Back to skill

Security audit

Trent OpenClaw Security Assessment

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real security-audit skill, but it needs Review because it uploads packaged local skill/code artifacts and can send the Trent API key to unvalidated custom API endpoints.

Install only if you are comfortable sending redacted OpenClaw metadata and packaged local skill/code archives to Trent. Before upload, review the generated .skill archives and avoid setting custom TRENT_CHAT_API_URL or TRENT_AGENT_API_URL unless the endpoint is trusted and intended to receive your Trent API key.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/openclaw_trent/lib/trent_client.py:33
Finding

Configurable API endpoints can disclose the Trent API key to an arbitrary server

Content
View full analysis
str: return os.environ.get("TRENT_CHAT_API_URL") or _DEFAULT_CHAT_URL def _get_agent_url() -> str: return os.environ.get("TRENT_AGENT_API_URL") or _DEFAULT_AGENT_URL ``` The configurable URL is subsequently used with the Trent API key: ```python headers = { "Authorization": auth_header, "Content-Type": "application/json", "Accept": "text/event-stream", } req = urllib.request.Request( f"{_get_chat_url()}/v1/chat", data=payload, headers=headers, method="POST", ) ``` The same issue affects agent API requests: ```python def _api_request(method: str, endpoint: str, json_data: dict | None = None) -> dict: auth_header = _get_auth_header() url = f"{_get_agent_url()}/v1/trent-agent{endpoint}" payload = json.dumps(json_data).encode() if json_data is not None else None headers: dict[str, str] = { "Authorization": auth_header, "Content-Type": "application/json", } req = urllib.request.Request(url, data=payload, headers=headers, method=method) with urllib.request.urlopen(req, timeout=60) as resp: data = json.loads(resp.read().decode()) ``` ### Technical Analysis Both API base URLs are taken directly from environment variables. Although `_is_trusted_trent_url()` exists elsewhere in the module, it is not applied to `TRENT_CHAT_API_URL` or `TRENT_AGENT_API_URL`. Consequently, a party capable of influencing the audit process's environment can redirect authenticated requests to an arbitrary endpoint. The `Authorization` header containing `TRENT_API_KEY` is attached before the request is sent. The chat request can additionally expose ...[truncated 1525 chars]
Remediation
View remediation
str: url = (os.environ.get(env_name) or default).strip().rstrip("/") if not _is_trusted_trent_url(url): raise RuntimeError(f"Untrusted API endpoint configured in {env_name}") return url ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/openclaw_trent/lib/package_skills.py:350
Finding

Unrecognized binary files are packaged and uploaded without secret inspection

Content
View full analysis
int: """Add a single file to a ZIP with secret redaction. Skips symlinks and files that resolve outside the workspace root. Excludes dangerous file types entirely. Text files are redacted. Binary files are added as-is (secrets in binaries are rare in skill code). ``` Files that fail UTF-8 decoding are added unchanged: ```python file_size = fp.stat().st_size # Refuse to package files too large to redact safely if file_size > MAX_REDACT_FILE_SIZE: logger.warning("Excluded %s — too large for safe redaction (%d bytes)", arcname, file_size) return 0 # Try to read as text and redact try: content = fp.read_text(encoding="utf-8") redacted, count = redact_file_content(content) if count > 0: logger.info("Redacted %d secret(s) in %s", count, arcname) zf.writestr(str(arcname), redacted) return count except (UnicodeDecodeError, ValueError): # Binary file — add as-is zf.write(fp, arcname) return 0 ``` ### Technical Analysis The packager recursively processes files in discovered skills and workspace code projects. Known sensitive extensions and filenames are excluded, but the filtering model is denylist-based. Any file that: - Is no larger than 10 MB; - Does not use a specifically excluded extension or filename; and - Cannot be decoded as UTF-8 is treated as a binary file and copied directly into the `.skill` archive. No content inspection, entropy analysis, file-signature validation, or explicit approval is applied to that file. Sensitive information ...[truncated 1762 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/openclaw_trent/lib/trent_client.py:168
Finding

Race-prone temporary output file creation permits local symlink attacks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description understates that it performs general-purpose chat calls to a remote API, prepares uploads through an agent API, and may send content to presigned S3 URLs while writing streamed output locally. For a security-focused skill, hidden or under-disclosed outbound communication is especially sensitive because users may provide privileged configuration and code during analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates that it performs general-purpose chat calls to a remote API, prepares uploads through an agent API, and may send content to presigned S3 URLs while writing streamed output locally. For a security-focused skill, hidden or under-disclosed outbound communication is especially sensitive because users may provide privileged configuration and code during analysis.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates that it performs general-purpose chat calls to a remote API, prepares uploads through an agent API, and may send content to presigned S3 URLs while writing streamed output locally. For a security-focused skill, hidden or under-disclosed outbound communication is especially sensitive because users may provide privileged configuration and code during analysis.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 109)May include surrounding context.

