Back to skill

Security audit

Manifest

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent setup guide for a Manifest OpenClaw routing plugin, with notable but disclosed high-impact request-routing and cloud trust-boundary considerations.

Prefer local mode for sensitive workloads unless you have reviewed Manifest's privacy and security documentation. Before using cloud mode, confirm what prompts, responses, metadata, costs, and tokens are transmitted, how long they are retained, and how the API key is stored or rotated.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unverified Third-Party Plugin Installation and Activation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–22 and 29–31
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

The documented setup procedures install a third-party plugin through the OpenClaw plugin registry and activate it by restarting the gateway.

bash
openclaw plugins install manifest@5.28.5
openclaw config set plugins.entries.manifest.config.mode local
openclaw gateway restart
bash
openclaw plugins install manifest@5.28.5
openclaw config set plugins.entries.manifest.config.apiKey "mnfst_YOUR_KEY"
openclaw gateway restart

Technical Analysis

The audited project contains only documentation and publication metadata; it does not include the source code of the installed manifest@5.28.5 plugin, an artifact checksum, or a signature-verification procedure. Consequently, the executable component activated by these instructions cannot be verified from the audited package.

Pinning the dependency to version 5.28.5 reduces exposure to unintended upgrades, but it does not independently authenticate the downloaded artifact. Security still depends on the integrity of the plugin registry, the publisher account, the distribution infrastructure, and the referenced release.

The plugin is described as routing every LLM request and collecting usage information. This places the installed dependency in a sensitive request-processing position. If the distributed artifact were compromised or substituted, malicious code could execute when the OpenClaw gateway loads the plugin.

Attack Path

  1. An attacker compromises the plugin publisher account, registry, distribution infrastructure, or the published manifest@5.28.5 artifact.
  2. A user follows the instructions in SKILL.md and runs openclaw plugins install manifest@5.28.5.
  3. OpenClaw retrieves and installs the compromised dependency without any documented checksum or signature verification.
  4. The user restarts the gateway as instructed.
  5. The compromi ...[truncated 1063 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the reviewed plugin source code in the auditable package, or link to an immutable source revision corresponding exactly to version 5.28.5.
  2. Publish a cryptographic checksum or signed provenance statement for the plugin artifact and add explicit verification steps before installation.
  3. Use a trusted, authenticated package registry and enforce signature verification in the OpenClaw installation process where supported.
  4. Generate and retain a software bill of materials for the plugin and its transitive dependencies.
  5. Run the plugin with least privilege, restricting filesystem access, outbound network destinations, environment variables, and access to unrelated credentials.
  6. Clearly document which request fields and telemetry are transmitted in cloud mode, including destinations, retention periods, redaction behavior, and deletion controls.
  7. Store the API key using OpenClaw's protected secret mechanism rather than exposing it through command history or plaintext configuration, where supported.
  8. Review and verify the downloaded artifact before restarting the gateway, and establish a rollback procedure for compromised releases.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The cloud setup instructs users to configure a remote API key and use the hosted service, but it does not clearly warn that prompts, metadata, usage, and potentially sensitive request content may be sent to a third-party service. In a routing and observability plugin, this omission is security-relevant because users may enable cloud mode during evaluation or production without understanding the data exposure and trust boundary change.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.