Back to skill

Security audit

System Monitor

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real system-monitoring skill, but it needs review because it stores host telemetry, some disable settings are ineffective, it exposes data through a third-party chart URL, and its automatic cleanup has unsafe deletion handling.

Install only if you are comfortable with a scheduled local monitor collecting and retaining host telemetry such as uptime, resource usage, network counters, Docker counts, service status, and top process names. Avoid opening generated QuickChart links unless sharing disk and memory history with quickchart.io is acceptable. Run it as an unprivileged user, restrict access to the history directory, and review or fix the cleanup and configuration-handling scripts before using it on shared or production systems.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/monitor.sh:9
Finding

Unsafe filename parsing permits deletion of unrelated files

Content
View full analysis
/dev/null | xargs -r stat --format="%Y %n" 2>/dev/null | while read timestamp filepath; do local age_days=$(( ($(date +%s) - timestamp) / 86400 )) if [ "$age_days" -gt 7 ]; then rm -f "$filepath" echo "$filepath" fi done) if [ -n "$deleted" ] && [ -n "$(echo "$deleted" | tr -d '[:space:]')" ]; then echo "🧹 已清理超过 7 天的历史日志" fi fi } ``` ### Technical Analysis The cleanup routine transports filenames through a whitespace-delimited pipeline: 1. `find` emits paths separated by newline characters. 2. `xargs` interprets whitespace, quotes, and backslashes rather than preserving each pathname exactly. 3. The output from `stat` is parsed again using `read timestamp filepath`. 4. The resulting path is passed to `rm`. Unix filenames may contain spaces, tabs, and newline characters. A specially crafted filename under the history directory can consequently be split into multiple arguments by `xargs`. One of those arguments can be an absolute path outside the history directory. If that external path exists and is older than seven days, `stat` reports it and the loop may pass it to `rm -f`. The `find` expression also lacks grouping: ```bash -type f -name "*.json" -o -name "*.log" ``` Because `-a` has higher precedence than `-o`, `-type f` applies only to the `*.json` branch. Although `rm -f` does not recursively remove directories, this expression is still broader than intended. Exploitation requires the attacker to be able to create crafted entries in the history directory. Privilege escalation in impact occurs only ...[truncated 1357 chars]
Remediation
View remediation

other

Note
Location
scripts/monitor-linux.sh:26
Finding

Configuration opt-outs do not prevent collection and persistence of system telemetry

Content
View full analysis
/dev/null || uptime | awk -F'up ' '{print $2}' | awk -F',' '{print $1}') NET_INFO=$(cat /proc/net/dev | grep -E "eth0|ens" | head -1) NET_RX=$(echo $NET_INFO | awk '{printf "%.1f", $2/1024/1024}') NET_TX=$(echo $NET_INFO | awk '{printf "%.1f", $10/1024/1024}') TOP_PROCESSES_OUTPUT=$(ps aux --sort=-%mem | head -6 | tail -5 | awk ...[truncated 3422 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the skill relies on an external QuickChart service not disclosed in the description, that is a genuine security concern because system monitoring data may be sent off-host unexpectedly. In a monitoring context, outbound transfer of host metrics or identifiers can expose sensitive operational information and violate network expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

If the skill relies on an external QuickChart service not disclosed in the description, that is a genuine security concern because system monitoring data may be sent off-host unexpectedly. In a monitoring context, outbound transfer of host metrics or identifiers can expose sensitive operational information and violate network expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

If the skill relies on an external QuickChart service not disclosed in the description, that is a genuine security concern because system monitoring data may be sent off-host unexpectedly. In a monitoring context, outbound transfer of host metrics or identifiers can expose sensitive operational information and violate network expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the skill relies on an external QuickChart service not disclosed in the description, that is a genuine security concern because system monitoring data may be sent off-host unexpectedly. In a monitoring context, outbound transfer of host metrics or identifiers can expose sensitive operational information and violate network expectations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to read local configuration/history files and references network monitoring, but it does not declare any explicit tool scope or permissions boundaries. In an agent environment, undocumented capabilities increase the chance of over-broad file access or unintended network-related actions without user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L003 将触发场景写为“用户询问系统状态、资源使用情况”等宽泛自然语言,没有限定具体触发短语、上下文边界或排除条件。这类表述容易与普通对话重叠,增加技能被非预期调用的风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill states that it automatically saves monitoring snapshots yet does not adequately warn that it will continuously write local historical records. Persistent storage of system health, service names, network statistics, and timestamps can create a sensitive local telemetry trail that may be accessed later by other users, processes, or agents.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

