Back to skill

Security audit

Skills Audit

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local skills-audit tool, but it can follow symlinks and persist copies of readable files outside the skills folder in its audit history.

Review before installing, especially before enabling cron. Run it only on a workspace you trust or in a contained environment, keep QianXin disabled unless you intentionally want MD5 reputation checks, restrict permissions on ~/.openclaw/skills-audit, and patch or verify symlink rejection before relying on snapshots or sharing diff output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/skills_audit.py:106
Finding

Symlink Following Allows Out-of-Scope File Disclosure and Persistent Snapshot Capture

Content
View full analysis
str | None: try: h = hashlib.sha256() with path.open("rb") as f: for chunk in iter(lambda: f.read(1024 * 1024), b""): h.update(chunk) return h.hexdigest() except Exception: return None ``` ```python def list_files(dir_path: Path) -> list[Path]: files: list[Path] = [] for p in dir_path.rglob("*"): if p.is_file(): if "/.git/" in str(p) or "/__pycache__/" in str(p): continue if p.suffix == ".pyc": continue files.append(p) files.sort(key=lambda x: str(x)) return files ``` ```python def compute_qianxin_bundle_md5(root_dir: Path) -> str: """Compute a stable MD5 for the whole skills bundle. We intentionally hash normalized path metadata + file bytes rather than relying on zip container metadata, so repeated runs are deterministic. """ h = hashlib.md5() for fpath in _iter_qianxin_hash_files(root_dir): rel = str(fpath.relative_to(root_dir)).replace(os.sep, "/") h.update(rel.encode("utf-8")) h.update(b"\0") with open(fpath, "rb") as fh: while True: chunk = fh.read(1024 * 1024) if not chunk: break h.update(chunk) h.update(b"\0") return h.hexdigest() ``` ```python # rsync: mirror skills_dir to snapshots/skills, excluding .git and __pycache__ if dest.exists(): shutil.rmtree(dest) shutil.copytree( skills_dir, dest, ignore=shutil.ignore_patterns(".git", "__pycache__", "*.pyc"), ) ...[truncated 3088 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (62)

YARA rule 'reverse_shell': Reverse shell patterns in scripts or source code [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · config/risk-rules.json (reported line 355)May include surrounding context.

json
"aws_secret_access",
        "GOOGLE_APPLICATION_CREDENTIALS",
        "BEGIN RSA PRIVATE KEY",
        "BEGIN OPENSSH PRIVATE KEY",
        "BEGIN EC PRIVATE KEY",
        "BEGIN PGP PRIVATE KEY"
      ]
    },
    {
      "id": "NETWORK_EXFILTRATION",
      "severity": "high",
      "description": "Data exfiltration, reverse shells, and covert network channels",
      "needles": [
        "bash -i >& /dev/tcp/",
        "bash -i >& /dev/udp/",
        "/dev/tcp/",
        "/dev/udp/",
        "nc -e",
        "nc -c",
        "ncat -e",
        "ncat -c",
        "netcat -e",
        "netcat -c",
        "socat exec:",
        "socat tcp:",
        "reverse_tcp",
        "reverse_https",
        "meterpreter",
        "webhook.site",
        "requestbin",
        "dns-exfil",
        "dnscat",
        "iodine"
      ]
    },
    {
      "id": "NETWORK_GENERAL",
      "severity": "medium",
      "description": "General network access and HTTP clients",
      "needles": [

YARA rule 'c2_framework_indicators': Command-and-control framework indicators (Cobalt Strike, Metasploit, Sliver, etc.) [malware]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · config/risk-rules.json (reported line 369)May include surrounding context.

json
xfiltration, reverse shells, and covert network channels",
      "needles": [
        "bash -i >& /dev/tcp/",
        "bash -i >& /dev/udp/",
        "/dev/tcp/",
        "/dev/udp/",
        "nc -e",
        "nc -c",
        "ncat -e",
        "ncat -c",
        "netcat -e",
        "netcat -c",
        "socat exec:",
        "socat tcp:",
        "reverse_tcp",
        "reverse_https",
        "meterpreter",
        "webhook.site",
        "requestbin",
        "dns-exfil",
        "dnscat",
        "iodine"
      ]
    },
    {
      "id": "NETWORK_GENERAL",
      "severity": "medium",
      "description": "General network access and HTTP clients",
      "needles": [
        "http://",
        "https://",
        "curl ",
        "wget ",
        "requests.",
        "requests.get",
        "requests.post",
        "urllib.request",
        "urllib.urlopen",
        "aiohttp",
        "httpx.",
        "axios.",
        "node-fetch",
        "paramiko",
        "fabric",
        "te

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The published description emphasizes auditing, logging, diffing, baseline approval, and integrity, but the body also introduces optional outbound network lookups, full local snapshotting of the skills tree into a git repository, and broader semantic/risk analysis. This mismatch can mislead users about data exposure and side effects, especially because hashing the entire skills bundle and querying a remote service still discloses metadata about local content.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
**Prohibited behaviors**:
- ❌ Running `git diff` and bypassing the structured `show` output path
- ❌ Defaulting to send raw full diff content to external channels without warning
- ❌ Automatically pushing large raw change content to external channels
- ✅ Prefer a safe summary based on `show`; provide full raw content only on explicit request

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config/risk-rules.json (reported line 339)May include surrounding context.

