Back to skill

Security audit

Skill Designer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed assistant for designing OpenClaw skill packages and does not show hidden installation, persistence, credential access, exfiltration, or destructive behavior.

Install this if you want an agent to help design OpenClaw skills. Be aware it may create generated files in an output directory after you confirm the design, and review any generated skill before installing it into an agent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad phrases like '创建 skill', '做一个技能', and '加一个能力', which can appear in ordinary discussion and cause accidental activation. Unintended invocation is risky here because the skill is designed to generate installation-ready artifacts and may steer the conversation into producing files or instructions the user did not intend to request.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
description: 通过需求收口帮用户从零设计一个 OpenClaw agent skill。逐步收集目标、输入、输出、过程控制,确认后输出完整的 skill 文件包(SKILL.md + 安装指南)。产出是文件,不替用户执行安装。当用户说"创建 skill"、"做一个技能"、"加一个能力"、"帮我把 XXX 变成 skill"时触发。
---

# Create Skill

通过需求收口帮用户设计 skill,输出完整可安装的 skill 文件包。

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
description: 通过需求收口帮用户从零设计一个 OpenClaw agent skill。逐步收集目标、输入、输出、过程控制,确认后输出完整的 skill 文件包(SKILL.md + 安装指南)。产出是文件,不替用户执行安装。当用户说"创建 skill"、"做一个技能"、"加一个能力"、"帮我把 XXX 变成 skill"时触发。
---

# Create Skill

通过需求收口帮用户设计 skill,输出完整可安装的 skill 文件包。

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly claims it will only output a file package and will not modify the environment, but later instructs writing generated files into a local working directory. That creates a mismatch between declared behavior and actual behavior, which can lead the hosting agent to perform filesystem writes when the user expected a purely advisory response.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.