Back to skill

Security audit

Ai Intelligent Agent Platform

Security checks for vulnerabilities and agentic risk

Overview

The skill itself is only a short description, but its install instructions tell users to download and run mutable external code that was not included for review.

Review the external repository and dependency lock files before installing, prefer a pinned commit or signed release, and run it in a restricted environment rather than directly in a sensitive user account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:39
Finding

Unpinned Remote Repository Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39-44
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
git clone https://github.com/openclaw-skills/ai-intelligent-agent-platform
cd ai-intelligent-agent-platform
pip install -r requirements.txt
python app.py

Technical Analysis

The installation instructions clone a mutable remote Git repository without pinning a reviewed commit, tag, or cryptographically verified release. They subsequently install dependencies from an external requirements.txt and execute app.py.

The audited project contains only SKILL.md; neither the application source nor its dependency manifest is included. Therefore, the effective code and dependencies executed by these commands cannot be verified from the reviewed artifact and may change after the Skill has been audited. The execution chain also permits Python package installation mechanisms, including package build scripts, to run code during dependency installation.

Attack Path

  1. An attacker compromises the referenced repository, gains control of its namespace, or introduces a malicious commit into its default branch.
  2. Alternatively, an attacker compromises or replaces a dependency referenced by the remote repository.
  3. A user follows the documented installation commands and clones the current, attacker-influenced repository state.
  4. pip install -r requirements.txt installs the uncontrolled dependencies and may execute malicious package build or installation logic.
  5. python app.py directly executes the remotely obtained application code.
  6. The malicious code runs with the permissions and environment access of the invoking user.

Impact Assessment

Successful exploitation can result in arbitrary code execution under the invoking user's account. The payload could access files, environment variables, credentials, network resources, and ...[truncated 415 chars]

Remediation
View remediation

Remediation Suggestions

  • Include the complete, auditable implementation and dependency manifest in the distributed Skill package.
  • If remote retrieval is necessary, pin the repository to a specific reviewed commit hash rather than cloning a mutable default branch.
  • Distribute signed releases and verify their cryptographic signatures or checksums before installation or execution.
  • Lock all Python dependencies to exact versions and require hashes, such as through pip install --require-hashes.
  • Review both direct and transitive dependencies and obtain them only from trusted package indexes.
  • Separate download, verification, dependency installation, and application execution into distinct steps rather than executing remote code immediately.
  • Run the application with a dedicated, least-privileged account in a sandbox or container with restricted filesystem, credential, and network access.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and use-case labels are highly generic (e.g., AI Agent, automation, intelligent assistant, workflow automation), which weakens invocation boundaries and makes it more likely an orchestrator or user will apply the skill in unintended contexts. For an agent platform skill that can coordinate tools and workflows, overbroad scoping increases the chance of unsafe or excessive capability exposure rather than constraining behavior to a narrow, auditable purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.