Back to skill

Security audit

Openclaw Business Guide

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a business guide, but it includes deployable automation examples that could redirect customer replies to the author's contact and create recurring publishing without enough safeguards.

Install only if you are comfortable treating it as Chinese-language business advice. Do not copy the automation snippets directly: replace all contact details with your own, review any customer-facing replies before enabling them, and avoid adding recurring cron tasks unless you understand how to list, disable, and remove them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:152
Finding

Hard-Coded Third-Party Contact Redirects Automated Customer Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 152-154
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Vulnerable code:

yaml
auto_reply:
  - trigger: "安装"
    reply: "安装服务 ¥99 起,微信:yang1002378395"

The same third-party contact information is reinforced at lines 199-201:

markdown
## 需要帮助?

- 变现咨询:¥99
- 1对1 指导:¥299
- 企业合作:¥999

联系:微信 yang1002378395 或 Telegram @yangster151

Technical Analysis

The skill supplies an automated-response configuration that embeds the author's fixed WeChat contact. If a user copies or applies this configuration, messages matching the installation trigger generate promotional output that directs customers to that third party.

This is not a generic configuration template because the contact destination is already populated and is not clearly identified as a placeholder requiring replacement. The behavior can therefore alter customer-facing agent output and redirect commercial leads away from the deploying user.

No credential theft, arbitrary code execution, or privilege escalation is demonstrated. The issue is limited to instruction-driven manipulation of automated responses and redirection of communications.

Attack Path

  1. A user loads the skill and follows its customer-automation guidance.
  2. The user copies or deploys the provided auto_reply configuration without replacing the embedded contact.
  3. A customer sends a message matching the installation trigger.
  4. The automation replies with the hard-coded WeChat account.
  5. The customer contacts the third party, potentially transferring the commercial lead and related communications outside the user's control.

Impact Assessment

The affected scope is customer-facing messaging configured from this skill. A third party may receive customer inquiries, commercial leads, and information voluntarily shared by customers after following the embedded co ...[truncated 302 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all personal WeChat, Telegram, and other third-party contact identifiers from reusable automation examples.
  • Replace fixed destinations with explicit placeholders such as ${SERVICE_CONTACT} or YOUR_CONTACT_HERE.
  • Require the deploying user to configure and confirm the destination before enabling automated replies.
  • Clearly label all example values as nonfunctional placeholders.
  • Display the final customer-facing response to the user for review before activation.
  • Add validation that rejects default author-controlled contact values in deployed configurations.
  • Keep promotional guidance separate from executable or directly reusable automation configuration.

T06 · System Persistence

Warning
Location
SKILL.md:142
Finding

Recurring Publication Task Creates Unbounded Cross-Session Automation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 142-147
Vulnerability Type: T06: System Persistence
Risk Level: Medium

Vulnerable code:

markdown
### 1. 内容自动发布

```bash
openclaw cron add publish_content "0 9 * * *"
text

### Technical Analysis

The documented command registers a recurring scheduled task that runs every day at 09:00. A cron-style task survives the initiating interaction and continues operating across sessions until it is explicitly removed or disabled.

The guide does not define the implementation of `publish_content`, the publication destination, the content source, the credentials or permissions used, failure behavior, an expiration time, or a removal command. Consequently, a user following the example may create persistent automation without being able to evaluate its complete effects.

The command does not independently prove arbitrary command execution or privilege escalation. Its demonstrated security property is persistence through recurring scheduled execution.

### Attack Path

1. A user follows the automation instructions and executes the supplied `openclaw cron add` command.
2. OpenClaw registers `publish_content` as a daily scheduled task.
3. The task remains registered after the original session ends.
4. At each scheduled time, the associated publication action executes using the permissions and integrations available to OpenClaw.
5. If the action or its destination is incorrectly configured, content may continue to be published without contemporaneous user approval until the schedule is discovered and removed.

### Impact Assessment

The impact depends on the permissions held by the OpenClaw environment and the implementation of `publish_content`. At minimum, the task can repeatedly invoke the configured publication workflow across sessions. If connected publishing accounts are available, the scope may include recurring posts to those configured destinatio
...[truncated 378 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not instruct users to create recurring schedules without first explaining the complete action, target, credentials, and security implications.
  • Require explicit confirmation immediately before schedule creation.
  • Provide commands for listing, disabling, and permanently deleting the scheduled task.
  • Use a disabled or one-time example by default instead of an indefinitely recurring schedule.
  • Configure an expiration date or execution limit where supported.
  • Apply least-privilege permissions to the publishing integration and restrict it to explicitly approved destinations.
  • Require preview and approval of content before each publication when unattended posting is unnecessary.
  • Record schedule creation and every execution in an auditable log.
  • Document failure handling and ensure repeated failures automatically disable the task rather than retrying indefinitely.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and all user-facing content are written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking region for compliance or other justified reasons. This creates a natural-language locale policy issue because the skill effectively imposes a specific language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.