Back to skill

Security audit

agentCreate

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to manage OpenClaw agents, but full uninstall can delete workspaces/accounts and directly rewrite a live configuration file with weak safeguards.

Install only if you intentionally want an administrative skill that can create and delete OpenClaw agents, workspaces, bindings, and channel accounts. Before full uninstall, verify the exact agent and channel account, back up the real OpenClaw config, avoid pasting secrets into shared chats/logs, and be aware that the documented direct config edit should be reviewed or replaced with a safer supported deletion method.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/delete.md:38
Finding

Unsafe Non-Atomic Rewrite of Sensitive OpenClaw Configuration

Content
View full analysis

Vulnerability Details

File Location: references/delete.md, lines 38-56
Vulnerability Type: Unsafe configuration-file handling
Risk Level: Medium

python
import json

path = '/Users/honor/.qclaw/openclaw.json'
with open(path, 'r') as f:
    config = json.load(f)

# 删除指定飞书账号
accounts = config.get('channels', {}).get('feishu', {}).get('accounts', {})
for account_id in ['{feishuAccount}']:  # 列出所有要删除的账号
    if account_id in accounts:
        del accounts[account_id]

with open(path, 'w') as f:
    json.dump(config, f, indent=2)

Technical Analysis

The full-uninstall procedure directly edits a sensitive live configuration file using a hard-coded absolute path associated with a specific user. This can target the wrong configuration when the Skill runs under a different account or deployment layout.

Opening the file with mode w truncates it before JSON serialization finishes. The operation does not use a same-directory temporary file followed by atomic replacement, file locking, synchronization, or a verified backup. A process interruption, serialization error, disk failure, or concurrent configuration update can therefore leave the file empty, partially written, or missing updates made by another process.

This procedure also contradicts the backup and rollback requirement stated in SKILL.md. The documented deletion sequence provides no implementation that creates a backup before modification or restores it if the direct rewrite fails. Because normal file opening follows symbolic links, unsafe ownership or link conditions at the fixed path could also redirect the write if a local actor already has sufficient access to manipulate that path.

Attack Path

  1. A user selects full agent uninstallation and provides the required confirmation.
  2. The workflow force-deletes the selected agent and its workspace.
  3. The Python procedure opens /Users/honor/.qclaw/openclaw.json, regardless of ...[truncated 1320 chars]
Remediation
View remediation

Remediation Suggestions

  1. Resolve the configuration path through the trusted QClaw/OpenClaw wrapper or derive it from the authenticated user's home directory. Do not use a fixed username.
  2. Canonicalize and validate the path before writing. Confirm that the file is a regular file, is owned by the expected user, and is not a symbolic link.
  3. Acquire an exclusive lock to prevent concurrent writers from losing each other's updates.
  4. Create a timestamped backup before modification and verify that the backup can be parsed.
  5. Write the updated JSON to a temporary file in the same directory with restrictive permissions.
  6. Flush buffered data and call fsync before replacing the original file.
  7. Atomically replace the live configuration with the temporary file and preserve the original ownership and access mode.
  8. Validate the resulting JSON and required configuration structure before considering the deletion successful.
  9. Restore the verified backup automatically if writing, validation, replacement, or gateway reload fails.
  10. Prefer a supported configuration API capable of explicit key deletion if one becomes available, avoiding direct modification of the live configuration.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The trigger list contains broad English and Chinese phrases such as 'new agent', 'new bot', and 'remove agent' that can plausibly appear in ordinary conversation and may cause accidental invocation of a high-impact administrative skill. Because this skill can create or delete isolated agents and modify bindings/configuration, unintended activation could lead to unauthorized provisioning or destructive workflows being initiated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs operators to place sensitive channel credentials such as appId and appSecret into configuration, but provides no warning about secret handling, storage protections, redaction, or exposure through logs and shared files. In an agent-management skill, this increases the chance that long-lived secrets are mishandled, leaked from config backups, or entered through insecure channels.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/create.md (reported line 60)May include surrounding context.

--non-interactive

text

- workspace 会自动创建,无需预先 mkdir
- `--bind` 格式:`channel:accountId`,如 `feishu:bot_test`、`wechat-access:user123`
- 通道账号必须在此步骤前已存在于配置中

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/create.md (reported line 60)May include surrounding context.

--non-interactive

text

- workspace 会自动创建,无需预先 mkdir
- `--bind` 格式:`channel:accountId`,如 `feishu:bot_test`、`wechat-access:user123`
- 通道账号必须在此步骤前已存在于配置中

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs direct deletion of agent configuration and channel account data from a live JSON config file, but it does not require an explicit destructive-action warning, backup step, or confirmation flow before data loss occurs. In this skill context, the risk is increased because the operation affects routing behavior and can cause unintended fallback to the main agent or irreversible loss of account/workspace state if the wrong account or agent is removed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language content of the skill is entirely in Chinese, including operational instructions and confirmation flows, with no indication that the user can choose another language. This can violate a language/locale policy when the skill is used in multilingual environments and no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language policy issues apply to all file types, including markdown. This file presents all instructions and warnings only in Chinese and does not indicate that the skill is region-specific or provide any user opt-in for language preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.