Back to skill

Security audit

status-monitor

Security checks for vulnerabilities and agentic risk

Overview

This status-monitoring skill appears legitimate, but it needs review because it asks users to paste a reusable token into chat, stores it locally, and can run a background uploader to a configurable endpoint.

Review before installing. Use it only if you are comfortable sending your OpenClaw agent IDs to the hosted dashboard and running a periodic/background uploader. Do not paste reusable tokens into chat if avoidable; prefer an environment variable or a protected local secret file, restrict file permissions, and avoid setting OPENCLAW_MONITOR_URL or monitorUrl to untrusted endpoints.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/status_uploader.py:57
Finding

Authentication Token Can Be Redirected to an Arbitrary or Plaintext Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:81
Finding

Setup Instructions Require Users to Disclose a Reusable Token Through Chat

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/status_uploader.py:89
Finding

Credentials File Is Written Without Enforcing Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (22)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 156)May include surrounding context.

md
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop

# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor

# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 159)May include surrounding context.

md
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop

# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor

# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 160)May include surrounding context.

md
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop

# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor

# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 156)May include surrounding context.

md
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop

# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor

# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 159)May include surrounding context.

rm -rf ~/.openclaw/skills/openclaw-status-monitor

删除配置文件(可选)

rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json rm -rf ~/.openclaw/logs/status_uploader*

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 160)May include surrounding context.

删除配置文件(可选)

rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json rm -rf ~/.openclaw/logs/status_uploader*

text

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs the agent to solicit a secret token from the user via chat and then persist it on disk. This is dangerous because secrets entered into chat are commonly retained in conversation history, logs, analytics, or debugging systems, turning a monitoring token into a potentially recoverable credential for unauthorized uploads or account misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The setup flow explicitly instructs the user to send the monitoring token to the agent in chat, then store it locally, without a strong warning that the token is a secret credential. Collecting secrets through conversational channels increases the risk of exposure through logs, transcripts, prompt history, or unintended downstream processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to generate a token and send it to the agent, but it does not warn that this token is a sensitive credential that could authorize uploads or account actions if exposed. Encouraging users to paste credentials into an agent workflow without clear handling guidance increases the risk of accidental leakage through logs, prompts, chat history, or other integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installation guide documents periodic uploads to a cloud monitoring platform, but it does not present this background network behavior as a prominent privacy/security warning at the point where users enable the service. Users may install or activate the skill without fully understanding that it runs continuously and transmits agent identifiers off-host, which weakens informed consent and can expose operational metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README prominently advertises automatic syncing of agent status and IDs to a cloud dashboard, but it does not clearly warn users about ongoing external data transmission, retention, or privacy implications before enablement. Even if only agent IDs are sent, this still exposes operational metadata and creates a risk of unintended disclosure because users may enable the feature without informed consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 20)May include surrounding context.

md
Every. Single. Time.

Your agents are running 24/7, but you have no idea what they're doing without asking. That's friction.

## The Solution

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README clearly promotes automatic syncing of agent status and IDs to a cloud dashboard, but it does not prominently warn users that operational metadata is being transmitted off-host to a third-party service. Even if only agent IDs are uploaded, this can disclose fleet membership, activity patterns, and presence information, creating privacy and security exposure through documentation-driven misconfiguration or uninformed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quick-start flow instructs users to enable monitoring and visit a hosted dashboard, but omits a clear disclosure that doing so shares agent status data remotely. This is especially risky because users may enable it with a simple command, causing external data exposure without understanding that agent identifiers and heartbeat/activity metadata are leaving their environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities to read environment variables, read and write local files, and communicate with a remote monitoring platform, but it does not declare any explicit tool scope or permissions. This creates an authorization transparency gap: users and the host platform cannot clearly constrain or review what the skill is allowed to access before it handles credentials and performs background sync.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description says the skill syncs status to a cloud monitoring platform, but it does not clearly warn that agent identifiers/status will be uploaded and that stored credentials may be used for ongoing background synchronization. This weakens informed consent, especially because the skill can run on a schedule or as a daemon.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger set includes broad phrases like 'sync status', 'start daemon', 'run in background', and similar variants that could plausibly appear in normal conversation. Because those triggers can start background processes, change intervals, or perform uploads, accidental invocation could cause unintended network transmission or persistent service execution without clear user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill persists a user-provided monitoring token under ~/.openclaw/credentials for ongoing reuse, enabling session/credential persistence beyond the immediate interaction. In context, this is more dangerous because the token is first collected via chat and then stored for a background service, extending the blast radius if the local machine, logs, or agent environment are compromised.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
2. **Wait for user to reply with token**

3. **Save the token**:
   - Create directory `~/.openclaw/credentials/`
   - Save to `~/.openclaw/credentials/openclaw-status-monitor.json`:
     ```json
     {

Ssd 3

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Including a realistic plaintext token value in documentation encourages insecure handling and may cause operators to copy the pattern directly into files without considering protection. Even if the sample token is not real, documenting secrets in plaintext next to the storage path normalizes weak secret hygiene.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example conversation repeatedly normalizes the user providing the token directly in chat, reinforcing an unsafe operational pattern. Repetition increases the chance that users will treat secret-sharing in conversation as expected and acceptable across deployments and future skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file includes its primary description in Chinese and continues using Chinese-only user-facing messages throughout the script, which imposes a specific language/locale without any opt-in or alternative. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document repeatedly hardcodes English and Chinese phrases and conversation patterns, but it does not state that users may choose their preferred language or locale. This can conflict with a language-choice policy when locale behavior is prescribed without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL.md:156