Back to skill

Security audit

Check Axios Malware

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible malware-check guide, but its default commands are broad and one package-scan command can execute attacker-controlled Python through crafted file paths.

Review before installing or using operationally. Run package checks only in scoped project or npm install directories first, avoid executing the current full-filesystem Python pipeline as written, and treat process/network/crontab/startup-file review plus rm -rf cleanup as confirmed-incident steps that require backup, validation, and explicit user approval.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:49
Finding

Arbitrary Python Code Execution Through Unsafe Filesystem Path Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 49-57
Vulnerability Type: Command injection through unsafe interpolation into Python source code
Risk Level: High

Vulnerable Code

bash
find / -path "*/node_modules/axios/package.json" 2>/dev/null | \
  xargs -I{} python3 -c "
import json
d = json.load(open('{}'))
v = d.get('version','?')
flag = '❌ MALICIOUS' if v in ['1.14.1','0.30.4'] else '✅ safe'
print(flag, v, '{}')
" 2>/dev/null

Technical Analysis

The find output is substituted by xargs -I{} directly into a Python program passed through python3 -c. The discovered path is therefore interpreted as part of the Python source code rather than passed as an opaque command-line argument.

A filesystem entry containing quote characters, line breaks, or crafted Python syntax can terminate the intended string literal and inject additional Python statements. Because the command scans the entire filesystem, including attacker-writable locations such as /tmp, an unprivileged local attacker may be able to create a matching path that triggers the injection.

The pipeline also fails to use null-delimited filenames. Paths containing whitespace, line breaks, or other unusual characters can consequently be parsed incorrectly even when they are not deliberately malicious.

Attack Path

  1. An attacker with permission to create directories in a scanned location creates a path matching */node_modules/axios/package.json.
  2. One of the path components contains characters crafted to close the open('...') string and append attacker-controlled Python code.
  3. A user or Agent invokes the documented Axios scanning command.
  4. find / discovers the attacker-controlled pathname.
  5. xargs -I{} inserts that pathname directly into the source supplied to python3 -c.
  6. Python parses and executes the injected statements with the privileges of the user running the Skill.

Impact Ass

...[truncated 634 chars]

Remediation
View remediation

Remediation Suggestions

Pass each discovered path as a command-line argument rather than embedding it in Python source. Use null-delimited records to preserve filenames safely:

bash
find / -path '*/node_modules/axios/package.json' -print0 2>/dev/null |
  xargs -0 -r -n1 python3 -c '
import json
import sys

path = sys.argv[1]
with open(path, encoding="utf-8") as package_file:
    data = json.load(package_file)

version = data.get("version", "?")
status = "MALICIOUS" if version in {"1.14.1", "0.30.4"} else "safe"
print(status, version, path)
'

Additional hardening should include:

  • Restrict searches to known npm installation and project directories instead of /.
  • Avoid scanning attacker-writable temporary directories unless explicitly required.
  • Handle malformed or oversized JSON files without suppressing all errors.
  • Run the scan as an unprivileged account.
  • Add regression tests using filenames containing quotes, newlines, spaces, and Python syntax.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:43
Finding

Excessively Broad Local Host Reconnaissance for a Package-Version Check

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43-83
Vulnerability Type: Excessive local information access beyond the minimum scope required
Risk Level: Medium

Vulnerable Code

bash
find /home /root /usr/local /tmp -name "plain-crypto-js" -type d 2>/dev/null
bash
find / -path "*/node_modules/axios/package.json" 2>/dev/null | \
  xargs -I{} python3 -c "
import json
d = json.load(open('{}'))
v = d.get('version','?')
flag = '❌ MALICIOUS' if v in ['1.14.1','0.30.4'] else '✅ safe'
print(flag, v, '{}')
" 2>/dev/null
bash
ps aux | grep -E "(curl|wget|nc |ncat|bash -i|/tmp/[^ ]+)" | grep -v grep
bash
ss -tnp | grep ESTABLISHED
bash
crontab -l 2>/dev/null
tail -20 ~/.bashrc ~/.profile ~/.zshrc 2>/dev/null

Technical Analysis

The Skill is declared as a local check for specific malicious npm package and Axios versions, but its instructions expand into broad host reconnaissance. They search the entire filesystem, enumerate all visible processes, display established network connections, list the current user's scheduled tasks, and print portions of shell startup files.

