Back to skill

Security audit

Openclaw Discord Setup

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Discord setup guide with expected credential and message-access risks, but no hidden code, persistence, or deceptive behavior in the artifact.

Install only if you are comfortable connecting an OpenClaw AI assistant to Discord. Limit the bot to trusted servers and channels, avoid enabling DMs unless needed, protect or externalize the bot token, keep ~/.openclaw/config.yaml private, and assume messages visible to the bot may be processed by the configured AI backend.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:38
Finding

Discord Bot Token Stored in Plaintext Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38-43
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

yaml
plugins:
  entries:
    - plugin: openclaw-discord
      config:
        botToken: "YOUR_BOT_TOKEN"
        clientId: "YOUR_CLIENT_ID"

Technical Analysis

The primary setup procedure directs users to place a Discord bot token directly in the persistent ~/.openclaw/config.yaml file. A similar inline-token configuration is repeated in the advanced slash-command example.

Discord bot tokens are authentication credentials that grant access to the bot account and its authorized Discord resources. Storing the token as a literal configuration value exposes it to local users and processes that can read the file, insecure backups, diagnostic archives, accidental source-control commits, or configuration files shared for technical support.

Although the document later recommends using an environment variable, it does not demonstrate how the plugin should consume that variable. Consequently, the actionable configuration examples continue to promote plaintext credential storage.

Attack Path

  1. A user follows the documented setup and writes a valid Discord bot token into ~/.openclaw/config.yaml.
  2. The configuration file is exposed through permissive file permissions, local malware, another account with filesystem access, an unprotected backup, a support archive, or an accidental repository commit.
  3. An attacker extracts the token from the botToken field.
  4. The attacker submits authenticated requests to the Discord Bot API using the stolen token.
  5. The attacker impersonates the bot and exercises the permissions granted to it until the token is revoked or regenerated.

Impact Assessment

A successful attacker can authenticate as the affected Discord bot. The resulting scope is limited by the bot's configured Discord permissions and the servers ...[truncated 552 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace every inline-token example with an explicit environment-variable or secret-manager reference supported by the OpenClaw plugin.
  2. Do not use placeholder syntax unless the documentation confirms that OpenClaw expands it. Provide a tested configuration example showing exactly how DISCORD_BOT_TOKEN is consumed.
  3. Store production credentials in an operating-system credential store or dedicated secrets manager where supported.
  4. Restrict the configuration file to the owning account, such as mode 0600 on Unix-like systems, and ensure the parent directory is not broadly accessible.
  5. Exclude local configuration and secret files from source control, backups shared with third parties, diagnostic bundles, and support attachments.
  6. Apply least privilege to the Discord bot and restrict it to explicitly approved guild IDs.
  7. Document immediate token regeneration through the Discord Developer Portal after any suspected disclosure.
  8. Add automated secret scanning to detect Discord bot tokens before files are committed or distributed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

  • name: "ask" description: "Ask AI a question" - name: "clear" description: "Clear conversation history"
text

### 多服务器支持

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide tells users to connect a Discord bot that reads channel messages and returns AI-generated replies, but it does not clearly disclose that Discord content may be transmitted to an external AI system and potentially logged, retained, or exposed to third-party processing. This can lead to unintentional sharing of private server content, sensitive discussions, or personal data by operators who follow the setup without understanding the privacy implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document presents all user-facing instructions in Chinese, including setup steps, troubleshooting, and support information. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy issue unless the locale constraint is explicitly justified, which it is not here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
52% confidence
Finding

The author field references a 'CN Team', which may indicate the skill is maintained for a specific locale. However, the file contains no explicit language-selection or locale-choice statement, so this is only a weak natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.