Back to skill

Security audit

openclaw-clawhome-cli

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate Clawhome messaging connector, but its installer runs mutable remote packages and immediately loads an unpinned plugin into OpenClaw.

Review before installing. Use only if you trust the Clawhome package publisher and OpenClaw plugin source, prefer a pinned reviewed version, verify the package/plugin provenance, and treat `channelSecret` like a password. Run the Gateway with least privilege because the installed plugin will persist and process messaging traffic.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Mutable Latest Release Executed Through npx

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
cli.mjs:6
Finding

Unpinned OpenClaw Plugin Installation and Immediate Gateway Loading

Content
View full analysis
Remediation
View remediation
"; ``` - Verify the downloaded plugin against trusted integrity metadata or a cryptographic signature before installation. - Include the plugin source and its lockfile in the security-review scope. - Require explicit confirmation after displaying the resolved package version, source, publisher, and integrity value. - Do not restart the Gateway automatically until plugin verification succeeds. - Run the Gateway and plugins under a dedicated least-privileged account with restricted filesystem and network access. - Protect channel secrets through an appropriate secret store and ensure plugins receive only the credentials required for their declared function. - Maintain an allowlist of approved plugin package names, versions, and integrity hashes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to execute an npm package via npx using @latest, which fetches and runs whatever code is currently published under that package name. This creates a supply-chain risk: a compromised maintainer account, malicious update, or dependency hijack could result in arbitrary code execution on the user's system during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to set a channelSecret credential but provides no warning about secure handling, storage, rotation, or avoiding disclosure in logs, screenshots, and shared shell history. In a messaging integration, exposure of this secret could let an attacker impersonate the agent, send unauthorized actions, or access the associated channel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user-facing strings throughout the installer and help output are written only in Chinese, including errors, status messages, and usage instructions. This imposes a specific language on all users without any opt-in, fallback, or indication that the tool is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The help text instructs users to run the package via npx -y @clawhome/openclaw-clawhome-cli without pinning a specific version. That means execution will fetch and run whatever version is current at install time, which creates a supply-chain risk if the package is later compromised, maliciously updated, unpublished/replaced, or unexpectedly changed. In this skill context, the command is especially sensitive because the script then performs plugin installation and shell-based command execution on the user's machine.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli.mjs:18