Back to skill

Security audit

Compliance Audit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local audit logger, but it overstates the strength of its audit trail and may store sensitive activity details in mutable plaintext files.

Install only if you treat this as a convenience activity log, not as a reliable compliance, incident-response, or tamper-proof audit system. Avoid logging secrets, tokens, personal data, or detailed financial/account information unless filesystem permissions and retention are managed separately.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit.py:107
Finding

Audit History Deletion and Truncation Can Pass Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit.py:29
Finding

Malformed Audit Files Are Silently Discarded and Overwritten

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/audit.py:15
Finding

Audit Records Are Stored in Plaintext Without Enforced Private Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents commands that write persistent audit logs to ~/.openclaw/audit/, which is a file-write capability, but it does not declare any tool scope such as permissions or allowed-tools. This creates a transparency and least-privilege gap: an agent or reviewer may invoke the skill without an explicit understanding that it can modify local state and persist potentially sensitive operational data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises an 'immutable' audit trail, but the implementation only maintains a locally stored hash chain over mutable JSON files. This mismatch is dangerous because operators may rely on the logs for governance or incident response, even though a local attacker can edit history and preserve internal consistency by recalculating hashes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code rewrites the entire audit file with normal local file permissions in a user-writable directory, so any process with the same user privileges can alter, truncate, or replace the log and then recompute the hash chain. Because there is no append-only storage, external anchoring, signature, or protected write path, the claimed tamper-evidence is weak and can be bypassed by an attacker who can modify local files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.