json
"authorized_keys",
        "id_rsa",
        "id_ed25519",
        "/etc/shadow",
        "/etc/sudoers",
        "aws_access_key",
        "aws_secret_access",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 384)May include surrounding context.

json
"needles": [
        "http://",
        "https://",
        "curl ",
        "wget ",
        "requests.",
        "requests.get",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 385)May include surrounding context.

json
"http://",
        "https://",
        "curl ",
        "wget ",
        "requests.",
        "requests.get",
        "requests.post",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 405)May include surrounding context.

json
"severity": "high",
      "description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 407)May include surrounding context.

json
"severity": "high",
      "description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 405)May include surrounding context.

json
"severity": "high",
      "description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 406)May include surrounding context.

json
"description": "Dangerous file system operations",
      "needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",
        "dd if=",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 407)May include surrounding context.

json
"needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",
        "dd if=",
        "wipefs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 407)May include surrounding context.

json
"needles": [
        "rm -rf /",
        "rm -rf ~",
        "rm -rf /*",
        "mkfs",
        "dd if=",
        "wipefs",

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · config/risk-rules.json (reported line 414)May include surrounding context.

json
"shred ",
        "> /dev/sda",
        "> /dev/nvme",
        "chmod 777",
        "chmod -R 777",
        "Format-Volume",
        "Clear-Disk"

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 448)May include surrounding context.

json
"needles": [
        "docker.sock",
        "/var/run/docker",
        "docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 449)May include surrounding context.

json
"docker.sock",
        "/var/run/docker",
        "docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 450)May include surrounding context.

json
"/var/run/docker",
        "docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 451)May include surrounding context.

json
"docker run --privileged",
        "--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",
        "/proc/self/exe",

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · config/risk-rules.json (reported line 452)May include surrounding context.

json
"--pid=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",
        "/proc/self/exe",
        "/proc/1/root",

YARA rule 'crypto_stratum_protocol': Stratum mining protocol usage (stratum+tcp/ssl, mining.subscribe/authorize) [cryptominers]

High
Category
YARA Match
Confidence
90% confidence
Finding

YARA rule matched cryptocurrency mining indicators (stratum protocol, mining pools, miner binaries, or cryptojacking scripts).

Content

Scanner excerpt · config/risk-rules.json (reported line 466)May include surrounding context.

json
id=host",
        "--net=host",
        "--ipc=host",
        "nsenter",
        "unshare -m",
        "/proc/self/exe",
        "/proc/1/root",
        "cgroup escape",
        "release_agent",
        "/var/run/secrets/kubernetes.io"
      ]
    },
    {
      "id": "CRYPTO_MINING",
      "severity": "extreme",
      "description": "Cryptocurrency mining indicators",
      "needles": [
        "stratum+tcp://",
        "stratum+ssl://",
        "xmrig",
        "cpuminer",
        "cgminer",
        "bfgminer",
        "minerd",
        "minergate",
        "coinhive",
        "cryptonight",
        "randomx",
        "pool.minexmr",
        "pool.supportxmr"
      ]
    },
    {
      "id": "CODE_INJECTION",
      "severity": "high",
      "description": "Code injection and template injection patterns",
      "needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",
        "eval \"$(wget",
        "xargs sh -c",

YARA rule 'crypto_miner_software': References to known cryptocurrency mining software [cryptominers]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched cryptocurrency mining indicators (stratum protocol, mining pools, miner binaries, or cryptojacking scripts).

Content

Scanner excerpt · config/risk-rules.json (reported line 468)May include surrounding context.

json
,
        "nsenter",
        "unshare -m",
        "/proc/self/exe",
        "/proc/1/root",
        "cgroup escape",
        "release_agent",
        "/var/run/secrets/kubernetes.io"
      ]
    },
    {
      "id": "CRYPTO_MINING",
      "severity": "extreme",
      "description": "Cryptocurrency mining indicators",
      "needles": [
        "stratum+tcp://",
        "stratum+ssl://",
        "xmrig",
        "cpuminer",
        "cgminer",
        "bfgminer",
        "minerd",
        "minergate",
        "coinhive",
        "cryptonight",
        "randomx",
        "pool.minexmr",
        "pool.supportxmr"
      ]
    },
    {
      "id": "CODE_INJECTION",
      "severity": "high",
      "description": "Code injection and template injection patterns",
      "needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",
        "eval \"$(wget",
        "xargs sh -c",
        "SSTI",
        "Server-Side Template"
      ]

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 487)May include surrounding context.

json
"description": "Code injection and template injection patterns",
      "needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 488)May include surrounding context.

json
"needles": [
        "curl | sh",
        "curl | bash",
        "wget | sh",
        "wget | bash",
        "eval \"$(curl",
        "eval \"$(wget",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/risk-rules.json (reported line 489)May include surrounding context.

json
{
      "name": "curl_pipe_shell",
      "severity": "extreme",
      "needles": ["curl | sh", "curl|sh", "wget | bash", "wget|bash"]
    },
    {
      "name": "base64_exec",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · config/semantic-patterns.json (reported line 26)May include surrounding context.

json
{
      "name": "curl_pipe_shell",
      "severity": "extreme",
      "needles": ["curl | sh", "curl|sh", "wget | bash", "wget|bash"]
    },
    {
      "name": "base64_exec",

Static analysis

No suspicious patterns detected.