This duplicate session-persistence finding is valid for the same reason: the documented setup creates durable local state outside the immediate execution context. In security-sensitive environments, unattended persistence can expose configuration and monitoring context to unintended future access.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

1. 复制示例配置:

bash
mkdir -p ~/.openclaw/skills/config/skill-system-monitor
cp ~/.openclaw/skills/skill-system-monitor/config.example.json ~/.openclaw/skills/config/skill-system-monitor/config.json

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

This duplicate session-persistence finding is valid for the same reason: the documented setup creates durable local state outside the immediate execution context. In security-sensitive environments, unattended persistence can expose configuration and monitoring context to unintended future access.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

1. 复制示例配置:

bash
mkdir -p ~/.openclaw/skills/config/skill-system-monitor
cp ~/.openclaw/skills/skill-system-monitor/config.example.json ~/.openclaw/skills/config/skill-system-monitor/config.json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

L139-L142 使用“系统状态”“服务器监控”“资源使用情况”等概括性场景描述,但没有给出负面示例或限定必须是本机/服务器监控请求。这会让技能触发范围显得模糊,不利于与一般性问答区分。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script includes natural-language comments and all user-facing status/warning messages in Chinese, but it provides no option for the user to select a language and no justification that the skill is intended only for a Chinese-speaking or region-specific environment. That creates a language/locale policy issue because the skill effectively forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

User-facing comments, status labels, warnings, and the generated report are consistently hard-coded in Chinese. The file does not provide a language option or explain that the skill is intentionally limited to a Chinese-speaking context, which violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill manifest emphasizes disk, memory, and CPU monitoring, but the script also enumerates Docker containers and checks named services/processes. That expands data collection and system reconnaissance beyond the declared scope, which can reveal infrastructure details and application presence to a caller or downstream logs without clear necessity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Probing specific services like MongoDB, MySQL, PostgreSQL, Docker, Nginx, and an OpenClaw-related process turns a generic health-check script into targeted environment discovery. This can disclose sensitive stack composition and security-relevant operational status, which is more dangerous in a reusable skill intended for scheduled execution and broad deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persistently stores detailed host telemetry, including uptime, resource usage, network counters, Docker counts, and service-related context, under a history directory without any disclosure, retention policy, or permission hardening. On shared systems, these files can become a long-lived source of operational intelligence and activity history for unauthorized local users or other tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically deletes history files older than 7 days every time it runs, without user confirmation, opt-out control, or defensive safeguards around the target directory contents. In a monitoring skill intended for scheduled execution, this can cause unintended destruction of audit/forensic data and may interfere with incident investigation or retention requirements.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script generates a QuickChart URL that embeds recent disk and memory usage history into a third-party service request, extending behavior beyond purely local monitoring. Even if it only prints the URL instead of fetching it, users or downstream tooling may open it and disclose operational telemetry externally without an explicit trust decision.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The output includes an external QuickChart URL containing system usage data but gives no warning that opening the link will transmit host telemetry to a third party. In a monitoring skill intended for scheduled health checks, this creates a privacy and operational-information leakage risk because historical resource patterns can reveal usage habits and system state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

该技能的描述、触发文本、输出示例和操作说明均固定为中文,没有提供用户语言偏好选择或说明这是面向特定中文环境的限定技能。按语言/locale 政策,这可能构成未获用户选择的语言强制。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script collects network traffic counters and lists top memory-consuming processes, neither of which is clearly disclosed in the stated capability summary. While common in monitoring tools, this still broadens telemetry collection and may expose process names or workload characteristics that users did not expect to share.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level comment describes this as a main monitoring script that automatically detects the system type and calls the corresponding script, implying implemented support for detected platforms. However, the macOS path explicitly errors with 'not yet implemented,' which contradicts that documentation-level claim.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script's comments and user-visible output strings are written in Chinese, including status and error messages. For a general-purpose monitoring script, this imposes a specific language on users without opt-in or justification, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description states the skill supports Linux and Windows, but the code explicitly detects Darwin/macOS and attempts to invoke a macOS-specific monitor script. Even though the macOS implementation is marked as not yet implemented when missing, the behavior broadens the advertised platform scope beyond the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types, including code comments and string literals. The script's comments and all user-facing messages are in Chinese, with no indication that the skill is region-specific or that the user can opt into another language, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.