Back to skill

Security audit

fff

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a skill-authoring helper, but it can modify and package agent-skill files with weak scope controls and a packager that may include unintended private files.

Install only if you intentionally want an agent to create, edit, and package OpenClaw skills. Review every SKILL.md diff, use a dedicated target directory, keep secrets and local-only files out of skill folders, inspect the generated .skill archive before sharing, and do not treat the included official tag as proof of trusted OpenClaw provenance.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
测试中文/package_skill.py:75
Finding

Recursive Packaging May Disclose Sensitive Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill is for authoring, editing, improving, reviewing, auditing, cleaning up, restructuring, and validating AgentSkills. However, the actual code does not implement those editing or audit behaviors. Its primary function is to package an existing skill directory into a .skill archive after running validation. It creates output files on disk, walks directories, filters files, and writes a zip-format archive. While validation is loosely related to the declared purpose, the main behavior—building distributable packages—is a materially different capability not represented in the description. Therefore this is a clear description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description centers on authoring, editing, auditing, and restructuring AgentSkills and SKILL.md content. The actual code does not create or edit skills for users; instead, it is an automated unit/regression test module for packaging behavior. Its primary function is to verify that package_skill securely builds archives and handles symlinks, path traversal, nested files, and output-archive exclusion. That is a materially different purpose from skill creation or cleanup, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a broad skill-management capability: create, edit, improve, audit, tidy up, clean up, restructure, and validate AgentSkills. The supplied code only covers one narrow subset of that description: creating a new skill scaffold from a template. It does not inspect existing skills, modify SKILL.md files, move files, remove stale content, review or audit anything, or validate a skill against a specification. While 'create a new skill from scratch' is included in the description, the actual code's primary behavior is much narrower than the declared purpose, so the description does not accurately represent the code chunk as a whole.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description frames the skill as an authoring/review/audit/cleanup tool for AgentSkills and SKILL.md files. The supplied code does not create, edit, improve, review, or restructure skills. Its primary function is to validate a skill folder and package it into a .skill file using zip compression. While validation is mentioned in the description, here it is only a prerequisite step supporting packaging, which is an undeclared and materially different primary capability. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad skill-authoring and maintenance capability: creating skills from scratch, editing/improving them, cleaning up directories, moving files, and auditing against the AgentSkills spec. The supplied code does not implement any write, modification, restructuring, or generation behavior. It only reads SKILL.md from a provided directory and performs a narrow validation of frontmatter presence, allowed keys, and basic constraints on name and description. While this limited validation partially overlaps with the phrase 'audit' or 'validate against the AgentSkills spec,' the overall declared purpose substantially overstates the implemented functionality and primary purpose of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description focuses on authoring and maintaining skill contents and directories—creating new skills, editing SKILL.md, tidying structure, removing stale content, and auditing against the AgentSkills spec. The actual code does not create or modify skills in that way. Instead, it defines regression tests for a packaging module, verifying that packaging includes expected files and excludes unsafe symlinked or out-of-root content. This is a materially different primary purpose: testing secure packaging logic rather than editing or auditing skill definitions/content. While 'audit' appears in the description, the code is specifically about automated packaging security tests, which is an undeclared and distinct capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a skill whose primary purpose is to create, edit, review, audit, or restructure AgentSkills and related files. The actual code shown does not perform those authoring or cleanup tasks; instead, it is a test suite for a validation utility. While validation is mentioned in the description, this code specifically implements automated regression tests for validator behavior, which is a materially different purpose from directly creating or auditing skill contents. The filesystem use here is limited to temporary test setup and is consistent with testing, not with the declared editing/restructuring workflow. Therefore this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to create and edit skill resources and SKILL.md, which is a self-modification capability. In an agent skill, self-modification is high risk because a prompted or compromised workflow could rewrite its own instructions or neighboring skills, weakening safeguards, persisting malicious changes, or altering future behavior.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
1. Understand the skill with concrete examples
2. Plan reusable skill contents (scripts, references, assets)
3. Initialize the skill (run init_skill.py)
4. Edit the skill (implement resources and write SKILL.md)
5. Package the skill (run package_skill.py)
6. Iterate based on real usage

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

The 'Update SKILL.md' instruction directly authorizes rewriting the skill’s own control document. Because SKILL.md defines behavior and triggering context, allowing routine updates creates a persistence mechanism for accidental or adversarial prompt injection to modify future executions.

