Back to skill

Security audit

OpenClaw 晴晴终极套件

Security checks for vulnerabilities and agentic risk

Overview

This suite bundles useful productivity skills, but it also enables broad automatic activation, external data delivery, persistent watchdog behavior, and destructive workspace recovery with unclear user control.

Review before installing. Do not enable automatic activation, Feishu delivery, or the guardian watchdog unless you understand what will be sent or changed. Avoid running the guardian rollback setup on a workspace with important uncommitted work or secrets, and do not use the IronClaw audit script on private files unless you accept sending their full contents to the external IronClaw API.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T06 · System Persistence

Error
Location
skills/ironclaw-guardian-evolved/scripts/guardian.sh:86
Finding

Persistent Guardian Performs Autonomous Repair and Recovery Operations

Content
View full analysis
> /tmp/openclaw-guardian.log 2>&1 & # Verify pgrep -a -f "guardian.sh" tail -f /tmp/openclaw-guardian.log ``` The same instructions state that the guardian should be added to `~/.openclaw/start-gateway.sh` to make it persistent. ```bash # skills/ironclaw-guardian-evolved/scripts/guardian.sh:86-142 monitor_loop() { log "IronClaw Guardian Evolved started" log "Check interval: ${GUARDIAN_CHECK_INTERVAL}s, maximum repairs: ${GUARDIAN_MAX_FIX_ATTEMPTS}, cooldown: ${GUARDIAN_COOLDOWN}s" local fix_attempts=0 local cooldown_active=false while true; do if check_gateway; then fix_attempts=0 cooldown_active=false sleep "$GUARDIAN_CHECK_INTERVAL" continue fi audit_log "gateway_down" "gateway detected as down" if [ "$cooldown_active" = true ]; then sleep "$GUARDIAN_CHECK_INTERVAL" continue fi fix_attempts=$((fix_attempts + 1)) audit_log "doctor_fix_attempt" "attempt $fix_attempts" if run_doctor_fix; then fix_attempts=0 sleep "$GUARDIAN_CHECK_INTERVAL" continue fi if [ "$fix_attempts" -ge "$GUARDIAN_MAX_FIX_ATTEMPTS" ]; then if git_rollback; then restart_gateway fix_attempts=0 else cooldown_active=true sleep "$GUARDIAN_COOLDOWN" fi else sleep "$GUARDIAN_CHECK_INTERVAL" fi done } monitor_loop ``` ### Technical Analysis The documented setup copies the guardian into the user's OpenClaw directory, launc ...[truncated 1292 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skills/ironclaw-guardian-evolved/scripts/guardian.sh:48
Finding

Guardian Can Hard-Reset the Entire OpenClaw Workspace

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/ironclaw-guardian-evolved/scripts/ironclaw_audit.py:44
Finding

Security Audit Uploads Full Files, Commands, and Messages to an External API

Content
View full analysis
dict: """Call IronClaw API to inspect content.""" payload = { "content_text": content, "criteria_text": criteria } headers = {"Content-Type": "application/json"} if api_key: headers["Authorization"] = f"Bearer {api_key}" req = urllib.request.Request( IRONCLAW_API, data=json.dumps(payload).encode("utf-8"), headers=headers, method="POST" ) try: with urllib.request.urlopen(req, timeout=10) as resp: result = json.loads(resp.read().decode("utf-8")) return result ``` ```python def scan_file(filepath: str, api_key: str = None): """Scan a skill file.""" print(f"Scanning file: {filepath}") content = Path(filepath).read_text() result = check_content(content, CRITERIA["skill_scan"], api_key) ``` ```python def check_command(command: str, api_key: str = None): result = check_content(command, CRITERIA["destructive_command"], api_key) ``` ```python def check_message(text: str, api_key: str = None): result = check_content(text, CRITERIA["prompt_injection"], api_key) ``` ```bash # scripts/security-scan.sh:15-18 for file in skills/*/SKILL.md; do echo "Scanning: $file" result=$(python3 skills/ironclaw-guardian-evolved/scripts/ironclaw_audit.py scan "$file" 2>&1) ``` The script also stores content previews locally: ```python record = { "timestamp": Path.home().expanduser().__str__(), "event": event, "content_preview": content[:200], "label": label, "confidence": confidence, "criteria": criteria } ``` ### Technical Analysis The ...[truncated 1571 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/openclaw-free-web-search/openclaw-workspace/skills/local-web-search/scripts/browse_page.py:218
Finding

