Back to skill

Security audit

Tamp

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate cost-saving purpose, but it asks users to install and persistently route Anthropic API traffic through a third-party local proxy with limited containment guidance.

Install only if you intentionally want OpenClaw Anthropic traffic, including prompts, tool results, and API headers, to pass through Tamp. Prefer a temporary foreground run first, review the Tamp package and dependencies, avoid sudo, keep direct Anthropic access as the default or fallback, and know how to disable the service and remove the provider configuration before enabling persistence.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:43
Finding

Persistent interception proxy for Anthropic API traffic

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:18
Finding

Execution of externally retrieved and insufficiently verified dependencies

Content
View full analysis
Remediation
View remediation
``` 5. Verify the checked-out commit or release using a trusted signature before installation. 6. Avoid `npx` for security-sensitive infrastructure because it combines retrieval and execution with limited opportunity for review. 7. Disable lifecycle scripts during dependency installation where compatible: ```bash npm ci --ignore-scripts ``` 8. Run the proxy in a sandboxed environment or container with minimal filesystem access, no unnecessary environment variables, and tightly restricted networking. 9. Publish a software bill of materials and document the exact source commit, package digest, dependency versions, and audit date. 10. Instruct users never to use `sudo` for package installation unless a reviewed deployment design specifically requires it. ]]>
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises broad trigger phrases like saving tokens, reducing API costs, and token compression, which can cause the agent to invoke this skill for general budgeting or model-usage questions rather than explicit proxy setup. That increases the chance of unsolicited infrastructure changes, package installation, and traffic rerouting through a local proxy when the user did not clearly request those actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

Instructing the user to create a systemd unit in ~/.config/systemd/user establishes a persistent execution mechanism. In this context, the persisted process is a local proxy that rewrites and forwards API requests, so unintended long-term deployment could affect confidentiality, troubleshooting, and future agent behavior.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

2. Run as systemd service

Create ~/.config/systemd/user/tamp.service:

ini
[Unit]

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The command enables a user-level systemd service to start automatically in future sessions, creating persistence beyond the immediate task. Persistence is security-relevant because it keeps a request-intercepting proxy running continuously and may outlive the user's awareness or intent.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

bash
systemctl --user daemon-reload
systemctl --user enable --now tamp.service
journalctl --user -u tamp -f  # live compression logs

Static analysis

No suspicious patterns detected.