Back to skill

Security audit

scenique-context-frame

Security checks for vulnerabilities and agentic risk

Overview

This context-frame demo has review-worthy issues: its launcher can run an unexpected file outside the package, and the demo can silently save conversation summaries to a fixed root workspace path.

Review this skill before installing or running it. The main concern is not that it uses Python or files, but that its launcher can execute a file outside the reviewed package and the demo can retain conversation snippets without telling the user. A safer version should load only packaged code, disclose or disable persistence by default, use a user-scoped configurable storage path, and pin or remove mutable CLI publishing commands.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T07 · Tool Hijacking and Spoofing

Error
Location
preload.py:5
Finding

Execution of Python Code Outside the Skill Package

Content
View full analysis
1 else 'demo' if p.exists(): import runpy runpy.run_path(str(p), run_name='__main__') ``` ### Technical Analysis `preload.py` is located in the Skill package directory, but `Path(__file__).resolve().parents[1]` resolves to the parent of that directory. Consequently, the launcher does not execute the packaged `context_sim.py`; it searches for and executes a different file named `context_sim.py` outside the reviewed package. The file is executed through `runpy.run_path(..., run_name='__main__')`, which gives it normal Python code-execution capabilities under the privileges of the user running the Skill. There is no verification of the target file's ownership, integrity, origin, or containment within the package. This creates a local file-planting and tool-hijacking condition. The external file can impersonate the expected implementation while executing arbitrary attacker logic. ### Attack Path 1. An attacker obtains write access to the directory immediately above the Skill package. 2. The attacker places a malicious file named `context_sim.py` in that directory. 3. A user or automation invokes `python3 preload.py` as documented in `SKILL.md`. 4. `preload.py` resolves the attacker's file rather than the packaged implementation. 5. `runpy.run_path` executes the malicious file as `__main__`. 6. The payload runs with all filesystem, process, credential, and network permissions available to the invoking account. ### Impact Assessment Successful exploitation provides arbitrary Python code execution with the privileges of the account running the Skill. Depending on those privileges, an attacker could read or modify access ...[truncated 386 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
context_sim.py:35
Finding

Unsafe Persistence of Conversation Content to a Fixed Privileged Path

Content
View full analysis
=2 else None if prev: entry = {'frame_id': prev['id'], 'title': prev['title'], 'summary': ' '.join(prev['history'])[:400]} try: with open(pending_path,'r') as pf: data=json.load(pf) except Exception: data=[] data.append(entry) with open(pending_path,'w') as pf: json.dump(data,pf) except Exception: pass ``` ### Technical Analysis When a topic switch is detected, the implementation writes conversation-derived titles and summaries to the hardcoded path `/root/.openclaw/workspace/context_frames_pending.json`. The persistence operation has several security weaknesses: - Persistence occurs implicitly rather than through an explicit user-controlled option. - The path is hardcoded to a root workspace instead of a configurable, user-scoped data directory. - Standard `open()` calls follow symbolic links. - The code does not verify file ownership, file type, or containment within a trusted directory. - No restrictive file mode is explicitly applied. - The read-modify-write process is not protected by file locking. - The destination is overwritten directly rather than through an atomic replacement. - Broad exception handlers silently suppress malformed-file, permission, and write failures. If the process is privileged and an attacker can manipulate the target path or workspace directory, a pre-created symbolic li ...[truncated 1962 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:18
Finding

Unpinned Package Execution in Publishing Instructions

Content
View full analysis
(web upload recommended for first-time publish to accept license). ``` ### Technical Analysis The documentation instructs publishers to execute `npx clawhub` without specifying a package version or integrity value. Depending on the local `npx` cache and configuration, this can retrieve and execute the package version currently resolved by the configured package registry. Because the command is not version-pinned, its effective code can change after the Skill has been reviewed. A compromised package release, registry account, registry configuration, or dependency chain could therefore execute unexpected code on a publisher's system. This command is optional publishing guidance and is not automatically executed by the Skill, which limits the immediate runtime risk. ### Attack Path 1. A user chooses the documented CLI publishing method. 2. The user runs `npx clawhub publish `. 3. `npx` resolves an uncached or updated package through the configured registry. 4. A compromised or unexpectedly changed package version is downloaded. 5. Package lifecycle or CLI code executes under the user's account. 6. The malicious package can access resources available to that account, including the package contents, local files, environment variables, and publishing credentials. ### Impact Assessment If the resolved package or its dependency chain is malicious, it can execute code with the publisher's local privileges. This may expose source artifacts, registry credentials, environment variables, or other files accessible to the publisher. The finding does not establish that the named package is currently malicious. The risk arises from executing an unpinned, mutable supply-chain component ...[truncated 5 chars]
Remediation
View remediation
`. 2. Document the expected registry and trusted publisher identity. 3. Verify package provenance, signatures, and integrity metadata where supported. 4. Prefer a locally installed dependency governed by a lockfile and integrity hashes. 5. Run publishing tooling in an isolated environment with only the minimum required files and credentials. 6. If the web-upload workflow is the preferred and trusted method, remove the unpinned CLI alternative or clearly mark it as requiring independent package verification. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The documentation instructs users to run npx clawhub without pinning an explicit package version, which can cause execution of whatever version is current at install time. If the upstream package is compromised, updated with unsafe behavior, or affected by a dependency-chain attack, users testing or publishing the skill could execute unreviewed code on their system.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file is labeled as a simple simulation/demo, but it silently persists conversation-derived summaries to a real filesystem path under /root/.openclaw/workspace/context_frames_pending.json. This mismatch increases the risk that operators or users will underestimate the privacy and security implications, leading to unexpected retention of potentially sensitive conversational data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes summaries derived from conversation history to disk without any warning, consent, or visibility to the user. Because the stored content may include sensitive prompts, business data, or personal information, silent persistence creates confidentiality and compliance risks, especially in an agent context where users may not expect logging to a root-owned workspace.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.