Arbitrary URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
tuple: """Returns (status_code, raw_html_str).""" ua = ( "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) " "AppleWebKit/537.36 (KHTML, like Gecko) " "Chrome/122.0.0.0 Safari/537.36" ) req = urllib.request.Request(url, headers={ "User-Agent": ua, "Accept": "text/html,application/xhtml+xml,*/*;q=0.8", "Accept-Language": "en-US,en;q=0.9", "Referer": "https://www.google.com/", }) with urllib.request.urlopen(req, timeout=timeout) as r: ct = r.headers.get("Content-Type", "utf-8") charset = "utf-8" m = re.search(r"charset=([\w-]+)", ct) if m: charset = m.group(1) return r.status, r.read().decode(charset, errors="replace") ``` ```python status, raw_html = _stdlib_fetch(url, timeout=timeout) ``` ```python p.add_argument("--url", required=True, help="URL to fetch") p.add_argument("--max-words", type=int, default=600, help="Maximum words to return") p.add_argument("--mode", choices=["auto", "fast", "stealth", "dynamic"], default="auto") p.add_argument("--timeout", type=int, default=20, help="Request timeout") p.add_argument("--json", action="store_true", help="Return JSON output") args = p.parse_args() result = fetch_page(args.url, mode=args.mode, timeout=args.timeout) ``` ### Technical Analysis A caller-controlled `--url` is passed to `urllib.request.urlopen` without scheme validation, hostname restrictions, DNS resolution checks, or destination IP filtering. Default redirect behavior can also follow a public URL to an internal destinat ...[truncated 1257 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skills/ironclaw-guardian-evolved/SKILL.md:55
Finding

Guardian Setup Overwrites Global Git Identity and Commits the Entire Workspace

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/email-daily-summary/SKILL.md:23
Finding

Unpinned Third-Party Packages Are Installed or Executed at Runtime

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (301)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill list includes automated social media posting and TikTok data collection capabilities, but the description does not provide corresponding warnings about publishing actions, scraping behavior, platform policy issues, or privacy implications. In context, these are high-risk side effects because they can affect external accounts, collect third-party data, and create compliance exposure without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README promotes automatic activation and Feishu delivery but does not clearly warn users that outputs, files, or notifications may be sent to an external platform. In a skill suite that handles office, research, and agent workflows, this omission creates a real risk of unintended data disclosure to third-party services.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic activation trigger phrases are extremely broad (e.g., common words like '开发', '产品', '网站', '内容', '搜索'), which can cause unintended invocation of powerful skills during ordinary conversation. In this suite, accidental activation is especially risky because it can chain into external actions such as web scraping, social media posting, task orchestration, and Feishu delivery without a clearly documented confirmation boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the actual code only performs self-improvement logging/reporting for one agent, then the description of a large integrated platform with security, Feishu, and many assistant functions is materially inaccurate. This can mislead users about the nature of collected data and the true boundaries of automation or logging.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The auto-activation triggers are broad everyday words such as '分析', '文档', '天气', '内容', and '搜索', which can match ordinary conversation and invoke multiple skills without clear, granular consent. In a suite that claims integration with scanning, notifications, and many subskills, over-broad triggers materially raise the risk of accidental data access, transmission, or execution of unintended workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-activation trigger words are broad everyday terms such as '开发', '分析', and '文档', making accidental invocation of powerful skills likely. In a suite with browser automation, social posting, and multi-agent orchestration, ambiguous triggers can cause unintended tool execution, data exposure, or external actions without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.browser_credential_automation

Browser automation instructions expose credentials or persist authenticated eval.

Critical
Code
suspicious.browser_credential_automation
Location
skills/email-daily-summary/SKILL.md:65