti
...[truncated 24 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · templates/openclaw-skills/agent-knock-knock/SKILL.md (reported line 114)May include surrounding context.

md
Hard creation failure includes an absent exact terminal, inability to identify its endpoint/process, absence of both a durable exact-task anchor and a read-only screen-status activity path, inability to create/write the durable Watch Store, or uncertain native probe input. Safe read-contract failures may fall back to activity observation only after revalidating the physical endpoint, PID, process incarnation, working directory, and screen-status path; never bypass an unsafe input surface or retry uncertain probe input. Existing identical active observation may return its current `watch_id` instead of failing as a duplicate.

Approval attention is notification-only for every Watch: never call an approval tool for a `watch_id`, send approval keys, or apply `autoApprove`. Native-interaction attention is different. An automatic exact request-bound Watch created by `terminal_user_explicit` unmanaged fallback can, after exact request acceptance and attribution, emit `interaction_required`; call Status with its exact `watch_id`, show the projected question to the user, and use `respond_interaction({watch_id,...})` only when that fresh owner-bound projection advertises `capabilities.respond=true`. A terminal-activity Watch or `interaction_manual_required` callback remains notify-only: tell the user to inspect and answer in the live TUI, and send no interaction input. Each new exact attention fingerprint is notified once while the Watch remains active. Terminal outcomes settle once. The durable outbox uses deterministic notification IDs/idempotency and leased retry, so startup and periodic supervision can safely recover callback delivery after AKK, OpenClaw, or Gateway restart.

The current integrations register the complete capability-handshake-verified semantic AKK tool catalog and list action-contract v30. Structured OpenClaw, Pi, and DeepSeek Harness Lists use compact projection v1 and point here for the static contract; the CLI keeps the complete operator/debug action c
...[truncated 24 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The skill permits a trusted plugin autoApprove policy to independently approve terminal prompts based on configured agent, command vector, and workspace evidence. Even though the model cannot modify the policy and it is default-disabled, any automated approval path around interactive terminal permissions can materially increase the blast radius of prompt-injection, tool misuse, or mistaken command execution if policy scope is too broad or matching is imperfect.

Content

Scanner excerpt · templates/openclaw-skills/agent-knock-knock/SKILL.md (reported line 219)May include surrounding context.

md
Unknown, stale, expired, ambiguous, persistent-permission, replayed, or changed requests must not receive any decision key. If semantic `reject` is not advertised, tell the user to resolve the prompt directly in the terminal; use `agent_knock_knock_cancel` only when the user explicitly intends to interrupt the whole Turn, never as a disguised No choice.

A trusted, default-disabled plugin `autoApprove` policy may independently approve only an exact configured agent, command vector, and canonical root listed in `autoApprove.rules[].workspaces`, backed by current terminal evidence. A rule may list multiple workspace roots. These entries are the only workspace boundary for automatic approval; they do not limit pane discovery or manual control. The model cannot create or modify that policy.

## Terminal Sessions

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly states that previous also accepts the human phrase 刚才那个, which introduces a language-specific interaction path. Under the policy, forcing or embedding a specific language without user opt-in can be a locale-policy issue unless clearly justified as region-specific or optional by locale selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This line treats a Chinese phrase as a first-class request variant alongside English, but the document does not say that language selection is user-driven or that multilingual phrases are generally supported. That can violate language/locale policy by privileging a specific locale without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/codex-process-incarnation.js:14
Evidence
const result = spawnSync(ps, ["-o", "lstart=", "-p", String(pid)], {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/codex-store-adapter.js:367
Evidence
const child = spawn("sqlite3", args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/command-json-callback-transport.js:40
Evidence
((executable, arguments_, spawnOptions) => spawnSync(executable, arguments_, spawnOptions));

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/doctor-capabilities.js:45
Evidence
const result = spawnSync(executable, args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/herdr-terminal-control-provider.js:1155
Evidence
const result = spawnSync(command, args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/install-doctor-command-adapter.js:187
Evidence
const linked = spawnSync(openclawBin, ["plugins", "install", "--link", ...capabilityConsentArgs, root], {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/openclaw-callback-transport.js:580
Evidence
((command, args, options) => spawnSync(command, args, options));

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/openclaw-doctor.js:189
Evidence
const result = spawnSync(executable, args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/semantic-tool-relay.js:30
Evidence
const spawned = spawnSync(process.execPath, [binPath, ...cliArgs], {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/terminal-control-provider.js:995
Evidence
const result = spawnSync(command, args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/terminal-process-source.js:210
Evidence
const result = spawnSync(command, args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/terminal-runtime-cli-adapter.js:173
Evidence
const result = spawnSync(claudeExecutable, ["agents", "--json", "--all"], {