Back to skill

Security audit

Pre Publish Security

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real pre-publish security scanner, but it needs Review because it installs persistent Git hooks, can inspect user-level credentials, and has unsafe agent/task handling around user-supplied paths.

Install only if you are comfortable with a repository pre-push hook that runs future audits automatically. Review or modify the hook installer first so it preserves existing hooks, avoid using this on attacker-controlled path names, remove the ~/.git-credentials check, and treat /tmp audit reports as potentially sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
audit.sh:20
Finding

Agent prompt and command injection through an untrusted target path

Content
View full analysis
"$REPORT_DIR/security.txt" 2>&1 & SEC_PID=$! ``` The same substitution pattern is used for the code-quality, documentation, and license sub-agents: ```bash --task "$(cat ~/.openclaw/workspace/skills/pre-publish-security/agents/code-quality.md | sed "s|{{TARGET}}|$TARGET_PATH|g")" ``` From `agents/security-auditor.md`: ```markdown **Target:** {{TARGET}} ## Commands to Run ```bash cd {{TARGET}} # Pattern scan grep -r -E "(github_pat_|ghp_|AKIA|api_key|apikey|Bearer|password=|pwd=)" . \ --exclude-dir=node_modules \ --exclude-dir=.git \ 2>/dev/null || true # Git history scan (last 10 commits) git log -p -10 | grep -E "(github_pat_|ghp_|AKIA|api_key|Bearer)" || true # Check for credential files find . -name ".env*" -o -name "*credentials*" -o -name "*.pem" | head -20 ``` ``` ### Technical Analysis `TARGET_PATH` is supplied by the caller and is substituted directly into natural-language agent instructions using `sed`. No canonicalization, control-character rejection, structured argument passing, or prompt-boundary protection is applied. A target value containing newline characters can add new instructions to the delegated task. Because the substituted value also appears in an unquoted `cd {{TARGET}}` shell example, shell metacharacters in the value can alter the command if the sub-agent executes the generated command block. The vulnerability crosses two interpretation boundaries: 1. The value is interpreted as part of an AI agent prompt. ...[truncated 1655 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
agents/security-auditor.md:22
Finding

Delegated agent is instructed to access a user-level credential store outside the audit target

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
audit-full.sh:11
Finding

Predictable temporary report paths permit symlink attacks and sensitive report exposure

Content
View full analysis
"$REPORT_FILE" echo "**Target:** $TARGET_PATH" >> "$REPORT_FILE" echo "**Scan Type:** $SCAN_TYPE" >> "$REPORT_FILE" echo "**Time:** $TIMESTAMP" >> "$REPORT_FILE" ``` From `audit.sh`: ```bash REPORT_DIR="/tmp/openclaw-security-audit-$(date +%s)" mkdir -p "$REPORT_DIR" ``` Sub-agent results are then written into this directory: ```bash > "$REPORT_DIR/security.txt" 2>&1 & ``` ```bash > "$REPORT_DIR/quality.txt" 2>&1 & ``` ```bash > "$REPORT_DIR/docs.txt" 2>&1 & ``` ```bash > "$REPORT_DIR/license.txt" 2>&1 & ``` ### Technical Analysis Temporary names are derived solely from the current Unix timestamp with one-second resolution. A local attacker can predict these names and create them before the audit starts. `audit-full.sh` opens its report through ordinary shell redirection. Shell redirection follows symbolic links, and the script does not use exclusive creation, verify ownership, reject symlinks, or set restrictive permissions. In `audit.sh`, `mkdir -p` accepts an already-existing attacker-controlled directory. The script neither checks whether it created the directory nor verifies its owner and mode before writing report files into it. The reports may contain snippets matched as secrets or sensitive environment variables. Without an explicit `umask 077`, resulting files can also inherit permissions that allow unintended local reads. ### Attack Path 1. A local attacker estimates the second when the victim will launch an audit. 2. For `audit-full.sh`, the attacker pre-creates `/tmp/security-audit-.md` as a symbolic link to another file writable by the victim. 3. The victim starts the audit during ...[truncated 1036 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill is presented as a release security auditor, but it also instructs installation/modification of local Git hooks and execution of external scripts from user-controlled paths. Repository hook modification is a sensitive action because it creates persistence in developer workflows and can cause repeated code execution on future Git operations; if users trust the skill as a harmless scanner, this context makes the behavior more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill is presented as a release security auditor, but it also instructs installation/modification of local Git hooks and execution of external scripts from user-controlled paths. Repository hook modification is a sensitive action because it creates persistence in developer workflows and can cause repeated code execution on future Git operations; if users trust the skill as a harmless scanner, this context makes the behavior more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill is presented as a release security auditor, but it also instructs installation/modification of local Git hooks and execution of external scripts from user-controlled paths. Repository hook modification is a sensitive action because it creates persistence in developer workflows and can cause repeated code execution on future Git operations; if users trust the skill as a harmless scanner, this context makes the behavior more dangerous.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a release security auditor, but it also instructs installation/modification of local Git hooks and execution of external scripts from user-controlled paths. Repository hook modification is a sensitive action because it creates persistence in developer workflows and can cause repeated code execution on future Git operations; if users trust the skill as a harmless scanner, this context makes the behavior more dangerous.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to inspect sensitive local credential stores such as ~/.git-credentials. In an agent setting, this expands access beyond the target repository into the operator or runner environment, creating a path to collect unrelated secrets and exfiltrate credentials if the skill or downstream components are compromised or overly permissive.

