Back to skill

Security audit

Slap Detector

Security checks for vulnerabilities and agentic risk

Overview

The skill’s slap-detection behavior is mostly coherent, but it asks users to run an external MCP server with sudo root privileges without explaining or limiting that authority.

Review before installing. Only use this if you trust the `slap-your-openclaw` binary and understand why it needs sudo; prefer a version that runs unprivileged or grants only narrowly scoped hardware access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:12
Finding

Root-Privileged MCP Server Violates Least-Privilege Boundaries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-19
Vulnerability Type: Privilege escalation through unnecessarily privileged service execution
Risk Level: High

Vulnerable Code

json
{
  "slap-detector": {
    "command": "sudo",
    "args": ["slap-your-openclaw", "mcp"]
  }
}

Technical Analysis

The documented MCP configuration launches the entire slap-your-openclaw process through sudo. This places all MCP server functionality within a root-privileged execution context, although the declared purpose is limited to monitoring accelerometer events and adjusting detector sensitivity.

The configuration does not use an absolute path for slap-your-openclaw, provide executable integrity validation, restrict the privileged operation to a narrow hardware-access helper, or explain why the complete server requires root privileges. Consequently, any vulnerability or malicious behavior in the executable would operate with privileges beyond those ordinarily required by the stated task.

Actual execution remains subject to the host's sudo policy and authorization requirements. However, on a system where the command is authorized—particularly through a passwordless or cached sudo session—the configuration creates a direct path to privileged code execution.

Attack Path

  1. The user installs or configures the Skill according to the documented prerequisite.
  2. The MCP launcher invokes sudo slap-your-openclaw mcp.
  3. The system resolves and executes the slap-your-openclaw binary, subject to the applicable sudo policy and command-resolution environment.
  4. An attacker who has compromised, replaced, or otherwise gained control of that executable—or who exploits a code-execution vulnerability in the MCP server—causes attacker-controlled instructions to run in the privileged process.
  5. Because the complete MCP server was launched through sudo, those instructions can execute with root ...[truncated 569 chars]
Remediation
View remediation

Remediation Suggestions

  1. Run the MCP server under an unprivileged, dedicated account rather than launching the entire process through sudo.
  2. If hardware access requires elevated permissions, grant narrowly scoped device access through operating-system permissions, groups, entitlements, or a minimal privileged helper with a restricted interface.
  3. Reference the executable using an absolute, administrator-controlled path and ensure that both the binary and every parent directory are not writable by untrusted users.
  4. Verify the executable's provenance and integrity before deployment, such as through code signing or cryptographic checksum validation.
  5. If sudo cannot be eliminated, define a narrowly scoped sudoers rule for the exact executable and arguments. Do not grant unrestricted command execution, allow attacker-controlled environment variables, or use wildcard arguments.
  6. Drop elevated privileges immediately after opening any hardware resource that genuinely requires them.
  7. Document why elevated access is required and test the detector with ordinary user privileges to confirm the minimum permissions necessary.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The response personality table hard-codes French severity/locale terms such as "VIB_LEGERE" and "CHOC_MAJEUR" as part of the skill's natural-language behavior. The file does not offer an opt-in choice of language or explain why French labels are required, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.