Back to skill

Security audit

Review Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real review coach, but it uses broad private data access, external model calls, and unaudited installation patching that users should review before installing.

Install only after an admin reviews the external GitHub installer and OpenClaw patch at a pinned commit, confirms OpenRouter data handling is acceptable for confidential drafts, restricts use to isolated Feishu/WeCom workspaces, and disables or tightly scopes delivery, purge, and legacy credential behaviors.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scan.py:40
Finding

Confidential review material is transmitted to OpenRouter without explicit disclosure or data minimization

Content
View full analysis
str: normalized = (sd / "normalized.md").read_text() if (sd / "normalized.md").exists() ...[truncated 5335 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/qa-step.py:237
Finding

Unrestricted session paths permit cross-workspace file access and modification

Content
View full analysis
Optional[Path]: """v2: session lives in /sessions//. The workspace is the subagent's cwd (overridable via REVIEW_AGENT_WORKSPACE for tests). Also accepts a full relative/absolute path for backward compat.""" # If caller passed a path, honor it p = Path(session_id) if p.is_absolute() and p.is_dir(): return p if (Path.cwd() / session_id).is_dir() and "/" in session_id: return (Path.cwd() / session_id).resolve() # Resolve workspace ws = Path(os.environ.get("REVIEW_AGENT_WORKSPACE", Path.cwd())).resolve() candidate = ws / "sessions" / session_id if candidate.is_dir(): return candidate # Legacy v1 fallback (for migration phase) legacy_root = Path(os.environ.get("REVIEW_AGENT_ROOT", Path.home() / ".review-agent")) if legacy_root.exists(): for p in (legacy_root / "users").glob(f"*/sessions/{session_id}"): if p.is_dir(): return p return None ``` Other workflow scripts accept a caller-provided path and only check whether it is a directory. For example, `scripts/merge-draft.py:120-123` contains: ```python sd = Path(args.session_dir) if not sd.is_dir(): print(f"error: {sd} not a directory", file=sys.stderr) sys.exit(2) ``` The accepted directory is subsequently used for sensitive reads and writes: ```python normalized = (sd / "normalized.md").read_text() if (sd / "normalized.md").exists() el ...[truncated 3127 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
POST_INSTALL.md:10
Finding

Installation instructions retrieve mutable remote code and execute a host-wide OpenClaw patch

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (74)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The troubleshooting guidance tells an operator to run a wildcarded rm -f against session files, which is a destructive action that can erase agent history and context with no confirmation or backup step. In this skill's context, those JSONL sessions may contain operational state and possibly sensitive review data, so broad deletion can cause data loss and incident-response blind spots even if the command is intended as maintenance.

Content

Scanner excerpt · POST_INSTALL.md (reported line 111)May include surrounding context.

