Back to skill

Security audit

SecOpsAI for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent SecOps tooling, but it needs review because it tells agents to run shell commands with user-derived values and install mutable external code.

Install only after reviewing or pinning the SecOpsAI repository and dependencies. Use a dedicated low-privilege account, keep OpenClaw logs and SOC data backed up, require explicit confirmation for all write actions, and treat finding IDs, dispositions, package names, versions, and analyst notes as values that must be validated before any shell command runs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:118
Finding

Shell Command Injection Through Unvalidated Triage Parameters

Content
View full analysis
--search-root "$HOME/secopsai" --json ``` ```bash secopsai triage close --disposition --note "" --json ``` ### Technical Analysis The command templates place chat-derived values directly into shell commands. `` and `` are unquoted, while `` is enclosed only in double quotes. The skill does not require strict format validation, allowlisting, or shell-safe argument handling before executing these commands. An attacker can inject shell metacharacters through an unquoted finding ID or disposition. The quoted note is also unsafe because an attacker can terminate the quoted string with `"` or use command substitution such as `$(...)`, which remains active inside double quotes. The confirmation requirement for closing findings reduces accidental execution but does not neutralize malicious syntax in a confirmed value. The investigation workflow is read-only at the application level and does not require confirmation, but shell injection could turn it into an arbitrary write or execution operation. ### Attack Path 1. An attacker supplies a crafted finding identifier, disposition, or analyst note through chat or other content processed as a user request. 2. The agent substitutes the supplied value into the documented shell command. 3. The command is passed to a shell through the agent's execution tool. 4. Shell metacharacters, quote termination, or command substitution are interpreted before `secopsai` processes its arguments. 5. The injected command runs with the operating-system permissions and environment of the OpenClaw agent. For example, an unquoted finding identifier containing a command separator could append another comma ...[truncated 705 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Installation From Mutable External Sources

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases for running the daily pipeline include broad language such as "run live" and "refresh findings," which can plausibly appear in ordinary conversation and unintentionally invoke shell execution. Because this skill is explicitly wired to an exec-capable agent, accidental activation can cause unplanned command execution and state changes in the SOC workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The triage orchestrator is a write-capable action that can auto-close findings, yet it is mapped to generic phrases like "process open findings" and "orchestrate findings." Ambiguous natural-language triggers on a write path materially increase the risk of accidental invocation, leading to unauthorized modification of the local SOC store and potentially suppressing real security findings.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Threat-intel refresh is bound to vague phrases like "refresh intel" and "update iocs," which are broad enough to match normal analytical discussion. While this is less severe than a write-capable triage action, it still triggers shell execution and may initiate unintended feed refreshes, consuming resources or changing local cached intelligence state without deliberate operator intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

IOC matching is exposed through generic prompts such as "check iocs" and "any intel matches," which can overlap with ordinary investigative conversation. In an exec-enabled skill, this creates a real risk of unintended command execution and could launch scans over local replay data without clear user authorization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.