Back to skill

Security audit

Openclaw Skill Bitwarden

Security checks for vulnerabilities and agentic risk

Overview

This Bitwarden/Vaultwarden skill is purpose-aligned but needs Review because it gives an agent broad access to a password vault while handling master passwords and session tokens in ways that are not tightly scoped or safely contained.

Install only if you are comfortable giving an agent access to your Bitwarden/Vaultwarden account. Use a dedicated low-privilege vault account if possible, configure manual approval for any retrieve/create/edit/delete/register operation, keep BW_SERVER pinned to a trusted HTTPS endpoint, avoid putting the master password in shell commands, and treat the /tmp session cache as sensitive.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
bw.sh:184
Finding

Sensitive authentication data may be transmitted to an untrusted or plaintext endpoint

Content
View full analysis
/dev/null 2>&1 || true ``` ```python # Submit registration r = requests.post(f'{server}/api/accounts/register', json={ 'name': name, 'email': email, 'masterPasswordHash': master_password_hash, 'masterPasswordHint': '', 'key': encrypted_key, 'kdf': 0, 'kdfIterations': kdf_iterations, }, timeout=30) ``` ### Technical Analysis The script accepts `BW_SERVER` from an environment variable or credential file and uses it without validating its scheme, hostname, port, or URL structure. The value is supplied both to the Bitwarden CLI and directly to `requests.post`. The registration request contains the account email, master-password verifier, encrypted account key, and key-derivation parameters. Base64 encoding of `masterPasswordHash` is required by the Bitwarden-compatible registration protocol and is not, by itself, evidence of covert exfiltration. Nevertheless, the verifier remains sensitive authentication material. The project documentation states that communication uses HTTPS, but the implementation does not enforce that requirement. A value such as `http://attacker.example` is accepted. The endpoint may also be changed to an arbitrary HTTPS server controlled by an attacker. TLS certificate verification by `requests` protects correctly configured HTTPS connections but does not protect against an intentionally or maliciously changed destination. Network transmission is necessary for the declared Bitwarden/Vaultwarden functionality. The issue is that the implementation grants the configured endpoint unrestricted control over where authentication material is sent, exceeding a safe least-privilege design unless the configuration is strongly protected and validated. ...[truncated 1327 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
bw.sh:90
Finding

Master passwords are exposed through process command-line arguments

Content
View full analysis
/dev/null) ``` ```bash python3 -c " # Registration implementation omitted here only outside the executed string; # the actual script receives the password through sys.argv[2]. email = sys.argv[1] password = sys.argv[2] name = sys.argv[3] server = sys.argv[4] ... " "$reg_email" "$reg_pass" "$reg_name" "$BW_SERVER" ``` ```bash cmd="${1:-help}" shift || true case "$cmd" in register) do_register "$@" ;; ``` The corresponding registration input assignment is: ```bash local reg_email="${1:-$BW_EMAIL}" local reg_pass="${2:-$BW_MASTER_PASSWORD}" local reg_name="${3:-OpenClaw}" ``` ### Technical Analysis The login operation supplies `BW_MASTER_PASSWORD` as a positional argument to the `bw` process. The registration operation similarly supplies `reg_pass` as a positional argument to `python3`, where it is read through `sys.argv[2]`. The public command interface also permits the master password to be supplied directly as an argument to `bw.sh register`. On systems where process command lines are visible, another local user, monitoring agent, debugging utility, audit subsystem, process collector, or orchestration platform may capture these arguments. Direct interactive invocation may additionally preserve an explicitly supplied password in shell history. Suppressing standard error does not protect process arguments. Environment variables also require careful treatment, but a protected standard-input or file-descriptor interface generally avoids broad command-line exposure. Handling a master password is inherent to automatic vault login. Exposing it in process metadata is not required for that functionality and therefore exceeds the minimum necessary exposure. ### Attack ...[truncated 1359 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
bw.sh:90
Finding

Vault session token is stored at an unsafe predictable temporary path

Content
View full analysis
/dev/null) echo "$session" > "$SESSION_FILE" chmod 600 "$SESSION_FILE" echo "Logged in successfully." elif [[ "$status" == "locked" ]]; then local session session=$(bw unlock "$BW_MASTER_PASSWORD" --raw 2>/dev/null) echo "$session" > "$SESSION_FILE" chmod 600 "$SESSION_FILE" echo "Vault unlocked." fi ``` ### Technical Analysis The script stores the decrypted-vault session token in the fixed path `/tmp/.bw_session`. That path is shared across accounts, servers, workspaces, and invocations. The write operation uses shell redirection before executing `chmod 600`. Consequently, the file is opened or created using the process's current `umask`, creating a potential interval in which permissions are broader than intended. The code does not create the file exclusively, reject symbolic links, verify ownership, or verify that the existing path is a regular file. Because `/tmp` is normally writable by multiple users, an attacker may pre-create or race the predictable path. Depending on operating-system hardening and ownership rules, this can cause symbolic-link redirection, denial of service, unintended overwrite, or session confusion. Concurrent invocations can also overwrite each other's tokens. Even in a single-user agent environment, multiple configured vault accounts will share the same cache path. Session caching is a convenience rather than an essential requirement for credentia ...[truncated 1787 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (16)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 58)May include surrounding context.

