Back to skill

Security audit

S2-Nomad-Agent-Protocol

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it requests sensitive device permissions and can perform location-based claim or override actions without enforcing authorization in code.

Review this before installing if you do not want a skill with preauthorized location/sensor permissions or active spatial-claim behavior. It should be constrained to explicit per-action user approval, remove unused device permissions, and validate agent identity and priority before any ownership override.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
openclaw.plugin.json:7
Finding

Unnecessary Geolocation and Environmental Sensor Permissions

Content
View full analysis

Vulnerability Details

File Location: openclaw.plugin.json, lines 7-11
Vulnerability Type: Excessive device permissions violating least privilege
Risk Level: Medium

Vulnerable Code

json
"permissions": {
  "network": ["localhost"],
  "device": ["geolocation", "environmental_sensors"],
  "tools": ["execute_nomad_expansion"]
},

Technical Analysis

The plugin manifest grants access to precise geolocation and environmental sensors even though the current implementation in handler.py does not access either capability. The documented workflow in SKILL.md also directs the agent to ask the user or host system to provide coordinates instead of reading GPS data directly.

These device permissions therefore exceed the minimum privileges required for the implemented in-memory grid simulation. Permission overprovisioning weakens the security boundary because a compromised handler, malicious update, or subsequently added code could access sensitive device telemetry without requiring a new permission grant.

The current reviewed implementation does not collect or exfiltrate geolocation or sensor information. The vulnerability is the preauthorized access surface created by the manifest.

Attack Path

  1. A user installs or enables the plugin with the permissions declared in openclaw.plugin.json.
  2. The host grants the plugin access to geolocation and environmental sensor capabilities.
  3. The handler is later compromised, replaced, or updated with code that invokes the authorized device APIs.
  4. That code reads precise location or environmental telemetry under the plugin's existing authorization.
  5. The acquired data could then be processed, retained, or exposed through another available channel without requiring a new device-permission request.

The reviewed version contains no code that performs steps 3 through 5, but the excessive authorization makes this path possible after compromise or an ...[truncated 530 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the unused device permissions from the manifest:

    json
    "permissions": {
      "network": ["localhost"],
      "tools": ["execute_nomad_expansion"]
    }
    
  2. Review whether localhost network access is also necessary. Remove it if no implemented feature requires network communication.

  3. Continue accepting coordinates explicitly supplied by the user or trusted host, as described in SKILL.md.

  4. If direct GPS or sensor access is implemented later, request only the specific capability needed and require explicit, purpose-specific runtime consent.

  5. Limit sensor access to the shortest practical duration and avoid retaining raw location or telemetry unless required.

  6. Add automated checks that compare manifest permissions against APIs actually used by the implementation to prevent future privilege drift.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The skill authorizes sensitive geolocation-driven actions and territorial claims/expansions through powerful tools, creating a mismatch between a benign-sounding description and materially stronger behavior. Even though the markdown text mentions consent, the skill normalizes actions such as claim, ripple expansion, and possible override/arbitration over shared space, which can lead an agent to invoke state-changing operations with privacy, resource, and control implications that exceed user expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation goes beyond passive boundary negotiation and user-consented slot claiming by autonomously expanding into adjacent grids and conditionally overriding existing owners based on priority. In a multi-agent environment, that behavior enables unauthorized resource capture and can violate user intent, ownership rules, or safety policies, especially because the tool accepts untrusted caller-supplied agent_id and priority values without authorization checks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest identifies the skill as "s2-nomad-expansion-engine" while the provided context describes a protocol/instruction skill named "s2-nomad-agent-protocol." This mismatch is dangerous because it obscures the skill's true function, making reviewers and users believe they are installing a passive guidance skill when the manifest suggests an active expansion-oriented component instead.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a code file, so SQP-3 applies to natural-language content in docstrings and strings. The class docstring and multiple user-facing messages are written only in Chinese, and the file does not provide any user opt-in, language selection, or justification for a Chinese-only locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code comments and surrounding description imply boundary negotiation, but the actual branch forcibly replaces the existing owner when the caller provides a higher priority. That mismatch is dangerous because downstream users or orchestrators may trust the skill as non-destructive, while an attacker or misconfigured agent can use it to evict others by supplying elevated priority values.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The permissions request geolocation, environmental sensors, and a tool named "execute_nomad_expansion," which exceeds the stated role of merely instructing an agent how to request consent and negotiate boundaries. In context, this creates a strong capability-to-description mismatch: the skill can collect sensitive location data and trigger active physical/environmental actions under a benign-sounding protocol label.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The heading includes a Chinese-only title variant and the document frames the protocol in a fixed bilingual style, but nowhere offers the user a language or locale preference. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.