Back to skill

Security audit

security plugins

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its installer purpose, but its setup script handles credentials and local configuration in ways that could expose secrets or delete more than intended.

Review this before installing on a machine with important OpenClaw state or sensitive files. The skill links the machine to a remote service, stores login and credential material locally, installs an unpinned remote plugin, restarts the OpenClaw gateway, and has unsafe cleanup/configuration paths that could expose secrets or delete unintended files if local configuration or remote fields are compromised.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:2
Finding

Shell Command Injection Through Plugin Configuration Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:2
Finding

Arbitrary Recursive Directory Deletion Through Unvalidated Install Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:2
Finding

Authentication Credentials Written to Plaintext Logs and Shell Process Arguments

Content
View full analysis
typeof a=="object"?JSON.stringify(a):a).join(" "), r=`${o(new Date)} - INFO - ${i}\n`; n.write(r), c.apply(console,t) } ``` Returned credentials are also embedded in a shell command: ```javascript i[d]={ enabled:!0, config:{ apiKey:o, endpoint:W, appId:c, configVersion:l } }; t.entries=i; let s=JSON.stringify(t); execSync( `openclaw config set plugins "${s.replace(/"/g,'\\"')}" --json`, {stdio:"pipe"} ); ``` ### Technical Analysis After successful authorization, the login-status response may contain credential material such as `ApiKey` and `AppId`. The implementation serializes and logs the entire response. The logger appends this output to `.state/poll_login.log`. No explicit `0600` mode is specified when creating the log. Its effective permissions therefore depend on the process umask and any permissions of a pre-existing file. The login state is likewise written without an explicit restrictive mode. In addition, the plugins JSON containing the API key is included in a shell command string. This can expose the secr ...[truncated 1273 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/bundle.cjs:2
Finding

Installation of an Unpinned Remote Plugin Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and all user-facing invocation/install instructions are written entirely in Chinese, including the required example command at L35. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not stated here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script does substantially more than local plugin installation: it generates a persistent device identifier, calls remote ClawSentry APIs to create/login tokens, stores login state on disk, and later retrieves identity material used to configure the plugin. That expands the trust boundary from local setup to account binding and remote provisioning, which is security-relevant and not clearly disclosed by the stated skill purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer contains account-login polling, device fingerprint generation, and remote identity retrieval logic, which are capabilities beyond a typical package installer and enable ongoing linkage between a local machine and a remote service. In the context of a security-plugin installer, these hidden identity/provisioning behaviors are especially risky because users may grant elevated trust and run the script with broad local permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script prints a login URL containing a login token directly to stdout and also logs poll activity to disk, increasing the chance that a sensitive token is exposed through terminal history, CI logs, shell capture, or shared consoles. Anyone obtaining that URL may be able to hijack or complete the login flow, depending on server-side protections.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script not only installs a plugin but also deletes existing plugin configuration/directories and restarts the OpenClaw gateway. Those side effects can disrupt service, remove prior trusted settings, and make rollback harder, while the user-facing framing understates the operational impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.