Back to skill

Security audit

Dead Or Not

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed check-in and emergency-email tool, but it uses persistent cron execution and plaintext SMTP credentials with weak scoping and incomplete notification flow details.

Review carefully before installing. Only use this with a dedicated revocable SMTP app password, owner-only permissions on ~/.openclaw/apps/deadornot and its config, a fixed trusted script path in cron, and a tested opt-in flow that previews recipients and messages. Treat the current package as needing hardening before relying on it for emergency or welfare checks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check.sh:11
Finding

Arbitrary Shell Command Execution Through Executable Configuration

Content
View full analysis

Vulnerability Details

File Location: scripts/check.sh:11-27
Vulnerability Type: Unsafe execution of configuration data
Risk Level: Medium

Vulnerable Code:

bash
# Load config
if [ ! -f "$CONFIG_FILE" ]; then
    mkdir -p "$CONFIG_DIR"
    echo "# DeadOrNot Configuration" > "$CONFIG_FILE"
    echo "TIMEOUT_HOURS=24" >> "$CONFIG_FILE"
    echo "NOTIFY_EMAIL=" >> "$CONFIG_FILE"
    echo "MESSAGE=User is unresponsive!" >> "$CONFIG_FILE"
    echo "ASK_HOUR=10" >> "$CONFIG_FILE"
    echo "SMTP_SERVER=smtp.qq.com" >> "$CONFIG_FILE"
    echo "SMTP_PORT=465" >> "$CONFIG_FILE"
    echo "SMTP_EMAIL=" >> "$CONFIG_FILE"
    echo "SMTP_PASSWORD=" >> "$CONFIG_FILE"
fi

source "$CONFIG_FILE"

Technical Analysis

The configuration file is documented and created as a collection of key-value settings, but source "$CONFIG_FILE" causes Bash to interpret its entire contents as executable shell code. The file can therefore contain command substitutions, redirections, function calls, external commands, or other shell syntax in addition to ordinary assignments.

Any local process or user capable of modifying ~/.openclaw/apps/deadornot/config can insert arbitrary commands. Because check.sh is intended to run automatically through cron, the injected commands will execute when the scheduled job next starts.

The injected code runs with the same operating-system identity and permissions as the account that owns the cron job. This does not directly grant root privileges unless the job is improperly installed under a privileged account, but it provides arbitrary code execution within the affected user account.

Attack Path

  1. An attacker obtains write access to ~/.openclaw/apps/deadornot/config, such as through another compromised process, an overly permissive directory, or shared local-account access.
  2. The attacker appends a shell payload, for example a command that copies user data or launc ...[truncated 786 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not use source, ., or eval to load a data-only configuration file.
  • Parse only explicitly supported keys such as TIMEOUT_HOURS, ASK_HOUR, SMTP_SERVER, and SMTP_PORT.
  • Reject unknown keys, command substitutions, shell metacharacters, multiline values, and malformed records.
  • Validate TIMEOUT_HOURS, ASK_HOUR, and SMTP_PORT as bounded integers before using them in arithmetic or network operations.
  • Prefer a non-executable format such as JSON and parse it with a parser that never evaluates shell code.
  • Create the configuration directory with mode 0700 and configuration file with mode 0600.
  • Before each scheduled execution, verify that the configuration is a regular file owned by the expected user and is not writable by group or other users.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check.sh:11
Finding

Plaintext SMTP Credential Stored Without Enforced Access Restrictions

Content
View full analysis

Vulnerability Details

File Location: scripts/check.sh:11-24 and SKILL.md:31-39
Vulnerability Type: Insecure sensitive credential storage
Risk Level: Medium

Vulnerable Code:

bash
# Load config
if [ ! -f "$CONFIG_FILE" ]; then
    mkdir -p "$CONFIG_DIR"
    echo "# DeadOrNot Configuration" > "$CONFIG_FILE"
    echo "TIMEOUT_HOURS=24" >> "$CONFIG_FILE"
    echo "NOTIFY_EMAIL=" >> "$CONFIG_FILE"
    echo "MESSAGE=User is unresponsive!" >> "$CONFIG_FILE"
    echo "ASK_HOUR=10" >> "$CONFIG_FILE"
    echo "SMTP_SERVER=smtp.qq.com" >> "$CONFIG_FILE"
    echo "SMTP_PORT=465" >> "$CONFIG_FILE"
    echo "SMTP_EMAIL=" >> "$CONFIG_FILE"
    echo "SMTP_PASSWORD=" >> "$CONFIG_FILE"
fi

