Back to skill

Security audit

OpenClaw安全审计与防护

Security checks for vulnerabilities and agentic risk

Overview

This security-audit skill is mostly purpose-aligned, but it ships hardcoded Feishu credentials and can send sensitive audit details to a fixed external recipient without deployment-specific control.

Install only after removing and rotating the embedded Feishu secret, replacing all recipient IDs with deployment-owned configuration, disabling external alerts by default, adding redaction for audit details, binding confirmations to exact per-request nonces, and restricting URL scanning to safe allowed destinations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit_feishu.py:18
Finding

Hardcoded Feishu Application Secret and Fixed Recipient Identity

Content
View full analysis
Remediation
View remediation

other

Error
Location
scripts/audit_logger.py:73
Finding

Unredacted Audit and Session Details Are Transmitted to a Hardcoded External Recipient

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/confirm.py:160
Finding

Generic or Stale Chat Messages Can Confirm Unrelated High-Risk Operations

Content
View full analysis
Remediation
View remediation
` or `REJECT `. 3. Bind approval to the original Feishu `message_id` or reply thread. 4. Verify the sender, chat, request identifier, and message creation time. 5. Reject messages created before the pending request. 6. Mark approval messages as consumed so they cannot authorize another action. 7. Process at most one pending action per valid response. 8. Remove broad substring checks for `ok`, `yes`, and `confirm`. 9. Include an immutable operation summary or hash in the confirmation request and verify it before execution. 10. Protect `pending_confirms.json` with restrictive filesystem permissions and atomic writes. 11. Add tests for stale messages, multiple simultaneous requests, replayed responses, ambiguous text, and expired requests. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/content_scan.py:76
Finding

Arbitrary URL Fetching Bypasses the URL Guard and Permits SSRF

Content
View full analysis
dict: """Fetch content from a URL and scan it.""" try: req = Request(url, headers={"User-Agent": "Mozilla/5.0"}) with urlopen(req, timeout=10) as resp: content = resp.read().decode("utf-8", errors="ignore") # Only scan the first 5000 characters content = content[:5000] result = scan_text(content) result["url"] = url result["scanned_chars"] = min(len(content), 5000) return result ``` The URL guard contains contradictory default rules: ```python # File storage "pastebin.com": "Pastebin", "dpaste.com": "DPaste", "transfer.sh": "Transfer.sh", ``` ```python BLOCKLIST = { "pastebin.com": "May enable malicious code execution", "dpaste.com": "May enable malicious code execution", "transfer.sh": "May be used for data exfiltration", "bit.ly": "Short URL may redirect to a malicious URL", "tinyurl.com": "Short URL may redirect to a malicious URL", } ``` Whitelist evaluation occurs before blocklist evaluation: ```python # Check whitelist if domain in domains: return { "allowed": True, "reason": "In whitelist", "domain": domain, "whitelist_reason": domains[domain], } # Check blocklist for blocked, reason in BLOCKLIST.items(): if domain == blocked or domain.endswith("." + blocked): return { "allowed": False, "reason": f"In blocklist: {reason}", "domain": domain, "whitelist_reason": "", } ``` ### Technical Analysis The URL-scanning feature accepts an arbitrary caller ...[truncated 2593 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains a hardcoded Feishu application secret directly in source code. Embedded secrets are easily leaked through source control, logs, backups, or skill distribution, allowing attackers to obtain access tokens and impersonate the application or exfiltrate audit data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The realtime alert function immediately sends operation details to Feishu without prior confirmation, creating automatic external exfiltration of potentially sensitive security events. Because this skill is explicitly for auditing sensitive operations, the transmitted details may include confidential actions or identifiers, making the behavior more dangerous in context.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains hardcoded Feishu application credentials and a fixed user identifier. Embedded secrets are highly dangerous because anyone with code or artifact access can reuse them to obtain tokens, send messages, and potentially abuse the linked tenant integration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script hardcodes Feishu app credentials and uses them to send and read external chat messages, creating an undisclosed outbound communication channel and exposing reusable secrets in source code. In the context of an audit/logging skill, this expands capability beyond passive logging into active external messaging and data access, which is dangerous if the code or environment is exposed or if the channel is abused for unauthorized approvals or exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Sensitive Feishu credentials are embedded directly in the script, making them recoverable by anyone with source access, logs, backups, or accidental disclosure of the file. Once exposed, an attacker could authenticate to the external service, send messages, read chat data within granted scope, or abuse the approval workflow.

