Back to skill

Security audit

nginx-explorer

Security checks for vulnerabilities and agentic risk

Overview

This skill is disclosed as an nginx tool explorer, but it also normalizes downloading, installing dependencies for, and executing remote tools without strong trust, verification, or approval controls.

Review this skill carefully before installing. Only use it with a trusted, HTTPS-protected nginx host, and do not let it execute downloaded tools or install dependencies unless a human verifies the source, checksum or signature, and runs the tool inside a disposable sandbox with no sensitive credentials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:113
Finding

Unverified Remote Tool Download and Execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:173
Finding

Remote Dependency Manifest Controls Package Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:12
Finding

Plaintext HTTP Guidance and Disabled TLS Verification Default

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:197
Finding

Untrusted Remote README Content Drives Agent Decisions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The guide instructs users to run a destructive recursive delete command against a path under the home directory without any safety warning, path validation, or backup guidance. Although intended for legitimate uninstall, such commands are risky because copy/paste mistakes, variable expansion errors, or path edits can permanently delete local data.

Content

Scanner excerpt · INSTALLATION.md (reported line 180)May include surrounding context.

手动卸载

bash
# 移除技能目录
rm -rf ~/.openclaw/skills/nginx-explorer

# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The guide instructs users to run a destructive recursive delete command against a path under the home directory without any safety warning, path validation, or backup guidance. Although intended for legitimate uninstall, such commands are risky because copy/paste mistakes, variable expansion errors, or path edits can permanently delete local data.

Content

Scanner excerpt · INSTALLATION.md (reported line 180)May include surrounding context.

手动卸载

bash
# 移除技能目录
rm -rf ~/.openclaw/skills/nginx-explorer

# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command recursively and forcibly deletes a workspace path and could cause unintended data loss if the placeholder path is replaced incorrectly or the command is run from copied documentation without careful editing. In a skill-installation guide, destructive filesystem operations are more dangerous because users may execute them verbatim during setup or removal workflows.

Content

Scanner excerpt · INSTALLATION.md (reported line 183)May include surrounding context.

md
rm -rf ~/.openclaw/skills/nginx-explorer

# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer

# 从配置中移除
# 编辑 ~/.openclaw/openclaw.json,删除 nginx-explorer 条目

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This command recursively and forcibly deletes a workspace path and could cause unintended data loss if the placeholder path is replaced incorrectly or the command is run from copied documentation without careful editing. In a skill-installation guide, destructive filesystem operations are more dangerous because users may execute them verbatim during setup or removal workflows.

Content

Scanner excerpt · INSTALLATION.md (reported line 183)May include surrounding context.

md
rm -rf ~/.openclaw/skills/nginx-explorer

# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer

# 从配置中移除
# 编辑 ~/.openclaw/openclaw.json,删除 nginx-explorer 条目

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as an explorer for nginx-served directories, but its instructions extend into downloading and executing remote tools. That materially increases the trust boundary from passive discovery to arbitrary code execution from remotely hosted content, which could compromise the host or data if the server or content is malicious or tampered with.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes downloading and executing remote tools without a prominent, user-facing warning that this can alter the system and expose data. The absence of clear warnings increases the chance that users treat the workflow as routine exploration rather than a high-risk code-execution action.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These examples instruct users to fetch a script from the configured nginx server, mark it executable, and run it locally. A discovery-oriented skill should not normalize direct execution of remote code, because a malicious or compromised server can deliver arbitrary payloads that immediately execute with the agent's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These instructions write a downloaded file to disk, make it executable, and run it, but do not provide a prominent warning about persistence, privilege implications, or malicious payload risk. In practice, that omission lowers operator caution and can lead to unsafe execution of unreviewed remote code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This workflow goes beyond exploration by downloading code and dependencies, then executing both installed packages and the fetched program. That creates a supply-chain and remote-code-execution path through untrusted nginx-hosted content, with added risk from dependency installation modifying the environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow installs dependencies and runs a downloaded program without clearly warning that package installation can execute arbitrary setup logic and alter the environment. This creates both immediate code-execution risk and longer-term integrity risk from modifying the system with untrusted packages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown provides rm -rf commands for manual uninstallation, which are irreversible file deletions. In this section there is no adjacent warning or caution about permanent data removal or verifying the target path before execution.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALLATION.md (reported line 191)May include surrounding context.

md
## 支持

- 查看技能文档:`cat ~/.openclaw/skills/nginx-explorer/SKILL.md`
- 访问 OpenClaw 文档:https://docs.openclaw.ai
- 加入社区:https://discord.com/invite/clawd

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README frames the skill as directory exploration, but its documented behavior explicitly includes downloading and executing remote tools. That creates a capability expansion from discovery to arbitrary code execution from an external server, which is a meaningful security risk if the nginx host, its contents, or transport are compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents downloading and executing external tools as a feature but does not give a strong user-facing warning that this is equivalent to running remote code of uncertain integrity. In this skill context, that omission is especially dangerous because the content is fetched from a configurable nginx server and may be treated as trusted by default.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation normalizes executing downloaded tools as part of problem solving even though the skill's stated purpose is exploration/discovery. In context, this makes the agent more likely to escalate from browsing remote content to running untrusted code, increasing the chance of compromise, data exfiltration, or system abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad phrases like when conventional approaches fail or complex processing is required, which can cause the skill to activate in many situations without clear limits. Because this skill can lead to downloading and executing remote tools, ambiguous invocation criteria materially increase unsafe use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented decision flow tells the agent to download and apply discovered tools to solve problems, which exceeds the declared purpose of exploration. Scope expansion like this is dangerous because users may invoke an apparently low-risk discovery skill without realizing it can escalate into executing arbitrary third-party tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This troubleshooting step triggers an outbound network request to the configured NGINX endpoint. Although expected in context, the markdown does not explicitly disclose that the command contacts the remote server and may expose the configured URL in shell history or logs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README claims safeguards such as trusted servers, script review, and user confirmation, but the documented quick-start and workflow present direct execution without any enforced controls. This mismatch can create a false sense of safety and lead operators or agents to run external tools without the promised validation steps.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALLATION.md:180