Back to skill

Security audit

Agent Execution Guard

Security checks for vulnerabilities and agentic risk

Overview

WorldLoops is mostly a coherent open-loop workflow skill, but it can upload private local signal text to a hosted API and expose local brief data through an unauthenticated Telegram demo bot.

Review this before installing if your handoff files may contain private email, Slack, calendar, GitHub, customer, legal, or business data. Treat the default brief/guard commands as remote-processing commands unless you have verified otherwise, do not set WORLDLOOPS_API_BASE_URL to an untrusted endpoint, and do not run telegram:test with real data unless you add your own chat allowlist or isolation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/brief.ts:3
Finding

Local communication contents are transmitted to a remote API without clear disclosure or explicit opt-in

Content
View full analysis
{ const apiKey = process.env.WORLDLOOPS_API_KEY; const baseUrl = getApiBaseUrl(); const response = await fetch(`${baseUrl}/api/v1/openclaw/brief`, { method: 'POST', headers: { 'Content-Type': 'application/json', ...(apiKey ? { Authorization: `Bearer ${apiKey}` } : {}), }, body: JSON.stringify({ signals: input.signals, mode: input.mode ?? (apiKey ? 'connected' : 'demo'), }), }); const json = (await response.json()) as WorldLoopsBriefResponse; ``` The primary guard command reads a local payload, converts it into a signal, and invokes this API: ```ts let raw: unknown; try { raw = JSON.parse(fs.readFileSync(path.resolve(inputPath), 'utf8')); } catch (e) { printError([`❌ Could not read input file: ${inputPath}`], outputFormat); process.exit(1); } const validation = validateAdapterSignal(raw); if (!validation.ok) { printError(['❌ Invalid adapter signal.', ...validation.errors], outputFormat); process.exit(1); } const signal = toWorldLoopsSignal(validation.signal); const signals: Signal[] = [signal]; const result = await callWorldLoopsBrief({ signals, mode: 'reconciliation' }); ``` The transmitted `Signal` structure includes full text and may include a source URL: ```ts export interface Signal { source: SignalSource; text: string; url?: string; createdAt?: string; } ``` ## ...[truncated 2505 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/scripts/telegramTestBot.ts:786
Finding

Telegram test bot returns private local inbox and loop data to unauthenticated chats

Content
View full analysis
): Promise { const message = update.message as Record | undefined; if (!message) return; const chatId = (message.chat as Record | undefined)?.id as number | undefined; const text = message.text as string | undefined; if (!chatId || !text) return; const trimmed = text.trim(); const labels = getLabels(detectLang(trimmed)); ``` The `/live` command runs a diagnostic against the OpenClaw inbox and sends its output to the requesting chat: ```ts function runLiveDiagnostic(): string { try { const result = spawnSync( 'node', ['dist/scripts/guardDaily.js', '--inbox', OPENCLAW_INBOX], { encoding: 'utf8', timeout: 30000, cwd: process.cwd() } ); if (result.error) { return `Error running live diagnostic: ${result.error.message}`; } const output = ((result.stdout ?? '') + (result.stderr ?? '')).trim(); return truncate(output || 'No output from live diagnostic.'); } catch (err) { return `Error running live diagnostic: ${String(err)}`; } } ``` ```ts if (trimmed === '/live') { await sendMessage(token, chatId, [ 'Raw diagnostic mode — this reads shallow live handoff payloads and may include noise.', 'For user-facing quality, use interpreted OpenClaw observations with /brief.', '', 'externalWrite:false', ].join('\n')); await sendMessage(token, chatId, runLiveDiagnostic()); return; } if (isBriefRequest(trimmed) || !trimmed.startsWith('/')) { await handleBriefCommand(token, chatId, labels); retur ...[truncated 3192 chars]
Remediation
View remediation
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (192)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · CHANGELOG.md (reported line 832)May include surrounding context.

md
AI agents are good at answering. But they often lose track of what is still unfinished.

WorldLoops now includes a local demo that shows how scattered signals across email, calendar, chat, documents, project tools, and meeting notes become accountable open loops with clear states.

### Highlights

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README.md (reported line 451)May include surrounding context.

md
afe transition.

---

## 🚨 Severity-aware open loops

WorldLoops classifies detected open loops by severity:

- **Critical / High** → escalated immediately, requires approval
- **Medium** → surfaced for review, proposal generated
- **Low** → tracked but not escalated

High-severity loops (like a legal claim follow-up) trigger proposals with `adjudication: requires_approval`.

---

## 🧑‍⚖️ Proposals, adjudication, and approval

When an open loop requires action, WorldLoops creates a proposal:

- what action is proposed
- why it is required
- what checks should be performed first
- whether approval is required (`requiredReview: true`)
- what boundary applies (`local_proposal_only`, `read_only`, etc.)

No proposal executes automatically.
Human approval is required before any local transition is committed.

