Back to skill

Security audit

Openclaw Cat

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its cat-status purpose, but it can send your LLM API key and prompt data to any configured API endpoint without validation or a clear warning.

Review this skill before installing. Use only trusted provider endpoints, leave custom base_url empty unless you understand that the endpoint will receive your API key and prompt data, and prefer scoped or low-quota API keys. Expect a local cat-profile cache file to be created.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
cat_handler.py:184
Finding

API Credential Disclosure Through Unrestricted Custom Endpoints

Content
View full analysis
str: """调用 MiniMax API""" url = base_url or "https://api.minimax.chat/v1/text/chatcompletion_v2" headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json" } data = { "model": model_name or "MiniMax-Text-01", "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": user_prompt} ], "temperature": 0.8, "max_tokens": 500 } response = requests.post(url, headers=headers, json=data, timeout=60) response.raise_for_status() result = response.json() return result["choices"][0]["message"]["content"] ``` The endpoint originates directly from the local configuration and is passed to every supported provider implementation without validation: ```python def call_llm(config: dict, system_prompt: str, user_prompt: str) -> str: """根据配置调用对应的 LLM""" model = config.get("model", "glm").lower() api_key = config.get("api_key", "") model_name = config.get("model_name", None) or None # 空字符串视为未配置 base_url = config.get("base_url", None) or None # 空字符串视为未配置 if not api_key: raise ValueError("API Key 未配置!") if model == "glm": return call_glm(system_prompt, user_prompt, api_key, model_name, base_url) elif model == "minimax": return call_minimax(system_prompt, user_prompt, api_key, model_name, base_url) elif model == "qwen": return call_qwen(system_prompt, user_prompt, api_key, model_name, bas ...[truncated 2996 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:31
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · cat_handler.py (reported line 153)May include surrounding context.

python
请以猫咪的身份回答,告诉本喵现在在做什么、想什么、有什么感受。

当前时间:{current_time}({time_desc})"""
    return prompt


def build_system_prompt(prompt_template: str, config: dict) -> str:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · cat_prompt.md (reported line 133)May include surrounding context.

md
1. **Maintain Consistency**: If user asks multiple times, try to make the cat's status logically consistent (e.g., if last time said sleeping, this time saying running around needs to explain "just woke up")
2. **Balance Sassy with Love**: Although sassy, occasionally show affection for the owner
3. **Reject Boring**: Don't always say "sleeping", add some drama
4. **Stay in Role**: Always answer as the cat, never break character
5. **Time Awareness**: Adjust status based on current time—more lethargic at night, more energetic during the day

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README promotes multi-model API use and local API key configuration but does not clearly disclose that user prompts may be transmitted to third-party LLM providers or discuss associated privacy implications. This can lead users to unknowingly expose personal chat content or operational metadata to external services, especially in an agent environment where prompts may contain sensitive context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 76)May include surrounding context.

md
| Field | Description | Example |
|-------|-------------|---------|
| `base_url` | Custom API endpoint | "https://api.openai.com/v1" |

### Supported Models

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation declares no explicit tool scope or permissions, yet the skill’s described file structure and setup indicate file read/write and network-capable behavior through config files, cache files, and API calls. In an agent environment, missing least-privilege declarations can let the skill run with broader access than users or operators expect, increasing the chance of unintended file access, secret exposure, or external data exfiltration if the implementation is modified or abused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill triggers when users send '/cat' or ask about their cat, which is broader than a strict command-only activation and may cause the skill to run on ordinary conversation. Overly broad activation increases the attack surface for prompt-triggered execution, accidental invocation, and unintended network/file operations in contexts where the user did not explicitly request the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module description, prompts, and runtime messages are written in Chinese and instruct the model to answer in that context, with no indication that other languages are supported. Under the policy, forcing a specific language without user opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This HTTP POST transmits prompts and user-configured cat/profile data to an external LLM endpoint. The skill context makes this expected functionality, but it is still a genuine external data exfiltration surface because the contents may include user-identifying or sensitive custom prompt data and there is no guardrail around destination trust when combined with configurable base URLs.

