Back to skill

Security audit

Switch Modes

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate model-switching purpose, but it can persistently rewrite the global OpenClaw model setting from ambiguous words while giving inconsistent scope disclosure.

Review before installing. This skill should only be used if you are comfortable with persistent global OpenClaw model changes that may affect cost and future sessions. Prefer using explicit slash commands, confirm before any write, back up ~/.openclaw/openclaw.json, and avoid exposing the full config or API keys in chat, logs, or errors.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

Ambiguous Commands Can Trigger Global Modification of Credential-Bearing OpenClaw Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · REFERENCE.md (reported line 131)May include surrounding context.

md
If `switch-modes.json` gets corrupted:

1. Delete it: `rm ~/.openclaw/workspace/switch-modes.json`
2. Run `/modes setup` to recreate
3. Or manually create with valid JSON structure (see above)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reference explains direct modification of the global OpenClaw config before prominently warning that the change affects all sessions. Users may reasonably assume the change is local to the current conversation, leading to cross-session behavior changes, unexpected cost increases, or weaker models being selected for unrelated sensitive work.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
77% confidence
Finding

The skill persists mode configuration in workspace and global config files, and the documentation encourages recreating or updating those files without discussing lifecycle, rollback, or cleanup. Persistent state can silently influence future sessions and users, making behavior changes durable beyond the immediate task.

Content

Scanner excerpt · REFERENCE.md (reported line 111)May include surrounding context.

md
2. Check `~/.openclaw/workspace/switch-modes.json` exists and is valid JSON
3. Check `~/.openclaw/openclaw.json` was actually updated
4. Verify file permissions (should be readable/writable)
5. Try `/modes setup` again to recreate config

**Common causes:**
- JSON syntax error in config file

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide says the agent 'scans user message for mode keywords' but does not clearly constrain when switching should occur, what exact commands are authoritative, or what contexts must be excluded. That ambiguity can cause unintended model changes from incidental text, quoted content, or prompt-injected instructions, altering agent behavior and cost/security posture without explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill triggers on standalone words like "eco", "balanced", "smart", and "max", which are common in normal conversation and can cause accidental activation. Because this skill performs configuration changes that persist by rewriting the OpenClaw model setting, overly broad matching can lead to unintended model switches, cost changes, or degraded performance without clear user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill instructs the agent to write directly to ~/.openclaw/openclaw.json, creating persistent session configuration changes. Persistent modification is risky because an accidental or mis-triggered activation will outlive the current exchange and silently alter future model behavior, including potentially increasing cost or changing trust/performance characteristics.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

  1. Update OpenClaw config:

    • Read current config: ~/.openclaw/openclaw.json
    • Update the model field with the new model ID
    • Write back to ~/.openclaw/openclaw.json
  2. Confirm to user:

    text

Static analysis

No suspicious patterns detected.