Back to skill

Security audit

Agency Agents Router

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent agent router, but it needs review because setup relies on unpinned third-party scripts and routine use can broadly share task content with sub-agents and web searches.

Review the external agency-agents-zh repository before running its install scripts, preferably pin to a specific reviewed commit and install in a restricted environment. Avoid sending sensitive prompts through this router unless you are comfortable with the task being copied into sub-agent sessions and potentially used in web searches.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:17
Finding

Execution of Unpinned Third-Party Installation Scripts

Content
View full analysis
Remediation
View remediation
``` 2. Publish and verify cryptographic checksums or signed release artifacts before executing any scripts. 3. Verify Git signatures where supported and document the expected signer identity. 4. Review the exact versions of `convert.sh` and `install.sh` before execution. 5. Avoid automatically executing downloaded scripts. Separate download, verification, and execution into explicit steps. 6. Run installation in a sandbox or restricted account with only the filesystem permissions required to install the agent definitions. 7. Document which paths the installer modifies and require confirmation before changes to `~/.openclaw/`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rebuild_index.py:238
Finding

Unsafe Reuse of a Predictable Repository Path in /tmp

Content
View full analysis
Remediation
View remediation
remote get-url origin ``` 6. Disable repository-controlled hooks by using an isolated empty hooks directory. 7. Add `check=True` to every security-relevant `subprocess.run` invocation and stop processing on failure. 8. Pin the checkout to a reviewed commit or signed release after cloning. 9. Validate downloaded README and frontmatter data before placing it into an agent-routing index, including length limits and rejection of instruction-like control content. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes the skill as handling arbitrary user-described tasks and 'figuring out which agents to use and how to run them,' which makes activation scope extremely broad. In an agentic system, such unconstrained routing can cause the skill to trigger on ordinary conversation and delegate sensitive prompts to other agents without sufficiently explicit user intent or safety gating.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage section says that once installed, users can simply describe a task in natural language and the skill will automatically analyze, select, and orchestrate agents. This increases the risk of unintended invocation, over-delegation, and prompt-routing of sensitive content to multiple agents, particularly because the skill is designed to run single, parallel, sequential, or DAG-style workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the orchestrator and sub-agents to perform live web_search/web_fetch for factual tasks, but it does not warn the user that their task content may be sent to external services or that external data will be incorporated. This creates privacy and data-governance risk, especially if user prompts contain sensitive business, personal, or unpublished information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs automatic sub-agent spawning and says results return to the main session automatically, but it does not warn users that their task details will be copied into other agent sessions/workspaces. This can broaden data exposure across multiple contexts and tools, increasing the chance of unintended disclosure, retention, or misuse of sensitive inputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill says users can 'describe the task naturally' and that the main agent will determine orchestration automatically, which is an overly broad natural-language trigger. This can cause the router to activate on ordinary conversation or ambiguous requests, increasing the chance of unintended agent invocation and execution of downstream actions without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest-level source label explicitly identifies the catalog as a Chinese variant, and the file overwhelmingly defines agent names/descriptions in Chinese. Because this is a general agent catalog rather than a clearly documented region-specific compliance artifact, it appears to enforce a locale preference without user opt-in.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/rebuild_index.py (reported line 210)May include surrounding context.

python
target = target or "/tmp/agency-agents-zh"
    if os.path.isdir(target):
        print(f"  Repo already exists at {target}, pulling ...")
        subprocess.run(["git", "-C", target, "pull", "--depth", "1"],
                       capture_output=True)
    else:
        print(f"  Cloning {REPO_URL} ...")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/rebuild_index.py (reported line 214)May include surrounding context.

python
capture_output=True)
    else:
        print(f"  Cloning {REPO_URL} ...")
        subprocess.run(["git", "clone", "--depth", "1", REPO_URL, target],
                       capture_output=True, check=True)
    return target

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The boilerplate requires unverifiable items to be marked as '[待确认]', which forces a Chinese-language label regardless of the user's language preference. This is a locale/language policy issue because the file does not offer a language choice or justify the constraint as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring states the script rebuilds data from the "agency-agents-zh" README, and the parser later hard-codes the Chinese section header "## 智能体阵容". This indicates the skill is designed around a fixed Chinese-language source and does not present any user choice or opt-in for language/locale handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The function downloads remote content from GitHub and writes it to .readme_cache.md. While the top-level usage mentions fetching, there is no user-facing warning in this function's docstring or comments that remote content will be cached locally, which is a file write combined with network access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.