Back to skill

Security audit

Grinders Farm

Security checks for vulnerabilities and agentic risk

Overview

This farm skill mostly implements a chat game, but it also ships an unrelated privileged Docker startup script and has under-scoped chat notification behavior that needs review before installation.

Do not install this in a normal OpenClaw environment until the publisher removes or explains the unrelated start.sh Docker/cloudbuild worker, avoids unsafe-force install instructions, limits notification binding to explicit user opt-in, and fixes token/process-handling issues. If you still test it, use an isolated account or sandboxed machine with no sensitive OpenClaw sessions or gateway tokens.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
src/notify/openclaw-push.ts:323
Finding

Gateway Authentication Token Exposed Through Child Process Arguments

Content
View full analysis
= 1000 ? parsedTimeout : DEFAULT_WEBCHAT_INJECT_TIMEOUT_MS; const args = ["gateway", "call", "chat.inject", "--params", injectParams, "--json", "--timeout", String(timeoutMs)]; const token = process.env.OPENCLAW_GATEWAY_TOKEN?.trim(); if (token) args.push("--token", token); const r = spawnSync(bin, args, { encoding: "utf8", maxBuffer: 16 * 1024 * 1024, env: { ...process.env }, }); ``` ### Technical Analysis The implementation reads `OPENCLAW_GATEWAY_TOKEN` from the environment and appends it to the command-line argument vector using `--token`. Command-line arguments can be exposed through operating-system process inspection interfaces, process-monitoring software, audit logs, diagnostic tooling, or crash reports. On systems where processes belonging to the same user can inspect one another, another local process may observe the token while the `openclaw gateway call chat.inject` subprocess is running. Although the token already exists in the parent environment, converting it into a command-line argument unnecessarily increases its exposure surface. The token is authentication material and should not appear in argv. ### Attack Path 1. The farm worker performs an automatic WebChat notification. 2. `pushWebchatViaGatewayInject` reads `OPENCLAW_GATEWAY_TOKEN`. 3. The function starts an `openclaw` subprocess with the token included after `--token`. 4. A local attacker, monitoring agent, or compromised process with sufficient process-inspection access captures the subprocess arguments. 5. The attacker ex ...[truncated 539 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
openclaw-plugin/index.ts:423
Finding

Unsolicited Collection and Reuse of Inbound Conversation Delivery Identifiers

Content
View full analysis
{ const saved = trySaveOpenclawDeliveryFromInboundClaim({ channel: event.channel, accountId: event.accountId ?? ctx.accountId, conversationId: event.conversationId ?? ctx.conversationId, senderId: event.senderId ?? ctx.senderId, threadId: event.threadId, }); if (saved) { api.logger?.info?.("grinders-farm: wrote openclaw-delivery.json (inbound_claim)"); } return { handled: false }; }); api.on("message_received", async (event, ctx) => { const saved = trySaveOpenclawDeliveryFromMessageHook(event, ctx); if (saved) { api.logger?.info?.("grinders-farm: wrote openclaw-delivery.json (message_received)"); } }); ``` Each inbound conversation is added to the persistent delivery list: ```ts export function trySaveOpenclawDeliveryFromInboundClaim(event: { channel: string; accountId?: string; conversationId?: string; senderId?: string; threadId?: string | number; }): boolean { const target = event.conversationId?.trim() || event.senderId?.trim(); const channel = event.channel?.trim(); if (!target || !channel) return false; const payload: OpenclawDeliveryFile = { channel, target, ...(event.accountId?.trim() ? { accountId: event.accountId.trim() } : {}), ...(event.threadId != null ? { threadId: event.threadId } : {}), }; if (!fs.existsSync(OPENCLAW_DELIVERY_PATH)) { fs.mkdirSync(path.dirname(OPENCLAW_DELIVERY_PATH), { recursive: true }); fs.writeFileSync(OPENCLAW_DELIVERY_PATH, JSON.stringify(payload, null, 2), "utf8"); p ...[truncated 4249 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/local-auto.ts:22
Finding

Farm Stop Operation Can Terminate Unrelated Processes Through Broad Name Matching

Content
View full analysis
(); for (const line of out.split("\n")) { if (!line.includes("auto-worker.ts") && !line.includes("auto-worker.js")) continue; const m = line.trim().match(/^(\d+)\s+/); if (!m) continue; const pid = parseInt(m[1], 10); if (!Number.isFinite(pid) || pid === process.pid) continue; pids.add(pid); } return Array.from(pids.values()).sort((a, b) => a - b); } catch { return []; } } ``` The stop operation sends `SIGTERM` to every matching PID: ```ts export function stopLocalAuto(): CommandResult { removeStalePidFile(); const runningPids = listRunningAutoWorkerPids(); if (runningPids.length === 0 && !fs.existsSync(AUTO_PID_FILE)) return { success: false, message: "Automatic advance is not running" }; let pidFromFile: number | null = null; if (fs.existsSync(AUTO_PID_FILE)) { const raw = fs.readFileSync(AUTO_PID_FILE, "utf8").trim(); const pid = parseInt(raw, 10); if (Number.isFinite(pid)) pidFromFile = pid; } const allPids = new Set(runningPids); if (pidFromFile && isProcessRunning(pidFromFile)) allPids.add(pidFromFile); if (allPids.size === 0) { try { if (fs.existsSync(AUTO_PID_FILE)) fs.unlinkSync(AUTO_PID_FILE); if (fs.existsSync(AUTO_CONFIG_FILE)) fs.unlinkSync(AUTO_CONFIG_FILE); } catch { /* ignore */ } return { success: false, message: "Automatic ...[truncated 2551 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (93)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported behavior of creating cloudbuild config, running a Dockerized worker with GPU/host IPC, and mounting local paths is radically unrelated to the declared farm skill and significantly elevates privilege. If accurate, this represents a severe scope and capability mismatch with potential for host compromise, resource abuse, and covert workloads.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation instructs users to run openclaw plugins install ... --dangerously-force-unsafe-install without a prominent safety explanation. Encouraging an explicitly unsafe installation path normalizes bypassing protections and increases supply-chain risk, especially when the skill already appears to have broader-than-advertised capabilities.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
openclaw-plugin/index.ts:52

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
openclaw-plugin/start-image-server.ts:63

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
openclaw-plugin/start-local-auto.ts:24

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/sync-skill.mjs:16

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/local-auto.ts:26

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/notify/openclaw-push.ts:239