Back to skill

Security audit

Echo

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide the advertised completion sound, but it does so by persistently modifying every detected OpenClaw UI installation with injected JavaScript.

Install only if you are comfortable with a local patch that edits OpenClaw's built UI files. Do not run it with sudo or admin privileges, review the payload first, and prefer an official OpenClaw extension or upstream feature when available. Use remove.sh to restore from backups if you no longer want the patch.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Warning
Location
apply.sh:113
Finding

Injection of Skill-Controlled Code into Trusted OpenClaw Application Bundles

Content
View full analysis
> "$DIST_JS" if ! grep -q "$MARKER" "$DIST_JS"; then red "✗ Patch append failed at $ROOT, restoring." cp "$DIST_JS.milly.bak" "$DIST_JS" continue fi # Cache-bust: rename and update index.html if [[ -f "$INDEX_HTML" ]]; then if [[ "$ENTRY_NAME" == *.milly-*.js ]]; then dim "→ already cache-busted ($ENTRY_NAME)" else BUST="milly-$(date +%s | tail -c 6)" NEW_NAME="${ENTRY_NAME%.js}.${BUST}.js" NEW_PATH="$ASSETS/$NEW_NAME" mv "$DIST_JS" "$NEW_PATH" [[ -f "$DIST_JS.milly.bak" ]] && mv "$DIST_JS.milly.bak" "$NEW_PATH.milly.bak" [[ -f "$INDEX_HTML.milly.bak" ]] || cp "$INDEX_HTML" "$INDEX_HTML.milly.bak" sed -i.tmp "s|$ENTRY_NAME|$NEW_NAME|g" "$INDEX_HTML" && rm -f "$INDEX_HTML.tmp" green "✓ Patched + cache-busted: $ENTRY_NAME → $NEW_NAME" fi else yellow "⚠ index.html not found at $INDEX_HTML; cache may persist." fi ``` The injected payload subsequently runs inside the OpenClaw UI and observes its document: ```javascript observer.observe(document.body, { subtree: true, childList: true }); mountWidget(); ``` ### Technical Analysis The installation script directly appends Skill-controlled JavaScript to OpenClaw's compiled entry bundle. It then renames that bundle and rewrites `index.html` so the trusted application loads the modified file. This is a tool-hijacking pattern because an existing trusted application artifact is modified to execute additional logic under the appearance and origin of the original OpenClaw UI. Although the audited payload implements the documented notification feature and no malicious network access, credential theft, or exfiltra ...[truncated 1923 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
apply.sh:31
Finding

Broad Modification of Weakly Validated Installation Targets

Content
View full analysis
/dev/null 2>&1; then R="$(npm root -g 2>/dev/null || true)" [[ -n "$R" && -d "$R/openclaw" ]] && CANDIDATES+=("$R/openclaw") fi if command -v pnpm >/dev/null 2>&1; then R="$(pnpm root -g 2>/dev/null || true)" [[ -n "$R" && -d "$R/openclaw" ]] && CANDIDATES+=("$R/openclaw") fi if command -v openclaw >/dev/null 2>&1; then RES="$(command -v openclaw)" command -v realpath >/dev/null 2>&1 && RES="$(realpath "$RES" 2>/dev/null || echo "$RES")" CUR="$(dirname "$RES")" for _ in 1 2 3 4 5 6; do if [[ -f "$CUR/package.json" ]] && grep -q '"name": *"openclaw"' "$CUR/package.json" 2>/dev/null; then CANDIDATES+=("$CUR"); break fi NEXT="$(dirname "$CUR")"; [[ "$NEXT" == "$CUR" ]] && break; CUR="$NEXT" done fi # Walk every nvm/n node version (gateway may run under a different node than `which openclaw`) for NVM_BASE in "$HOME/.nvm/versions/node" "/usr/local/n/versions/node"; do [[ -d "$NVM_BASE" ]] || continue while IFS= read -r d; do [[ -n "$d" ]] && CANDIDATES+=("$d") done < <(find "$NVM_BASE" -maxdepth 4 -path "*/lib/node_modules/openclaw" -type d 2>/dev/null) done # Dedupe (preserve order) DEDUPED=("") # placeholder so set -u doesn't bite on empty array expansion DEDUPED=() for R in "${CANDIDATES[@]}"; do skip=0 if [[ ${#DEDUPED[@]} -gt 0 ]]; then for E in "${DEDUPED[@]}"; do [[ "$E" == "$R" ]] && { skip=1; break; }; done fi [[ $skip -eq 0 ]] && DEDUPED+=("$R") done CANDIDATES=("${DEDUPED[@]}") ``` All accepted candidates are later processed: ```bash for ROOT in "${CANDIDATES[@]}"; do ``` ### Technical Analysis The script intentionally discovers and patches every OpenClaw installation a ...[truncated 2515 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · apply.sh (reported line 136)May include surrounding context.

sh
mv "$DIST_JS" "$NEW_PATH"
      [[ -f "$DIST_JS.milly.bak" ]] && mv "$DIST_JS.milly.bak" "$NEW_PATH.milly.bak"
      [[ -f "$INDEX_HTML.milly.bak" ]] || cp "$INDEX_HTML" "$INDEX_HTML.milly.bak"
      sed -i.tmp "s|$ENTRY_NAME|$NEW_NAME|g" "$INDEX_HTML" && rm -f "$INDEX_HTML.tmp"
      green "✓ Patched + cache-busted: $ENTRY_NAME → $NEW_NAME"
    fi
  else

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s behavior is broader than its framing: it enumerates multiple OpenClaw installations and modifies each discovered UI bundle in place. This is dangerous because it silently alters installed application assets across environments, which can affect other users, sessions, or runtime contexts and makes rollback/auditing harder than a single targeted local patch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script appends JavaScript payloads directly into built UI bundles and rewrites index.html without an explicit warning that local application files across discovered installs will be modified. In a skill context, this is especially risky because users may treat the script as a harmless customization while it performs persistent code injection into application assets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.