Content

No source excerpt is available for this finding.

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · scripts/content_scan.py (reported line 15)May include surrounding context.

python
# 高风险模式(匹配到则触发告警)
HIGH_RISK_PATTERNS = [
    (r"ignore\s+(all\s+)?(previous|prior|above)\s+(instruction|inject)", "提示词注入: ignore previous instructions"),
    (r"(system|developer)\s*:\s*", "提示词注入: system/developer role"),
    (r"disregard\s+(all\s+)?(previous|prior)", "提示词注入: disregard previous"),
    (r"forget\s+(all\s+)?(previous|prior|instructions)", "提示词注入: forget instructions"),

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · scripts/content_scan.py (reported line 17)May include surrounding context.

python
HIGH_RISK_PATTERNS = [
    (r"ignore\s+(all\s+)?(previous|prior|above)\s+(instruction|inject)", "提示词注入: ignore previous instructions"),
    (r"(system|developer)\s*:\s*", "提示词注入: system/developer role"),
    (r"disregard\s+(all\s+)?(previous|prior)", "提示词注入: disregard previous"),
    (r"forget\s+(all\s+)?(previous|prior|instructions)", "提示词注入: forget instructions"),
    (r"you\s+are\s+(now\s+)?(?:no longer|not\s+a)", "角色扮演陷阱: 解除AI身份"),
    (r"(unconditional|absolute)\s+obedience", "精神控制: 无条件服从"),

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script embeds Feishu app credentials and a fixed recipient identifier directly in source code, then uses them to transmit audit-derived alerts to an external messaging service. Hardcoded secrets are easily exposed through source distribution, logs, backups, or repository access, enabling unauthorized use of the Feishu app and unintended exfiltration of operational activity data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Hardcoded APP_ID, APP_SECRET, and USER_ID are sensitive operational identifiers used to obtain an access token and send messages. Because they are embedded and used without any user-facing disclosure, anyone with access to the code can reuse them to impersonate the application, trigger alerts, or abuse the associated Feishu integration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file’s behavior materially diverges from the declared audit-log skill purpose: it implements URL screening, whitelist management, and outbound messaging. This kind of capability mismatch is dangerous because operators may grant trust or permissions based on the manifest while the code performs unrelated network-policy and notification actions, increasing the chance of unnoticed data handling and policy bypass.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The script embeds Feishu application credentials and a user identifier directly in source code, enabling anyone with file access to reuse them for unauthorized API access or impersonated messaging. In the context of a purported audit tool, hidden messaging credentials are especially dangerous because they create covert outbound communication and secret-management failures at the same time.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The hard-coded Feishu credentials are actively used to request a tenant access token over the network, meaning exposed secrets are not merely dormant but operational. This creates immediate risk of credential abuse, unauthorized message sending, and account compromise if the code or logs are exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

When a URL is not whitelisted, the script silently sends the full checked URL and domain context to Feishu without explicit user disclosure or consent. This can leak sensitive URLs, internal endpoints, tokens embedded in query strings, or user activity metadata to an external service, making it a meaningful privacy and exfiltration risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and demonstrates file access, shell execution, subprocess use, and network interactions, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a governance gap: a reviewer or runtime may not correctly constrain what the skill can do, increasing the chance of over-privileged execution or unnoticed sensitive actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L003 的描述全文使用中文来规定技能的触发与用途,文件其余内容也默认以中文进行交互与确认,但没有说明这是面向特定中文环境的合规需求,也没有提供用户可选择语言的机制。根据规则,未获用户选择即隐含强制特定语言/locale,属于自然语言层面的组织政策风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These API calls transmit audit contents to an external Feishu service, which can expose sensitive operational details outside the local trust boundary. In an audit/protection skill, logs may include high-risk actions, timestamps, and details, so undisclosed outbound transfer increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file includes natural-language documentation in Chinese and later uses Chinese operation labels and status text, but does not provide any language selection or indicate that the skill is intentionally limited to a Chinese-speaking context. That creates a language/locale policy issue under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.