Back to skill

Security audit

Chat Group Behavior

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for group chat participation, but it broadens group message access and can erase session history without enough scoping or safeguards.

Review this skill carefully before installing. It should only be used if you are comfortable with the agent editing openclaw.json, temporarily opening group message delivery, and scheduling a close job. Safer use would require saving and restoring the exact prior groupAllowFrom value, getting explicit owner approval before config or transcript changes, and backing up or using a supported reset flow instead of directly clearing session transcripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:28
Finding

Platform-Wide Group Sender Filter Is Broadened Without Restoration

Content
View full analysis
.groupAllowFrom` to `["*"]` so all group members' messages are delivered. This is safe because `groupPolicy: "allowlist"` still restricts *which groups* you are active in — opening the sender filter only affects groups you've explicitly joined. Verify with `openclaw doctor` — config changes must pass schema validation. ``` The corresponding cleanup instructions only restore the group-specific mention requirement: ```markdown **Step 5 — Set a closing cron job** Create a one-shot cron job (`kind: "at"`) for the parsed duration. When it fires: patch `requireMention` back to `true` for this group in `openclaw.json`, then send a brief goodbye. The gateway hot-reloads and the gate closes — no owner action needed. ``` ### Technical Analysis The skill instructs the agent to replace the platform-level `channels..groupAllowFrom` setting with the wildcard value `["*"]`. This is broader than the group-specific `requireMention` change used to join a single conversation. Neither the timed-close procedure nor the early-close procedure records and restores the previous `groupAllowFrom` value. They only restore `requireMention` for the selected group. Consequently, the sender filter can remain broadly open after the requested participation window ends. Schema validation through `openclaw doctor` can confirm that the configurati ...[truncated 1769 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:80
Finding

Unsafe Session Transcript Clearing Can Destroy Unrelated State and Audit History

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
When the owner @mentions you in a group chat, follow these steps in order.

**Step 1 — Capture context**

From the inbound message metadata: platform (e.g. `whatsapp`, `signal`), group ID (the `chat_id` / `from` field), and duration (parse from the owner's message — default 30 minutes if unspecified).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to patch live configuration in openclaw.json and later advises clearing a session transcript file, but it does not require any explicit confirmation or warning about the operational and data impacts of those actions. In a security-sensitive agent environment, silent config mutation and transcript deletion can alter access controls, affect message routing, and destroy audit/debug history without the owner's informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs changing groupAllowFrom to ["*"], which broadens message delivery from only the owner to all group members, yet it frames this as 'safe' without any user-facing privacy or exposure warning. This materially expands who can send content to the agent in active groups, increasing prompt-injection surface, unintended data exposure, and the chance the agent processes untrusted group content under elevated trust assumptions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.