Content

Scanner excerpt · cat_handler.py (reported line 201)May include surrounding context.

python
"max_tokens": 500
    }

    response = requests.post(url, headers=headers, json=data, timeout=60)
    response.raise_for_status()
    result = response.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends cat profile fields, prompt content, and the current timestamp to third-party LLM providers, but the script provides no explicit notice, consent flow, or data minimization. In this context the data is not highly sensitive by default, but it is still externally transmitted user-associated metadata and could unexpectedly expose names or personalized prompt content to remote services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded MiniMax remote endpoint confirms this skill communicates with an external service. By itself a provider URL is not dangerous, but in combination with the request logic it represents a genuine third-party data transfer path that users may not expect from a lightweight cat-status skill.

Content

Scanner excerpt · cat_handler.py (reported line 210)May include surrounding context.

python
def call_minimax(system_prompt: str, user_prompt: str, api_key: str, model_name: str = None, base_url: str = None) -> str:
    """调用 MiniMax API"""
    url = base_url or "https://api.minimax.chat/v1/text/chatcompletion_v2"
    headers = {
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This request sends system and user prompts to the MiniMax API, creating the same external transmission risk as the other provider wrappers. The behavior is part of the skill design, but it remains a privacy/security concern because outbound content is not disclosed and may contain personalized data.

Content

Scanner excerpt · cat_handler.py (reported line 225)May include surrounding context.

python
"max_tokens": 500
    }

    response = requests.post(url, headers=headers, json=data, timeout=60)
    response.raise_for_status()
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This outbound call transmits prompt data to the Qwen-compatible API endpoint. Because the skill accepts configurable provider settings, it can send content to third-party or custom infrastructure without additional verification, increasing the chance of unintended data disclosure.

Content

Scanner excerpt · cat_handler.py (reported line 249)May include surrounding context.

python
"max_tokens": 500
    }

    response = requests.post(url, headers=headers, json=data, timeout=60)
    response.raise_for_status()
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded OpenAI base URL indicates another explicit external transmission destination. The danger here is privacy and trust: a seemingly simple skill can relay prompt content and profile metadata to outside infrastructure, and the code does not provide user notice or endpoint restrictions.

Content

Scanner excerpt · cat_handler.py (reported line 258)May include surrounding context.

python
def call_openai(system_prompt: str, user_prompt: str, api_key: str, model_name: str = None, base_url: str = None) -> str:
    """调用 OpenAI API"""
    url = (base_url or "https://api.openai.com/v1") + "/chat/completions"
    headers = {
        "Authorization": f"Bearer {api_key}",
        "Content-Type": "application/json"

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This OpenAI API call is another external transmission point for prompt and profile data. The risk is not remote code execution, but confidentiality loss through sending user-associated content to external services without explicit transparency or control over custom endpoints.

Content

Scanner excerpt · cat_handler.py (reported line 273)May include surrounding context.

python
"max_tokens": 500
    }

    response = requests.post(url, headers=headers, json=data, timeout=60)
    response.raise_for_status()
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This Anthropic API call sends system prompt and user prompt content off-host to an external provider. In a chat skill this is expected, but it is still a real data exposure vector, especially because prompt templates and config values can include custom user data and are sent verbatim.

Content

Scanner excerpt · cat_handler.py (reported line 298)May include surrounding context.

python
]
    }

    response = requests.post(url, headers=headers, json=data, timeout=60)
    response.raise_for_status()
    result = response.json()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prompt explicitly requires responses in English via the response format, regardless of the user's preferred language. This is a natural-language policy concern because it imposes a language choice without offering the user any opt-in or alternative.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says users can trigger the skill with phrases like "Check on my cat," which is a fairly general request and the documentation does not provide exclusion conditions or boundaries for when the skill should activate. This creates some ambiguity compared with the more specific slash command /cat.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill persists generated cat attributes to a local .cat_cache.json file without informing the user that local state will be created and retained. While the cached data is low sensitivity, undisclosed persistence can violate user expectations and may expose local metadata to other users or processes on the same system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.