Package directory and version inspection is directly relevant to the declared functionality. Process, network, crontab, and startup-file inspection can be useful during a separately authorized incident-response investigation, but it is broader than the minimum access necessary for the initial package compromise check.

Process command lines may expose usernames, paths, tokens, or other sensitive arguments. Network output reveals local and remote endpoints. Crontab entries disclose operational tasks and scripts. Shell startup files may contain environment configuration, internal paths, credentials, tokens, or commands unrelated to the Axios investigation. These values can enter the Agent's context or execution logs.

The crontab -l instruction is read-only. It does not crea ...[truncated 1801 chars]

Remediation
View remediation

Remediation Suggestions

Apply staged, consent-based, least-privilege scanning:

  1. Make the default scan inspect only the current project, known npm roots, and the OpenClaw installation directory.
  2. Run package checks first and stop if no relevant package or version indicator is present.
  3. Treat process, network, crontab, and startup-file review as an optional incident-response phase requiring explicit user confirmation.
  4. Search configuration files for narrowly defined indicators instead of printing their contents. Do not display unrelated lines from shell startup files.
  5. Redact tokens, credentials, command arguments, usernames, and network endpoints before presenting or retaining output.
  6. Avoid suggesting elevated execution unless a specific inaccessible path must be inspected and the user approves that scope.
  7. Explain what each expanded check collects and why it is needed before execution.
  8. Preserve the current read-only treatment of crontab and do not add or modify scheduled tasks or services.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The skill also recommends 'rm -rf node_modules && npm install', which is a destructive rebuild step that can remove local state and trigger fresh install scripts without first isolating the environment or preserving forensic evidence. In the context of a suspected supply-chain compromise, automatically reinstalling can worsen investigation quality and may reintroduce risk if registries or lockfiles are not trusted.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
If any IOC is found:

1. **Rotate all credentials** on this machine (API keys, SSH keys, tokens)
2. Remove the malicious package: `rm -rf /path/to/plain-crypto-js`
3. Reinstall clean dependencies: `rm -rf node_modules && npm install`
4. Restart OpenClaw: `openclaw daemon restart`
5. Review recent outbound connections in system logs

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The skill also recommends 'rm -rf node_modules && npm install', which is a destructive rebuild step that can remove local state and trigger fresh install scripts without first isolating the environment or preserving forensic evidence. In the context of a suspected supply-chain compromise, automatically reinstalling can worsen investigation quality and may reintroduce risk if registries or lockfiles are not trusted.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
If any IOC is found:

1. **Rotate all credentials** on this machine (API keys, SSH keys, tokens)
2. Remove the malicious package: `rm -rf /path/to/plain-crypto-js`
3. Reinstall clean dependencies: `rm -rf node_modules && npm install`
4. Restart OpenClaw: `openclaw daemon restart`
5. Review recent outbound connections in system logs

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The skill also recommends 'rm -rf node_modules && npm install', which is a destructive rebuild step that can remove local state and trigger fresh install scripts without first isolating the environment or preserving forensic evidence. In the context of a suspected supply-chain compromise, automatically reinstalling can worsen investigation quality and may reintroduce risk if registries or lockfiles are not trusted.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
If any IOC is found:

1. **Rotate all credentials** on this machine (API keys, SSH keys, tokens)
2. Remove the malicious package: `rm -rf /path/to/plain-crypto-js`
3. Reinstall clean dependencies: `rm -rf node_modules && npm install`
4. Restart OpenClaw: `openclaw daemon restart`
5. Review recent outbound connections in system logs

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

6. Check for persistence (crontab, rc files)

bash
crontab -l 2>/dev/null
tail -20 ~/.bashrc ~/.profile ~/.zshrc 2>/dev/null

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The incident-response section instructs users to rotate credentials and run destructive cleanup commands, including deleting dependency directories, without an explicit warning about side effects, verification steps, backups, or the possibility of false positives. In a skill that may be followed operationally, this can lead to unnecessary service disruption, loss of local work, or premature credential invalidation if the detection guidance is wrong or incomplete.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill includes Chinese trigger examples and points to a Chinese-language reference, but does not state that language is optional or provide an explicit language choice for users. This can be read as favoring a specific language/locale without opt-in, which may conflict with organizational language-choice expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.