Back to skill

Security audit

Openclaw Lifx

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it stores a smart-home API token locally and can turn untrusted LIFX device names into persistent agent instructions.

Install only if you are comfortable giving this skill ongoing control of your LIFX lights and storing a reusable LIFX token on disk. Prefer using an environment secret instead of setup.sh <token>, do not commit or copy .lifx-token, review generated SKILL.md before use, and avoid device or scene names that contain Markdown, newlines, or instruction-like text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
setup.sh:42
Finding

Persistent Agent Instruction Injection Through Untrusted LIFX Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.sh:16
Finding

LIFX Bearer Token Exposed Through Process Arguments and Plaintext Storage

Content
View full analysis
&2 exit 1 } echo "🔍 Discovering scenes..." SCENES=$(curl -sf -H "Authorization: Bearer $TOKEN" "$API/scenes") || { echo "❌ Failed to fetch scenes." >&2 exit 1 } # Save token echo "$TOKEN" > "$SKILL_DIR/.lifx-token" chmod 600 "$SKILL_DIR/.lifx-token" echo "🔑 Token saved to .lifx-token" ``` The documented invocation encourages placing the secret directly on the command line: ```bash bash setup.sh ``` ### Technical Analysis The setup script requires the LIFX bearer token as a positional command-line argument. Depending on the operating system and process isolation configuration, command-line arguments may be visible to other local processes through process-listing interfaces. The command can also remain in interactive shell history. The script then persists the reusable bearer token in `.lifx-token` as plaintext. Setting mode `0600` is a positive control that restricts ordinary filesystem access to the file owner, but it does not protect the token from compromise of that account, accidental workspace copying, backups, archives, or tools operating with the same user privileges. The supplied project structure does not include a `.gitignore`, despite the documentation stating that `.lifx-token` is ignored. The documented `cp -r .` installation method can also copy the token into another directory, creating an additional persistent copy. Sending the bearer token in an HTTPS authorization header to `https://api.lifx.com/v1` is necessary for the declared functionalit ...[truncated 1218 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (17)

Tainted flow: 'token' from os.environ.get (line 171, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scene-status.py (reported line 22)May include surrounding context.

python
def api(token: str, path: str) -> Any:
    r = requests.get(f"{LIFX_API}{path}", headers={"Authorization": f"Bearer {token}"}, timeout=15)
    r.raise_for_status()
    return r.json()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 22)May include surrounding context.

md
### 1. Get your LIFX token

Go to [cloud.lifx.com/settings](https://cloud.lifx.com/settings) and generate a personal access token.

### 2. Run setup

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill instructs users to run setup that stores a LIFX API token locally, queries cloud APIs, discovers home devices/scenes, and rewrites SKILL.md with personalized context, but those data-handling behaviors are not clearly disclosed in the primary description. Undeclared storage of credentials and home-device metadata can surprise users and create privacy and secret-management risks, especially in shared repositories or agent workspaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill instructs users to run setup that stores a LIFX API token locally, queries cloud APIs, discovers home devices/scenes, and rewrites SKILL.md with personalized context, but those data-handling behaviors are not clearly disclosed in the primary description. Undeclared storage of credentials and home-device metadata can surprise users and create privacy and secret-management risks, especially in shared repositories or agent workspaces.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
This discovers your lights, groups, and scenes, then generates a personalized `SKILL.md` with your device context.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · lifx-api.sh (reported line 58)May include surrounding context.

sh
local tmpfile
  tmpfile=$(mktemp)
  
  http_code=$(curl -s -o "$tmpfile" -w "%{http_code}" \
    -X "$method" \
    -H "Authorization: Bearer ${TOKEN}" \
    -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to pass a personal LIFX access token into setup and says the script performs device discovery and generates local files, but it does not clearly warn that this stores the token locally and initiates network calls against the user's LIFX account. In an agent-skill context, insufficient disclosure is security-relevant because users may expose credentials on disk or through shell history without understanding the trust boundary.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares access to a sensitive environment variable (LIFX_TOKEN) and instructs use of shell scripts and outbound API calls, but it does not define any explicit tool scope such as allowed tools or permissions. In an agent environment, missing scope boundaries can let the skill invoke broader shell/network capabilities than users expect, increasing the blast radius if the skill or its surrounding tooling is abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation says setup.sh rewrites SKILL.md with discovered lights, rooms, scenes, and location context, but it does not warn that this embeds personal household metadata into a project file. That can expose sensitive occupancy, naming, or location information through source control, logs, backups, or sharing of the skill directory.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 71)May include surrounding context.

md
#!/bin/bash
set -euo pipefail

API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"

# Load token from skill directory if not set

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 126)May include surrounding context.

md
#!/bin/bash
set -euo pipefail

API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"

# Load token from skill directory if not set

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · lifx-api.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
set -euo pipefail

API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"

# Load token from skill directory if not set

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scene-status.py (reported line 11)May include surrounding context.

python
#!/bin/bash
set -euo pipefail

API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"

# Load token from skill directory if not set

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 5)May include surrounding context.

sh
#!/bin/bash
set -euo pipefail

API="https://api.lifx.com/v1"
TOKEN="${LIFX_TOKEN:-}"

# Load token from skill directory if not set

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script loads authentication material from a local .lifx-token file if the environment variable is absent. This expands the credential surface beyond the stated skill behavior and can lead to unintended use of locally stored secrets, especially in shared or multi-skill environments where neighboring files may be readable or mistakenly packaged.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists the LIFX bearer token to disk in a local file, which creates a credential-at-rest risk if the skill directory is later copied, backed up, committed, or read by another process running as the same user. Although chmod 600 limits access to the current account, the user is not meaningfully warned that a reusable cloud API credential will be stored locally for ongoing use.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 34)May include surrounding context.

sh
# Save token
echo "$TOKEN" > "$SKILL_DIR/.lifx-token"
chmod 600 "$SKILL_DIR/.lifx-token"
echo "🔑 Token saved to .lifx-token"

# Generate device context

Static analysis

No suspicious patterns detected.