---

## 🧾 Receipts and audit trail

Every approved decision creates a receipt:

- transition receipt (records the loop state change)
- proposal decision receipt (re

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk is merely a .d.ts type declaration exposing a validation function signature. It suggests a narrow adapter-signal validation utility, not the broader declared functionality of an agent execution guard or governed open-loop responsibility layer. There is no implementation showing resource access, triggers, write controls, or enforcement behavior. Because the declared description presents a substantially broader primary purpose than what this code chunk supports, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents the skill as an agent execution guard/responsibility layer focused on governance and safety properties. The supplied code chunk instead defines TypeScript types and function signatures for handling a calendar payload and converting it into an adapter signal. This is a materially different primary purpose: calendar integration plumbing rather than execution guarding. No evidence in this chunk supports the claimed guard/open-loop governance behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents the skill as a broad safety/governance layer for AI agent responsibility management. However, the code shown is narrowly focused on calendar data ingestion and transformation: it validates a Gog Calendar payload, ranks events by preparation-related keywords, builds a text summary, and returns a normalized signal marked externalWrite:false. While the code is read-only and consistent with preserving externalWrite:false, its primary purpose is not an execution guard or responsibility layer. This is a material description-behavior mismatch because the implemented functionality is a calendar adapter rather than agent governance logic.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as an agent execution guard focused on governance/safety of work signals. The supplied code instead defines a Gmail adapter interface and conversion utilities for Gmail message payloads. This is a materially different primary purpose and introduces an undeclared resource domain (Gmail/email). There is no evidence in this code chunk of an execution guard or responsibility-layer behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broad governance/safety layer for AI agent responsibility management, but the code shown is narrowly focused on Gmail ingestion and normalization. It identifies Gmail payloads, inspects messages, ranks them by actionable keywords, builds text summaries, and outputs a structured signal with Gmail metadata. While the code does preserve externalWrite:false, its primary purpose is an email adapter rather than a general execution guard or responsibility layer. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The supplied code chunk does not implement a general agent execution guard or responsibility/governance layer. Instead, it defines payload interfaces for Gmail and Calendar snapshot data and declares functions that transform those snapshots into Signal arrays. This is a materially different, narrower purpose focused on email/calendar data adaptation. While transforming snapshots into signals could support a broader workflow system, the declared description does not mention Gmail or Calendar ingestion/adapters, so the code’s actual behavior is not accurately represented by the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents this skill as an agent execution/responsibility guard focused on governance and safety constraints. The supplied code does not implement execution guarding, policy enforcement, or write restrictions. Instead, it is a data-adapter utility that reads Gmail and Calendar payload structures and converts them into normalized signal records. That is a materially different primary purpose from the declared description, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk is not implementing a general agent execution guard or responsibility layer. It defines a payload shape containing account, calendarId, events/items/count and exposes a function to transform calendar events into Signal objects. That is a specific adapter for calendar data ingestion/normalization. The declared description emphasizes governance, safe-by-default loop management, and preserving externalWrite:false, none of which are evidenced in this code. This is therefore a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad agent execution guard/responsibility layer focused on governance and safety constraints. The supplied code does not implement guarding, policy enforcement, execution control, or write restrictions. Instead, it is a narrow adapter that reads calendar event data and converts it into signal objects. This is a materially different primary purpose and introduces an undeclared capability: ingesting and transforming calendar resource data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a general agent execution guard/responsibility layer focused on governance and safe-by-default loop management. The provided code instead exposes a Gmail-specific adapter interface for webhook payloads and a conversion function from Gmail webhook data to signals. That is a materially different primary purpose and introduces an undeclared external resource/domain (Gmail email/webhooks). Even though the function outputs signals, the code is not implementing a governance or execution guard layer; it is an integration adapter for email events.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description describes a broad safety/governance layer for AI agent execution, but the supplied code is a narrow data transformation adapter for Gmail/OpenClaw events. It does not implement guardrails, responsibility governance, policy enforcement, or anything clearly related to preserving externalWrite:false. Instead, it ingests payload items/messages/events and emits normalized Gmail signals. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description emphasizes an agent execution guard and governance layer with safety-oriented behavior. The supplied code chunk is just a type declaration plus a function signature for translating message payloads into signals. That is an adapter/serialization role, not an execution guard. While converting messages to signals could support a broader guard system, this chunk itself does not implement or expose the described primary purpose, nor does it show any enforcement of safe-by-default controls or external write restrictions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is a narrow adapter that parses message arrays from various payload shapes and converts them into standardized signal objects. It does not implement a responsibility layer, execution guard, governance logic, safety enforcement, or any mechanism related to preserving externalWrite:false. While the output uses the term 'signal,' the actual behavior is just message normalization. That is materially different from the declared high-level purpose, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk is specifically about Slack payload ingestion and normalization, exposing a SlackHostPayload interface plus functions to identify and transform Slack data into an AdapterSignal. The declared description instead presents the skill as a general agent execution guard/responsibility layer focused on governed open loops and safety properties. There is no indication in the description of Slack integration, payload parsing, or adapter conversion. That makes the code's concrete primary purpose materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code is narrowly focused on ingesting Slack payloads and converting them into a normalized signal object. It identifies Slack-like payloads, inspects message fields, scores messages by actionable keywords, extracts metadata such as channel/user/thread/permalink, and emits a structured signal. While this does preserve externalWrite:false and could support a larger 'execution guard' system, the declared description is much broader and governance-oriented, whereas the actual code is a Slack adapter implementation. The Slack-specific ingestion and message-selection behavior is not accurately represented by the declared description, so this is a material description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding

The code is read-only and its output relates loosely to identifying possible open loops, which partially aligns with the 'governed open loops' phrasing. However, the declared description presents a broad 'Agent Execution Guard' and 'responsibility layer for AI agents' that turns scattered work signals into governed open loops, while the actual code is a much narrower adapter that classifies Re:/Fwd: threads using simple phrase heuristics. It does not implement a general execution guard, policy layer, or broader responsibility/governance system. So the description overstates the scope and primary purpose of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents the skill as a generic 'Agent Execution Guard' focused on governance of agent responsibilities and open loops with externalWrite:false. The supplied code chunk instead defines a daily brief processing interface: it enumerates Gmail/Calendar/Slack sources, reads from a local inbox directory, extracts proposal candidates, classifies message/event content, and produces summary lines and briefs. That is a materially different primary purpose from an execution guard/responsibility layer. There is no clear evidence here of agent-execution guarding; instead the code is oriented around inbox/source summarization and candidate generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a substantial runtime safety/governance capability for AI agents. However, the supplied code chunk is merely a declaration file defining an exported ProposalTemplate array type. It does not show any implementation related to guarding agent execution, governing loops, enforcing safety constraints, or handling work signals. This is a materially different primary purpose from the description, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents an agent execution governance/guard layer focused on responsibility management and preserving externalWrite:false. The supplied code instead defines a notifications preferences component. It exposes capabilities for storing and retrieving notification settings, handling multiple outbound communication channels, and applying quiet-hour and severity rules. Those behaviors are materially different from the declared purpose, and the presence of save/load preferences and external channel support is inconsistent with the description’s framing of a guarded agent responsibility layer.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code is not an agent execution guard or responsibility/governance layer. It is a notification preferences utility module. Its primary behavior is reading and writing a JSON preferences file under a .worldloops directory, initializing defaults, and evaluating notification-related settings such as channels, quiet hours, and severity thresholds. This also conflicts with the description's claim of preserving externalWrite:false, because the code performs filesystem writes via mkdirSync and writeFileSync. While local persistence could be a supporting detail in some systems, the code's core purpose here is plainly notification preference storage and evaluation, which is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

The declared description presents a broad agent execution guard/responsibility layer focused on governing agent work signals and maintaining safe-by-default behavior. The supplied code chunk instead exposes a narrow notification-state storage interface, including a saveState function that implies local persistence and write access. This is materially different from the declared primary purpose, and the write/storage behavior is not reflected in the declared permissions or description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk is a simple local state management module for notifications. It reads and writes a JSON file on the local filesystem, including creating directories as needed. That behavior is materially more specific and different from the declared purpose of an 'Agent Execution Guard' responsibility layer. Most notably, the description claims preservation of externalWrite:false, but this code explicitly writes state to disk. Even if local persistence is considered a supporting detail in some contexts, the declared description does not disclose this storage behavior, and the module’s primary observed function here is persistence, not execution guarding.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The supplied code chunk is only a .d.ts declaration for a function adjudicateSeverity(severity) returning a SeverityAdjudication. It does not show any implementation related to agent execution guarding, responsibility layering, governing open loops, or preserving externalWrite behavior. While this could be a small supporting piece within a larger system, based on the provided chunk alone the actual behavior is narrowly a severity-classification API surface, which is materially different from the declared primary purpose.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/scripts/telegramTestBot.js:54

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/scripts/telegramTestBot.ts:29

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/contractCreate.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/contractList.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/contractReview.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/contractShow.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/doctorMobile.test.cjs:7

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/loopList.test.cjs:16

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/loopReview.test.cjs:16

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/loopShow.test.cjs:40

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/loopSummary.test.cjs:16

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/loopTransition.test.cjs:37

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/planCreate.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/planList.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/planReview.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/planShow.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/proposalCreate.test.cjs:11

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/proposalDecide.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/proposalList.test.cjs:11

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/proposalReceipts.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/proposalReview.test.cjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/proposalShow.test.cjs:11

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/proposalTemplates.test.cjs:15

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/receiptsVerify.test.cjs:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/stateCheck.test.cjs:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/stateRepair.test.cjs:27

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
tests/briefPreferences.test.cjs:13

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
tests/guardAdapter.test.cjs:8

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
tests/guardDaily.test.cjs:8

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
tests/guardHandoff.test.cjs:8