Content

Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.

md
If you used `--examples`, delete any placeholder files that are not needed for the skill. Only create resource directories that are actually required.

#### Update SKILL.md

**Writing Guidelines:** Always use imperative/infinitive form.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

This section explicitly instructs the agent to create and edit skills, including running initialization and packaging scripts and writing SKILL.md content. Because this is a meta-skill that changes agent behavior artifacts, it enables self-modification of future instructions and capabilities. In the presence of prompt injection or weak approval boundaries, a user could leverage this workflow to introduce unsafe instructions, broaden triggers, or persist malicious behavior into distributable skill packages.

Content

Scanner excerpt · skill-creator/SKILL.md (reported line 209)May include surrounding context.

md
1. Understand the skill with concrete examples
2. Plan reusable skill contents (scripts, references, assets)
3. Initialize the skill (run init_skill.py)
4. Edit the skill (implement resources and write SKILL.md)
5. Package the skill (run package_skill.py)
6. Iterate based on real usage

Self-Modification

High
Category
Rogue Agent
Confidence
91% confidence
Finding

The 'Update SKILL.md' instruction directly tells the agent to modify the instruction file that controls future skill behavior. This is a classic self-modification sink: changing frontmatter affects activation, while changing the body affects operational behavior after triggering. Since the skill is specifically designed to rewrite skills, an attacker could use apparently benign requests to smuggle in unsafe routing language or operational instructions that persist beyond the current session.

Content

Scanner excerpt · skill-creator/SKILL.md (reported line 316)May include surrounding context.

md
If you used `--examples`, delete any placeholder files that are not needed for the skill. Only create resource directories that are actually required.

#### Update SKILL.md

**Writing Guidelines:** Always use imperative/infinitive form.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill-creator/测试中文/test_package_skill.py (reported line 67)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill-creator/测试中文/test_package_skill.py (reported line 92)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill-creator/测试中文/test_package_skill.py (reported line 109)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · 测试中文/test_package_skill.py (reported line 67)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · 测试中文/test_package_skill.py (reported line 92)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · 测试中文/test_package_skill.py (reported line 109)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · skill-creator/测试中文/测试中文.py (reported line 307)May include surrounding context.

python
# Print next steps
    print(f"\n[OK] Skill '{skill_name}' initialized successfully at {skill_dir}")
    print("\nNext steps:")
    print("1. Edit SKILL.md to complete the TODO items and update the description")
    if resources:
        if include_examples:
            print("2. Customize or delete the example files in scripts/, references/, and assets/")

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · 测试中文/测试中文.py (reported line 307)May include surrounding context.

python
# Print next steps
    print(f"\n[OK] Skill '{skill_name}' initialized successfully at {skill_dir}")
    print("\nNext steps:")
    print("1. Edit SKILL.md to complete the TODO items and update the description")
    if resources:
        if include_examples:
            print("2. Customize or delete the example files in scripts/, references/, and assets/")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to read and write files and execute local scripts (init_skill.py, package_skill.py) without declaring any explicit tool scope or restrictions. In a skill that can modify skill directories and package artifacts, missing scope increases the blast radius of accidental or prompt-induced actions because the agent has no embedded guardrails limiting filesystem or shell usage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description includes broad everyday phrases like 'improve this skill', 'review the skill', and 'clean up the skill', which can cause unintended activation in loosely related conversations. For a skill that can guide file modification, script execution, and packaging, accidental triggering increases the chance of unnecessary or unsafe changes to local content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description contains very broad trigger phrases such as creating, improving, reviewing, cleaning up, or auditing a skill. Because trigger metadata is always in context and governs activation, this can cause the skill to activate for many generic editing or review requests, increasing the chance that a skill with file-modification guidance is invoked inappropriately. In an agent setting, overbroad routing can become a security issue by widening the situations where the model is encouraged to restructure files, run helper scripts, or modify instructions without strong user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The regex ^[a-z0-9-]+$ and accompanying error message require skill names to use lowercase ASCII letters, digits, and hyphens only. This is a natural-language/locale policy concern because it hard-codes an English-centric naming convention and rejects names in other scripts, with no opt-in, alternative, or justification shown in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code creates a new directory tree and writes SKILL.md and optional example files to disk. Although it prints success messages after actions complete, there is no explicit pre-action warning, confirmation prompt, or docstring/comment disclosing that running the command will modify the filesystem at the provided path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.