Content

Scanner excerpt · agents/security-auditor.md (reported line 25)May include surrounding context.

md
3. **Config Files:**
   - `.env`, `.env.local`, `config.json`
   - Git config files (`.git/config`)
   - Credential stores (`~/.git-credentials`)

4. **Environment Variables:**
   - Hardcoded secrets in scripts

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises and instructs use of shell scripts (./install-hooks.sh, ./audit-full.sh, ./schedule.sh) but does not declare any explicit tool scope such as permissions or allowed-tools. That creates a transparency and containment problem: users and platforms cannot clearly enforce what shell capabilities the skill needs, increasing the risk of unexpected command execution or file modification when the skill is invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script silently creates and updates a persistent state file under the user's home directory, which is an undisclosed side effect outside the target repository. Even though the stored data appears limited to scan timestamps and counters, writing to a hidden path can surprise users, leak usage metadata, and create persistence where none was expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This shell script changes into a user-supplied target path and then executes multiple scanning commands such as grep, git log, npm audit, and safety check against that repository. While these operations are central to the audit purpose, the script provides no upfront user-facing disclosure that it will execute external tools and potentially networked package-audit commands on the target.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The script writes agent outputs to a predictable path under /tmp using only a timestamp, then preserves those files after execution. In a multi-user environment, this can expose potentially sensitive scan output or enable symlink/race issues if another local user can pre-create or manipulate the directory path before use.

Content

Scanner excerpt · audit.sh (reported line 8)May include surrounding context.

sh
TARGET_PATH="${1:-.}"
REPORT_DIR="/tmp/openclaw-security-audit-$(date +%s)"
mkdir -p "$REPORT_DIR"

echo "=== Pre-Publish Security Audit ==="
echo "Target: $TARGET_PATH"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest scope is framed around pre-publish security auditing: credential leaks, vulnerabilities, documentation validation, and blocking bad pushes. Spawning a dedicated license-checker adds software license compliance review, which is a distinct governance/compliance function not described in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script unconditionally replaces any existing .git/hooks/pre-push hook with its own content, which can silently disable prior security, compliance, or workflow protections already configured in the repository. In a security-related skill, forcibly taking over a hook is especially risky because users may assume they are adding protection while actually removing other controls or custom logic without notice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script writes a markdown report containing potentially sensitive scan results, including matched secret-like strings and excerpts from repository files or git history, to a predictable location in /tmp. Temporary directories are commonly accessible to other local users or processes, so this can expose discovered secrets or confidential code fragments beyond the intended audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The comment suggests the orchestrator's remaining behavior is only to wait for agent completion, but later code introduces an interactive approval gate for HIGH findings via read. That documentation is not just incomplete about implementation detail; it misstates the control flow by implying agent completion is the final synchronization step.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.