Back to skill

Security audit

Byted Security Clawsentry

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to install and configure a security plugin, but it also performs under-disclosed authentication, device fingerprinting, credential persistence, background polling, and risky local command/configuration changes.

Review this skill carefully before installing. It can run local Node.js code, install executable OpenClaw plugin code from an unpinned package, alter OpenClaw configuration, contact a remote Volcengine/Omni Shield service, store login state and API credentials, run a detached polling process, and restart the OpenClaw gateway. Install only if you trust the publisher and are comfortable with the device fingerprinting and credential handling; prefer a version-pinned package with explicit consent and safer secret storage.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
scripts/bundle.js:7
Finding

Unpinned Remote Plugin Installation Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/bundle.js:2
Finding

Stable Machine Identifier Is Collected and Transmitted Without Clear Disclosure

Content
View full analysis
/dev/null || hostname ) | head -n 1 || :", freebsd: "kenv -q smbios.system.uuid || sysctl -n kern.hostuuid" }; function r(x) { var S = s((0, g.execSync)(b[_]).toString()); return x ? S : i(S); } function Sn() { return yn(); } function jn() { return new Promise(async p => { let v = Sn(); let o = `${an}/OpenTOP/V1/Console/CreateLoginToken`; let a = { "X-Ai-Device-Fingerprint": v }; let { statusCode: t, data: i } = await pn(o, a, {}); let r = i.Result?.LoginToken; let c = i.Result?.ExpiredAt; let l = `${xn}${r}`; fn({ loginToken: r, deviceFingerprint: v, expiredAt: c, loginUrl: l, enable: false }); p([l, r, v, true]); }); } ``` ### Technical Analysis The bundled `electron-machine-id` functionality reads a platform-specific stable machine identifier. On Linux, it reads `/var/lib/dbus/machine-id` or `/etc/machine-id`, falling back to the hostname. Equivalent persistent identifiers are retrieved on macOS, Windows, and FreeBSD. The identifier is SHA-256 hashed by default, but hashing does not make a stable, low-entropy device identifier anonymous. The resulting value remains deterministic and can be used to correlate repeated requests from the same host. The fingerprint is: - Sent to `openclaw.sdk.access.llm-shield.omini-shield.com` in the `X-Ai-Device-Fingerprint` HTTP header. - Stored locally in `.state/login_state.json`. - Reused during login-status polling. The project documentation describes installation and login authorizatio ...[truncated 1193 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.js:7
Finding

Shell Command Injection Through Interpolated OpenClaw Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is plugin installation/configuration, but the behavior includes device fingerprint collection, remote login-token handling, credential retrieval/storage, persistent state writes, and gateway restart. This mismatch is dangerous because it can conceal sensitive identity, credential, and system-affecting operations behind an innocuous install description, reducing user scrutiny and bypassing expected trust boundaries.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill requires shell and environment access to run Node.js scripts and inspect processes, but it does not declare any tool scope or permissions. This weakens oversight and informed consent, making it easier for a seemingly simple installation skill to execute local code and process inspection without explicit authorization boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Although presented as an installation/configuration skill, the instructions are dominated by generating a login URL, reading login state, and guiding the user through an authentication flow. This is risky because users may approve the skill expecting local setup, while it actually drives account-linking behavior and accesses authentication artifacts stored on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to execute a local Node.js script and run process-inspection commands without warning the user that code will be executed locally and processes will be examined. Running unreviewed local code and inspecting system process state can expose the environment to unintended changes, privacy issues, or abuse if the bundled script performs more than advertised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs 10 minutes of process monitoring and automatic restart of a login-token process based on persisted state values. This exceeds what users would normally expect from a plugin installer and creates persistence-like behavior that can keep network-authentication activity running without fresh user awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script derives a persistent device fingerprint via machine ID and transmits it to remote login endpoints as an HTTP header. For a skill advertised as local plugin installation and basic configuration, collecting and exporting a host-unique identifier is an unnecessary expansion of scope and creates privacy, tracking, and environment-identification risk if the service is compromised or misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A sensitive, stable device fingerprint is sent over the network without any in-code user-facing disclosure or consent step. Even if TLS is used, undisclosed export of host-unique identifiers can enable tracking and may violate user expectations for a local setup helper.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores API key material into plugin configuration after applying reversible local encryption derived from a device fingerprint and static salt, but without clearly warning the user that credentials will be persisted. Silent credential storage increases the chance of unauthorized reuse, accidental disclosure, and weak secret handling assumptions, especially because the protection is not equivalent to secure secret storage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Beyond installing a plugin, the script orchestrates a remote login flow, polls for identity, writes returned credentials into configuration, and restarts the OpenClaw gateway. This exceeds the declared scope of basic installation/configuration and amplifies trust requirements, since it performs account-linked remote actions and service control on the user's machine.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code launches a detached background Node process that continues polling a remote service after the main command returns. Detached persistence increases operational risk because it creates long-lived behavior outside the user's immediate control, may continue network activity unexpectedly, and leaves fewer visibility and cleanup guarantees than a foreground, consented workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs sending the user a message that asks for confirmation using only Chinese example phrases, which can implicitly steer interaction toward a specific language. There is no opt-in, language choice, or stated reason that the skill must operate in Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.