Back to skill

Security audit

X Skill Updater

Security checks for vulnerabilities and agentic risk

Overview

This updater is not clearly malicious, but it can bulk-install remote skill updates without an enforced confirmation or integrity check, so it deserves review before use.

Install only if you are comfortable with a skill that can inspect all installed OpenClaw skills and update them through external registries. Avoid --all unless you have reviewed the configured sources, and prefer per-skill updates after checking publisher, version, and changelog manually.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/upgrade.py:47
Finding

Remote Skill Updates Are Installed Without Version or Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upgrade.py:124
Finding

Configuration Slugs Bypass Validation in Bulk Upgrade Mode

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The document promises a safety workflow of check, notify, obtain confirmation, then upgrade, but it also advertises direct execution paths including bulk upgrade via --all. In an updater skill with shell and network capability, this mismatch is dangerous because operators may rely on the stated confirmation gate even though the exposed command paths enable immediate modification of local installations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The document promises a safety workflow of check, notify, obtain confirmation, then upgrade, but it also advertises direct execution paths including bulk upgrade via --all. In an updater skill with shell and network capability, this mismatch is dangerous because operators may rely on the stated confirmation gate even though the exposed command paths enable immediate modification of local installations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The document promises a safety workflow of check, notify, obtain confirmation, then upgrade, but it also advertises direct execution paths including bulk upgrade via --all. In an updater skill with shell and network capability, this mismatch is dangerous because operators may rely on the stated confirmation gate even though the exposed command paths enable immediate modification of local installations.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
2. **全量字段核对**:`_meta.json`(ownerId / slug / version / publishedAt)+ `SKILL.md`(author / slug / homepage / metadata)全部纳入核对

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
2. **全量字段核对**:`_meta.json`(ownerId / slug / version / publishedAt)+ `SKILL.md`(author / slug / homepage / metadata)全部纳入核对

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares capabilities to read/write files, use the network, and execute shell commands, but does not define any explicit tool scope or permission boundaries. For an updater skill, this combination is especially risky because it can modify installed skills and fetch remote content, creating a clear path for unintended code execution or supply-chain compromise if the surrounding platform does not enforce least privilege.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Broad trigger phrases like '更新skill' and 'skill更新' increase the chance of accidental activation during normal conversation. In this skill's context, accidental activation is more serious than usual because the skill can inspect local files, access the network, and potentially initiate upgrade-related actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Repeating ambiguous trigger examples and extending them with '等' leaves the activation boundary undefined. Given that this skill manages installed skills and writes local state, underspecified triggering can cause unintended scans or preparation steps without a clearly intentional user request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level docstring presents the skill name, description, and usage entirely in Chinese, with no indication that other languages are supported. This creates a natural-language locale constraint without user opt-in, which matches the policy-violation category for forced language or locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script enumerates both the global skills directory and every workspace-* skills directory under OPENCLAW_HOME, which broadens visibility far beyond a single targeted skill. In a multi-workspace or multi-tenant environment this can expose the existence, metadata, versions, and source hints of unrelated installed skills, violating least-privilege and potentially leaking sensitive local configuration details into the generated report.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Although presented as a check operation, the script persists results to last-report.md and may also write pending-sources.json when unknown skills are found. This creates side effects from a nominally read-only action, which can overwrite prior state, leave audit artifacts, and store metadata about local installations without explicit consent at execution time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script persists data to pending-sources.json and later last-report.md, which are file-write operations affecting local state. Although the module docstring explains report generation, there is no comparable disclosure before the pending file write, and the main report write at REPORT_PATH.write_text occurs without any prior user-facing warning or confirmation in code comments or prompts.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/upgrade.py (reported line 47)May include surrounding context.

python
dest = skill_dir(slug)
    print(f"[skillhub] 升级 {slug} → {dest}")
    try:
        result = subprocess.run(
            ["skillhub", "install", slug],
            capture_output=True, text=True, timeout=120
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/upgrade.py (reported line 67)May include surrounding context.

python
"""通过 clawhub CLI 升级 clawhub 来源的 skill"""
    print(f"[clawhub] 升级 {slug}")
    try:
        result = subprocess.run(
            ["clawhub", "install", slug],
            capture_output=True, text=True, timeout=120
        )

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script supports --all batch upgrades of all skills from the manifest without an explicit per-upgrade confirmation step, which conflicts with the stated behavior of notifying and confirming before upgrade. In a skill-updater context, automatic bulk installation of updated code materially increases supply-chain risk: a compromised registry entry, malicious update, or mistaken source mapping could propagate code changes across all installed skills without user approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation is written entirely in Chinese, including usage and operational instructions, with no indication that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains natural-language documentation and user-facing messages entirely in Chinese, including usage and safety notes, without any indication of language selection or opt-in. Under the policy rule for language/locale constraints, this is a natural-language policy issue because it imposes a specific language on all users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.