Back to skill

Security audit

OpenClaw Claude Codex Workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent multi-model coding workflow, but it asks users to persist API keys and runs powerful model CLIs without technical containment.

Install only if you are comfortable giving the configured model CLIs the same local repository, environment-variable, and credential access as your user account. Prefer temporary or secret-manager based API keys, run it in a dedicated workspace or container, review dry-run output and diffs before execution, and do not include secrets in .claude artifacts or commits.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ccg_orchestrator.sh:76
Finding

Model executors run without enforced filesystem or privilege boundaries

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/ccg_orchestrator.sh:49
Finding

Repository cleanliness check does not detect untracked files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
- `scripts/ccg_orchestrator.sh --dry-run` 可快速排查参数;若脚本报 “缺少命令”,按 Quick Start 安装 CLI。
- 遇到模型超时:按 references/model-routing.md 的 fallback 重新分配,记录在 `.claude/log_*`。
- Claude/Codex/Gemini 均不得直接推送,必须由 Codex 在本地执行 `git commit`/`git push`。
- 禁止执行用户未授权的 destructive 命令(`git reset --hard`, `rm -rf` 等);若需求确实需要,必须在 OPSX 备注并得到显式同意。
- 任何自动生成的 patch 在合并前由人类或 Claude Review 二次比对。

## 附加参考

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly tells users to export long-lived API keys in their shell profile so downstream scripts inherit them, but it gives no warning about persistence, accidental disclosure, or safer alternatives. Persisting secrets in shell startup files increases the chance of credential leakage through dotfile syncing, backups, shared accounts, terminal history, or later subprocess exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

该文件以中文编写并作为通用“模型路由指南”呈现,但没有说明这是特定区域/团队要求,也没有提供语言选择或用户 opt-in。根据规则,强制特定语言而无选择或正当限定,属于自然语言层面的语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file title and all procedural instructions are written entirely in Chinese, which effectively imposes a language choice on users of the skill workflow. The document does not offer an alternative language, opt-in, or explain that the workflow is intentionally region- or team-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script includes its primary user instructions entirely in Chinese, and additional user-facing runtime messages throughout the file are also Chinese-only. That creates a language/locale policy issue because the skill enforces a specific language without any user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.