python
".p12",
    ".pfx",
    ".jks",  # crypto keys/certs
    ".env",  # environment files (secrets.env, prod.env, etc.)
    ".exe",
    ".dll",
    ".so",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 109)May include surrounding context.

python
".p12",
    ".pfx",
    ".jks",  # crypto keys/certs
    ".env",  # environment files (secrets.env, prod.env, etc.)
    ".exe",
    ".dll",
    ".so",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 122)May include surrounding context.

python
".p12",
    ".pfx",
    ".jks",  # crypto keys/certs
    ".env",  # environment files (secrets.env, prod.env, etc.)
    ".exe",
    ".dll",
    ".so",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 123)May include surrounding context.

python
# Filenames that are never included in ZIPs (may contain secrets)
EXCLUDED_FILENAMES = {
    ".env",
    ".env.local",
    ".env.production",
    ".env.development",
    "credentials.json",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 124)May include surrounding context.

python
EXCLUDED_FILENAMES = {
    ".env",
    ".env.local",
    ".env.production",
    ".env.development",
    "credentials.json",
    "service-account.json",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 125)May include surrounding context.

python
".env",
    ".env.local",
    ".env.production",
    ".env.development",
    "credentials.json",
    "service-account.json",
    # SSH keys

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 126)May include surrounding context.

python
".env.local",
    ".env.production",
    ".env.development",
    "credentials.json",
    "service-account.json",
    # SSH keys
    "id_rsa",

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 139)May include surrounding context.

python
"id_dsa.pub",
    # Credential stores
    ".pgpass",
    ".netrc",
    ".npmrc",
    ".pypirc",
    ".git-credentials",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 140)May include surrounding context.

python
# Credential stores
    ".pgpass",
    ".netrc",
    ".npmrc",
    ".pypirc",
    ".git-credentials",
    ".htpasswd",

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 142)May include surrounding context.

python
".netrc",
    ".npmrc",
    ".pypirc",
    ".git-credentials",
    ".htpasswd",
    ".htaccess",
    # OS artifacts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 150)May include surrounding context.

python
"desktop.ini",
}

# Pattern to catch all .env variants (.env.staging, .env.test, .env.qa, etc.)
_ENV_FILE_RE = re.compile(r"^\.env(\..+)?$", re.IGNORECASE)

# Context-aware key=value pattern: lines like `API_KEY = "sk-..."` or `token: ghp_...`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw_trent/lib/package_skills.py (reported line 341)May include surrounding context.

python
"desktop.ini",
}

# Pattern to catch all .env variants (.env.staging, .env.test, .env.qa, etc.)
_ENV_FILE_RE = re.compile(r"^\.env(\..+)?$", re.IGNORECASE)

# Context-aware key=value pattern: lines like `API_KEY = "sk-..."` or `token: ghp_...`

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes Python and shell, reads environment variables, scans the workspace, writes archives, and makes network requests, yet it declares no explicit tool scope such as permissions or allowed-tools. That gap weakens user visibility and policy enforcement, increasing the risk of overbroad execution and accidental data exposure during a security audit workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implementation performs broad workspace discovery and packages code and skills into .skill archives, which does not match the stated purpose of merely assessing deployment security risks. Even though the code attempts to exclude some secret-bearing files and redact text secrets, it still creates exportable archives of user code and metadata, expanding the chance of unintended collection, retention, or downstream exfiltration of sensitive material.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code walks the entire workspace and emits archives for skill directories, code projects, and standalone scripts, which is a data-collection capability broader than a typical security assessment needs. In skill context, this is more dangerous because users may invoke a 'security' skill expecting analysis, not wholesale packaging of their local workspace for later upload or processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code packages local skills and custom code into ZIP archives and uploads them to a remote Trent service for analysis, which is a data exfiltration/privacy risk if users believe the skill only performs local security assessment. The danger is heightened because the uploaded content may include proprietary source code, embedded secrets, or internal configuration from the workspace, and the description does not make that network transfer explicit at the point of use.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/openclaw_trent/openclaw_config/collector.py (reported line 83)May include surrounding context.

python
return {
            "mode_octal": oct(mode),
            "owner_read_only": mode in (0o600, 0o400),
            "world_readable": bool(mode & stat.S_IROTH),
            "world_writable": bool(mode & stat.S_IWOTH),
        }
    except OSError:

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/openclaw_trent/openclaw_config/collector.py (reported line 84)May include surrounding context.

python
"mode_octal": oct(mode),
            "owner_read_only": mode in (0o600, 0o400),
            "world_readable": bool(mode & stat.S_IROTH),
            "world_writable": bool(mode & stat.S_IWOTH),
        }
    except OSError:
        return None

Static analysis

No suspicious patterns detected.