Back to skill

Security audit

Knowledge Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent consulting-agent purpose, but it needs review because it recommends broad Feishu, web, browser, and file-write access and ships an unsafe setup script.

Review before installing. Prefer an allowlisted Feishu group with explicit participant disclosure, avoid the open all-groups policy, pin or verify any search skill dependency, and do not run setup-consultant.sh with untrusted agent IDs, domains, or workspace paths until it validates and escapes inputs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-consultant.sh:34
Finding

Unsanitized Template Substitution and Workspace Path Injection

Content
View full analysis
"$DST" ``` ### Technical Analysis The script places the user-controlled `AGENT_ID`, `DOMAIN`, and derived `WORKSPACE` values directly inside executable `sed` expressions. The values are not escaped for replacement-string metacharacters such as `&` and backslashes, expression delimiters such as `/` and `|`, or embedded newline characters. At minimum, ordinary input containing these characters can corrupt generated files or cause `sed` to terminate with an error. Under GNU `sed`, a crafted value containing expression delimiters and newlines can terminate the intended substitution and introduce an additional command. The GNU `sed` `e` command can execute a shell command, making local command execution possible when untrusted values reach this script. The unvalidated `AGENT_ID` is also incorporated into: ```bash WORKSPACE="$BAS ...[truncated 1794 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Canonicalize `BASE` and `WORKSPACE`, then verify that the workspace remains beneath the approved base directory. 3. Reject existing destination directories by default. Require an explicit `--force` option before overwriting files. 4. Do not construct `sed` programs from untrusted values. Use a template renderer that passes replacement values strictly as data. 5. If `sed` must be retained, escape backslashes, ampersands, delimiters, carriage returns, and newlines before substitution. Do not rely on shell quoting alone. 6. Generate files in a private temporary directory created with `mktemp -d`, apply restrictive permissions, validate the output, and move it atomically into place. 7. Add automated tests covering slashes, ampersands, backslashes, newlines, Unicode, traversal strings, and pre-existing destinations. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:122
Finding

Unpinned and Unverified External Search Skill

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/feishu-delivery.md:9
Finding

Overly Broad Feishu Group Policy Processes Messages Without Explicit Invocation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README uses broad trigger phrases such as "knowledge agent" and general questions about turning expertise into an automated consulting service, which can cause this skill to activate for ordinary user requests that are not specifically asking to install or use this skill. Over-broad invocation increases the chance of unintended context injection, workflow hijacking, or the skill influencing unrelated conversations in ways the user did not expect.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs users to install and rely on a network-capable search skill and to configure external Feishu delivery, but it does not declare an explicit tool scope or allowed-tools policy. That mismatch weakens least-privilege controls and can cause the agent to gain broader network access than reviewers or operators expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger text includes broad activation language such as handling 'any question' about turning expertise into an automated consulting service. Overly broad routing can cause this skill to activate in adjacent contexts, increasing the chance that users receive operational instructions or security-sensitive setup guidance when a narrower skill would be more appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to hide its platform identity, internal files, and system structure from clients at all times. In a paid consulting context, this reduces transparency, can mislead users about the nature of the service, and may obstruct informed consent, auditing, or safe escalation when the system is acting autonomously.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/feishu-delivery.md (reported line 5)May include surrounding context.

md
## Overview

The delivery model: Create a Feishu group → Add the Agent bot → Clients join and ask questions directly (no @ needed).

## No-@ Reply Configuration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented 'open' group policy causes the bot to process and respond to every message in every group it joins, which materially increases the chance of collecting or exposing sensitive business or personal information without participants realizing the bot is active. The file notes the bot will respond in all groups, but it does not pair that recommendation with strong privacy warnings, consent requirements, or guidance to avoid using this mode in mixed-purpose groups.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The onboarding flow instructs operators to place paying clients into a group where the agent answers automatically, but it does not require an explicit notice that messages are being processed by an AI system. In a paid consulting context, this omission can mislead users about who is handling their data and raises privacy, consent, and trust risks, especially if users share sensitive business information.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/knowledge-layers.md (reported line 7)May include surrounding context.

md
**Every consulting agent MUST have its own dedicated workspace.** OpenClaw loads `AGENTS.md` from the workspace root — sharing a workspace with another agent means both read the same file, causing identity confusion.

Create a dedicated agent first: `openclaw agents add <agent-id>`, which generates an isolated workspace at `~/.openclaw/workspace-<agent-id>/`.

## Why Layering Matters

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance explicitly instructs the agent to hide its platform/model identity and redirect when asked about system details, which creates a deceptive-response policy rather than a safety control. In a paid consulting context, this can undermine user trust, interfere with informed consent, and normalize concealment that may also frustrate incident response or compliance review.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-consultant.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# Create workspace directory structure for a knowledge consultant Agent
#
# Usage:
#   ./setup-consultant.sh <agentId> <domain> [workspace-base]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template explicitly grants write capability to the agent but provides no requirement for user confirmation, scope restriction, or safety checks before modifying files. In a client-facing consulting agent, this can enable unintended or prompt-induced file changes to agent configs, knowledge files, or workspace content, especially since the template also includes broad browser/search tooling and a writable workspace path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.