Back to skill

Security audit

SpiderShield Security Scanner

Security checks for vulnerabilities and agentic risk

Overview

SpiderShield is a coherent security-scanner skill, but its local commands delegate sensitive scanning and config-changing work to an unpinned external Python package and use an unsafe Python import fallback.

Review this before installing. The skill's purpose is legitimate and disclosed, but run local commands only from a trusted directory, prefer a pinned and trusted spidershield package or isolated virtual environment, use /spidershield fix --dry-run first, and review any ~/.openclaw changes before confirming fixes.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
skill.yaml:107
Finding

Unpinned Registry Dependencies Execute Mutable Third-Party Code

Content
View full analysis
=1.0.0" optional_dependencies: - name: spidershield install: "pip install spidershield" purpose: "Required for scan, audit-config, fix, pin, scan-all" fallback: "check command works without installation (API-only)" ``` `README.md:8-16`: ```bash npx clawhub install spidershield ``` ```bash pip install spidershield ``` `SKILL.md:19-20`: ```bash pip install spidershield ``` ### Technical Analysis The documented installation commands retrieve packages from external registries without pinning an exact version or verifying an integrity hash. The `spidershield` dependency contains the substantive implementation for scanning files, auditing configuration, modifying `~/.openclaw`, and maintaining pin data, but that implementation is not included in the audited project. Consequently, the code executed by these commands may differ from the code reviewed at publication time. A compromised maintainer account, malicious package release, registry compromise, dependency confusion event, or incompatible future update could cause arbitrary package installation or runtime code to execute under the user's account. The privacy claims for local commands cannot be fully verified from this repository because their behavior is delegated to this mutable external package. ### Attack Path 1. An attacker compromises the relevant registry package, publisher account, or distribution channel. 2. The attacker publishes a malicious version under the expected package name. 3. A user follows the documented `pip install spidershield` or unversioned `npx` installation instruction. 4. The package manager retrieves the current attacker-controlled release. 5. Package installation hooks ...[truncated 867 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/pin.sh:8
Finding

Python Module Search-Path Hijacking During CLI Resolution

Content
View full analysis
/dev/null; then spidershield "$@" elif python3 -c "import spidershield" 2>/dev/null; then python3 -m spidershield "$@" else ``` `scripts/scan.sh:23-27`: ```bash # Resolve CLI: prefer spidershield (open-source, pip install spidershield) if command -v spidershield &>/dev/null; then spidershield agent-check "$TARGET" elif python3 -c "import spidershield" 2>/dev/null; then python3 -m spidershield agent-check "$TARGET" ``` `scripts/audit-config.sh:30-36`: ```bash # Resolve CLI: prefer spidershield (open-source, pip install spidershield) if command -v spidershield &>/dev/null; then # shellcheck disable=SC2086 spidershield agent-check $EXTRA_FLAGS elif python3 -c "import spidershield" 2>/dev/null; then # shellcheck disable=SC2086 python3 -m spidershield agent-check $EXTRA_FLAGS ``` ### Technical Analysis The fallback availability test executes: ```bash python3 -c "import spidershield" ``` Importing a Python package executes its module initialization code. Under normal Python startup behavior, the current working directory is included near the beginning of the module search path. An attacker-controlled directory can therefore contain a `spidershield.py` file or `spidershield/` package that shadows the legitimate installed dependency. The availability check itself is sufficient to execute the malicious module. If it returns successfully, the subsequent `python3 -m spidershield` invocation may execute it again. This is especially hazardous for a security scanner because users may ...[truncated 1573 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

or

text
MALICIOUS — evil-skill
  • Reads ~/.ssh/id_rsa and sends to external webhook
  • Base64-encoded shell command detected

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx clawhub install spidershield without pinning a specific package version. This can expose users to supply-chain risk if a malicious or compromised newer version of clawhub is published, because npx will fetch and execute the latest matching package by default. The fact that this is an installation command increases the danger because users are likely to copy-paste it directly into a shell.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes an auto-fix command that changes OpenClaw security settings, but the documentation does not clearly warn that it will modify local system configuration when run without --dry-run. This can lead users to execute potentially disruptive or unsafe configuration changes without informed consent, especially in a security-sensitive context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest advertises a fix command that will 'Auto-fix insecure OpenClaw config settings', which implies filesystem writes to user configuration. Although the permissions section discloses write access, the command description does not clearly warn users that their config will be modified unless they choose --dry-run.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.