Back to skill

Security audit

Researching In Parallel

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed parallel research workflow that uses sub-agents, web/PDF retrieval, and workspace file outputs in ways that match its stated purpose.

Before installing, be aware that this skill can spawn multiple sub-agents, perform extensive web/PDF/browser research, and save reports, prompts, bibliographies, and optional source extracts in a workspace directory. Use a new empty workspace, review provided-source paths before running, and verify generated citations before relying on the report.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requires file read/write access and instructs the agent to create, copy, and update files in a workspace, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity: a host agent may expose broader filesystem capabilities than intended, increasing the risk of unintended file access or overwrite if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/configuration.md (reported line 146)May include surrounding context.

md
## Sub-agent system prompt (promptMode)

Sub-agents automatically run with `promptMode: minimal` — this is set by the OpenClaw runtime and is not user-configurable. Under `minimal`, Skills, Memory Recall, User Identity, Heartbeats, and several other context blocks are stripped out. Sub-agents only receive `AGENTS.md` and `TOOLS.md` from your bootstrap files; `SOUL.md`, `IDENTITY.md`, `USER.md`, `HEARTBEAT.md`, `BOOTSTRAP.md`, and `MEMORY.md` are filtered out.

There is a leaner `promptMode: none` (returns only a base identity line) but the runtime assigns prompt modes — you cannot request it.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code performs file writes to paths derived from the user-supplied workspace argument, but there is no confirmation prompt, pre-write disclosure, or explanatory comment/docstring near the write operation describing that files will be created or overwritten. The later "Generated" print happens only after the write completes, so it does not function as an upfront warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.