Back to skill

Security audit

Responses Third-Party Prompt Cache Patch

Security checks for vulnerabilities and agentic risk

Overview

The skill openly patches local OpenClaw installation files for a stated prompt-cache behavior change and provides dry-run, backup, validation, and rollback controls.

Install only if you are comfortable editing your local OpenClaw installation. Run the dry-run first, confirm the target root and bundle paths, consider testing with --root on a copied fixture, and keep the rollback script available before restarting the gateway.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/_bundle_patch_common.py (reported line 2)May include surrounding context.

python
#!/usr/bin/env python3
"""Shared helpers for the responses third-party prompt-cache patch skill."""

from __future__ import annotations

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs users to run local patch and rollback scripts that write into an installed OpenClaw dist/ bundle and invoke shell commands, but it declares no permissions or allowed-tools scope. That mismatch is dangerous because a consumer or agent may execute file-write and shell-capable actions without an explicit trust boundary, increasing the risk of unintended modification of a live installation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/_bundle_patch_common.py (reported line 129)May include surrounding context.

python
def _resolve_root_from_systemctl() -> tuple[str, Path] | None:
    try:
        result = subprocess.run(
            ["systemctl", "--user", "show", SYSTEMD_UNIT_NAME, "--property=ExecStart", "--value"],
            capture_output=True,
            text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This helper writes directly to bundle files and creates backup copies via write_text and create_backup, which are safety-relevant filesystem modifications. Although errors are surfaced, the file contains no confirmation prompt before modification and no user-facing disclosure in comments or docstrings describing that installed files will be changed.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/_bundle_patch_common.py (reported line 350)May include surrounding context.

python
def run_node_check(path: Path) -> None:
    try:
        result = subprocess.run(
            ["node", "--check", str(path)],
            capture_output=True,
            text=True,

Static analysis

No suspicious patterns detected.