Back to skill

Security audit

Openclaw Version Bug Hunter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a purpose-aligned GitHub issue reporting helper with some privacy and untrusted-output cautions, but no evidence of hidden, persistent, destructive, or credential-stealing behavior.

Install only if you are comfortable with the skill using your authenticated GitHub CLI to query the public OpenClaw repository. Treat issue and PR titles in reports as untrusted data, and confirm the target version before asking an agent to run the report or use it for upgrade decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bug-hunt.sh:118
Finding

Unsanitized GitHub Issue Titles Enable Indirect Prompt Injection and Terminal Output Manipulation

Content
View full analysis
/dev/null || echo "[]") ``` ```bash items=$(echo "$EVALUATED" | jq -r --arg cat "$category" ' [.[] | select(.category == $cat)] | map( .dup_of as $d | .quality as $q | (if $d != "" then "🔁 dup of #\($d)" elif $q == "actionable" then "✅ actionable" elif $q == "partial" then "⚡ partial" elif $q == "vague" then "⚠️ vague" else "❓ needs info" end) as $marker | "- #\(.number): \(.title) [\($marker)]" ``` The resulting value is subsequently printed without sanitization: ```bash echo "$items" ``` ### Technical Analysis The script retrieves issue titles from the public `openclaw/openclaw` GitHub repository and includes them verbatim in its report. GitHub issue titles are remotely supplied, attacker-controlled data. The use of `jq -r` converts JSON strings to raw output. Consequently, control characters represented in JSON may be decoded before the title is printed. The script does not remove terminal control sequences, normalize control characters, escape Markdown or prompt-like syntax, or mark issue content as untrusted data. This creates two related attack surfaces: 1. **Indirect prompt injection:** The Skill documentation directs an AI Agent to consume the generated report and use issue information when making an upgrade recommendation. A malicious title can contain instruction-like text intended to alter that analysis. Without a trust boundary, the Agent may interpret data from the issue title as operational instructions rather than as inert evidence. 2. **Terminal output manipulation:** A malicious title containing ...[truncated 2089 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to interact with the agent using unrestricted natural language and says the agent will automatically run the skill. This broad invocation model can cause accidental or overly eager activation when a user asks general upgrade or bug-related questions, increasing the chance of unintended data access or command execution through the skill pipeline.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example trigger phrases are broad conversational requests such as asking to check whether a version has bugs or to compare versions. Because these overlap with normal discussion about upgrades, an agent may invoke the skill when the user intended only a general conversation, leading to unintended GitHub queries or follow-on actions based on workspace config.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage instructions are written as direct guidance for interacting with the agent in Chinese and provide only Chinese invocation examples, without offering a language or locale choice. This can constitute a language-policy violation because it implicitly constrains user interaction to a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill encourages very broad natural-language triggers such as 'just talk naturally' and promises the agent will automatically run scripts. In an agent environment, this can cause unintended activation and execution of external-querying behavior when the user's intent is ambiguous, increasing the chance of accidental data exposure or unnecessary network actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill wraps GitHub CLI searches and says the agent may combine output with the user's configuration, but it does not clearly warn that queries and possibly contextualized search terms will be sent to GitHub. In privacy-sensitive environments, this can leak version targets, deployment details, plugin names, or operational context to a third party.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. This markdown file presents all operational guidance exclusively in Chinese, and nowhere indicates that the user can choose another language or that the content is intentionally limited to a Chinese-speaking audience for a documented reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header comment and usage/help text are written entirely in Chinese, and the script's runtime output also uses Chinese-only messages. This imposes a specific language on users without any opt-in, fallback, or documented justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.