You can also override the credentials file path:

bash
export CREDS_FILE=/path/to/your/credentials.env

Server Configuration Examples

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The README instructs users to store the Bitwarden master password in a persistent plaintext file under the workspace. Even with restrictive permissions, persistent plaintext storage of a master password materially increases compromise impact because any local file disclosure, backup leak, or workspace access exposes the vault's root secret.

Content

Scanner excerpt · README.md (reported line 39)May include surrounding context.

Configuration

Create a credentials file at secrets/bitwarden.env in your OpenClaw workspace:

bash
BW_SERVER=https://vault.bitwarden.com

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

Secure the file:

bash
chmod 600 ~/.openclaw/workspace/secrets/bitwarden.env

Alternatively, set these as environment variables directly.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises a register capability that creates accounts on a remote Bitwarden/Vaultwarden server, which goes beyond the stated purpose of vault credential management. Expanding a skill's authority to remote account creation increases attack surface and could enable unauthorized provisioning or policy bypass if invoked unexpectedly by an agent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The security-improvements section highlights remote account registration as a feature, normalizing an account-creation action unrelated to ordinary password storage and retrieval. In an agent context, this can cause overbroad use of the skill for identity lifecycle actions that should require separate review and authorization.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares capabilities that clearly involve shell execution and network communication, but it does not define any explicit tool scope such as permissions or allowed-tools. In an autonomous agent setting, this weakens containment and makes it easier for the agent to invoke sensitive operations like credential retrieval, vault modification, or remote communication without clear policy boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The autonomous invocation guidance is broad enough to trigger on common tasks involving credentials, password retrieval, or storage, which are highly sensitive actions. In a password-manager skill, overly permissive invocation criteria materially increase the chance of unintended secret access or exfiltration through routine automation flows.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 125)May include surrounding context.

md
local session
    session=$(bw login "$BW_EMAIL" "$BW_MASTER_PASSWORD" --raw 2>/dev/null)
    echo "$session" > "$SESSION_FILE"
    chmod 600 "$SESSION_FILE"
    echo "Logged in successfully."
  elif [[ "$status" == "locked" ]]; then
    local session

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
local session
    session=$(bw login "$BW_EMAIL" "$BW_MASTER_PASSWORD" --raw 2>/dev/null)
    echo "$session" > "$SESSION_FILE"
    chmod 600 "$SESSION_FILE"
    echo "Logged in successfully."
  elif [[ "$status" == "locked" ]]; then
    local session

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
local session
    session=$(bw login "$BW_EMAIL" "$BW_MASTER_PASSWORD" --raw 2>/dev/null)
    echo "$session" > "$SESSION_FILE"
    chmod 600 "$SESSION_FILE"
    echo "Logged in successfully."
  elif [[ "$status" == "locked" ]]; then
    local session

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · bw.sh (reported line 91)May include surrounding context.

sh
local session
    session=$(bw login "$BW_EMAIL" "$BW_MASTER_PASSWORD" --raw 2>/dev/null)
    echo "$session" > "$SESSION_FILE"
    chmod 600 "$SESSION_FILE"
    echo "Logged in successfully."
  elif [[ "$status" == "locked" ]]; then
    local session

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · bw.sh (reported line 97)May include surrounding context.

sh
local session
    session=$(bw login "$BW_EMAIL" "$BW_MASTER_PASSWORD" --raw 2>/dev/null)
    echo "$session" > "$SESSION_FILE"
    chmod 600 "$SESSION_FILE"
    echo "Logged in successfully."
  elif [[ "$status" == "locked" ]]; then
    local session

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The register flow sends the user's email and a derived master-password hash to the user-configured Bitwarden/Vaultwarden server, but there is no confirmation prompt or explicit warning at the point of execution. While the header notes external endpoints generally, the command help does not clearly warn users that registration will transmit credential-related data to whatever BW_SERVER is configured.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · bw.sh (reported line 179)May include surrounding context.

sh
)

# Submit registration
r = requests.post(f'{server}/api/accounts/register', json={
    'name': name,
    'email': email,
    'masterPasswordHash': master_password_hash,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The delete command irreversibly removes vault items with no confirmation, dry-run, or safety interlock. In a credential-management skill, accidental deletion can cause immediate loss of important secrets or service access, especially if invoked by an automated agent or with the wrong identifier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README lists destructive and account-modifying commands such as register, create, edit, delete, lock, and logout without prominent warnings about irreversible changes or service-side effects. In an autonomous or semi-autonomous agent setting, weak safety signaling increases the chance of accidental destructive actions.

Content

No source excerpt is available for this finding.