The documented configuration instructs users to place the credential directly in that file:

bash
NOTIFY_EMAIL=your_email@example.com
MESSAGE=User is unresponsive, please check on them!
TIMEOUT_HOURS=24
ASK_HOUR=10
SMTP_SERVER=smtp.qq.com
SMTP_PORT=465
SMTP_EMAIL=your_qq@qq.com
SMTP_PASSWORD=your_auth_code

Technical Analysis

The Skill stores the SMTP authentication secret as plaintext in ~/.openclaw/apps/deadornot/config. Neither the setup documentation nor the creation logic enforces restrictive permissions on the directory or file.

mkdir -p and shell redirection apply permissions according to the process umask. With a common umask of 022, a newly created directory may be mode 0755 and a newly created configuration file may be mode 0644. This can expose the SMTP email address, recipient address, message, and SMTP password to other local users.

Although plaintext storage may be necessary when no secret-management facility is available, failing to enforce owner-only access exceeds the minimum exposure required by the declared email functionality.

Attack Path

  1. The user follows SKILL.md and stores a valid SMTP app password in the configuration file.
  2. The fil ...[truncated 850 chars]
Remediation
View remediation

Remediation Suggestions

  • Set umask 077 before creating the configuration directory or file.
  • Create the directory with mkdir -m 700 and enforce chmod 700 "$CONFIG_DIR".
  • Create the configuration with mode 0600 and verify its ownership before reading it.
  • Prefer an operating-system keyring, credential helper, or dedicated secret manager instead of storing the SMTP password in the general configuration file.
  • Use a dedicated, least-privileged, revocable SMTP app password rather than the primary email-account password.
  • Document credential rotation and removal procedures.
  • Avoid writing credentials to command output, cron logs, exception messages, or diagnostic files.
  • Warn and refuse to proceed when the configuration is group-readable, world-readable, or owned by an unexpected account.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented behavior promises health checks and emergency email notifications, but the file only describes partial local state and cron setup while omitting the actual mail-sending and reply-handling implementation. This mismatch is dangerous because users may trust the skill for safety-critical notification workflows that it may not actually perform, creating a false sense of protection.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill can automatically contact emergency recipients if the user fails to respond, yet the markdown does not present that as a prominent warning or require explicit opt-in acknowledgment. In a sensitive context involving personal contacts and implied welfare checks, silent or unclear automation can cause privacy harm, false alarms, and unauthorized disclosure of the user's status.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/check.sh (reported line 60)May include surrounding context.

sh
echo "Outside ask hours ($ASK_HOUR-$((ASK_HOUR+2))), skipping"
    fi
else
    rm -f "$CONFIG_DIR/check_flag"
    echo "All good! User is still alive."
fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill describes behavior that relies on environment-backed secrets and configuration such as SMTP credentials, but it does not declare any explicit tool scope or permissions boundary. That ambiguity can cause the runtime to expose more capability than users expect, especially for a skill that may access sensitive configuration and trigger outbound notification behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The "Use when" list includes generic phrases like "Daily health check," "Auto-notify on unresponsive users," and "Setting up check-in reminders" without defining exact trigger phrases, scope limits, or exclusion conditions. In a markdown skill description, this can cause unintended activation because the boundaries of when the skill should be invoked are not clearly specified.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

1. Initialize

bash
mkdir -p ~/.openclaw/apps/deadornot

2. Configure

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The cron installation establishes persistent scheduled execution outside the immediate user session. Persistence is sensitive because it can continue monitoring inactivity and triggering downstream actions such as prompts or notifications without ongoing awareness, and can be abused if the referenced script path is later modified.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

3. Set up Cron

bash
crontab -l | { cat; echo "0 0 * * * /path/to/check.sh >> /path/to/log.txt 2>&1"; } | crontab -

Configuration

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module documentation states 'Configure via config file before use', which implies file-based configuration. However, the implementation loads SMTP server, credentials, recipient, and message content exclusively through os.getenv environment variables.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.