md
## Troubleshooting

- **`replies=0` on dispatch_complete** → subagent's `message` tool call has wrong `target`. Check the subagent's jsonl for bare open_ids. Our SOUL.md forbids this but older sessions may have cached. Clear: `rm -f ~/.openclaw/agents/feishu-ou_*/sessions/*.jsonl` then re-test.
- **Subagent replies with "Hey I just came online, who am I?"** → the feishu-seed patch didn't land. Run step 1 again and confirm `grep "review-agent local patch" /opt/homebrew/lib/node_modules/openclaw/dist/monitor-D9C3Olkl.js` returns a line.
- **"Thinking Process:" shows up in Lark replies** → SOUL.md didn't load. Check `~/.openclaw/workspace-feishu-<open_id>/SOUL.md` exists and contains "不要填 target 字段".
- **Each DM triggers a new `creating dynamic agent` log line** → harmless. openclaw re-spawns per-message due to an internal consistency quirk. The cp -R seed is idempotent; your workspace data is preserved.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding highlights undeclared operational scope: attachment/URL ingestion, local session storage, external OCR/PDF/audio tooling, and optional third-party access are materially broader than a simple chat review description suggests. In a non-isolated main-agent deployment, such hidden resource use can expose user content, increase attack surface through parsers and shell tools, and make unsafe access paths easier to trigger unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding highlights undeclared operational scope: attachment/URL ingestion, local session storage, external OCR/PDF/audio tooling, and optional third-party access are materially broader than a simple chat review description suggests. In a non-isolated main-agent deployment, such hidden resource use can expose user content, increase attack surface through parsers and shell tools, and make unsafe access paths easier to trigger unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding highlights undeclared operational scope: attachment/URL ingestion, local session storage, external OCR/PDF/audio tooling, and optional third-party access are materially broader than a simple chat review description suggests. In a non-isolated main-agent deployment, such hidden resource use can expose user content, increase attack surface through parsers and shell tools, and make unsafe access paths easier to trigger unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding highlights undeclared operational scope: attachment/URL ingestion, local session storage, external OCR/PDF/audio tooling, and optional third-party access are materially broader than a simple chat review description suggests. In a non-isolated main-agent deployment, such hidden resource use can expose user content, increase attack surface through parsers and shell tools, and make unsafe access paths easier to trigger unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding highlights undeclared operational scope: attachment/URL ingestion, local session storage, external OCR/PDF/audio tooling, and optional third-party access are materially broader than a simple chat review description suggests. In a non-isolated main-agent deployment, such hidden resource use can expose user content, increase attack surface through parsers and shell tools, and make unsafe access paths easier to trigger unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding highlights undeclared operational scope: attachment/URL ingestion, local session storage, external OCR/PDF/audio tooling, and optional third-party access are materially broader than a simple chat review description suggests. In a non-isolated main-agent deployment, such hidden resource use can expose user content, increase attack surface through parsers and shell tools, and make unsafe access paths easier to trigger unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The persona states the agent's core value is to challenge the requester and that it 'cannot write answers for them.' Later, the same reference defines a document merge stage that can generate final/revised.md and even directly edit Lark or Google Docs, which goes beyond critique into drafting/editing work the documentation says it should not do.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The 'do not' section explicitly bans phrases like 'I’ll help you rewrite it' and says findings must point out problems rather than do the homework. However, later sections require 'specific modification suggestions (verb + replacement text)' and even prescribe messages like 'Original X → change to Y,' which is an active contradiction in the documented intent.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/delivery/README.md (reported line 70)May include surrounding context.

md
### `lark_dm`
- Uses `~/bin/lark_send` (or the in-repo `scripts/send-lark.sh` if not installed globally)
- Sends: a text/post message + (attempt) file — if file upload fails (app missing `im:resource:upload`), inline as `post` rich text with linked summary
- Reads tenant access token via openclaw `feishu` config

### `local_path`
- Simple file copy

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/_json_repair.py (reported line 112)May include surrounding context.

python
def _strip_line_comments(s: str) -> str:
    # Remove // ... line comments, but only when NOT inside a string.
    # Simple heuristic: track string state.
    out = []
    i, n = 0, len(s)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_platform.py (reported line 7)May include surrounding context.

python
Centralizes lookups that v1 hardcoded for hermes:
  - load_openrouter_key() — v1 read ~/.hermes/.env; v2 reads openclaw.json
    (~/.openclaw/openclaw.json → models.providers.openrouter.apiKey) with
    .env fallback for transitional setups.
  - resolve_responder(workspace) — v1 walked ~/.review-agent/users/<oid>/...;
    v2 reads the current workspace's owner.json / USER.md.
  - workspace_root() — the peer workspace root. Defaults to cwd (where the

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_platform.py (reported line 24)May include surrounding context.

python
Centralizes lookups that v1 hardcoded for hermes:
  - load_openrouter_key() — v1 read ~/.hermes/.env; v2 reads openclaw.json
    (~/.openclaw/openclaw.json → models.providers.openrouter.apiKey) with
    .env fallback for transitional setups.
  - resolve_responder(workspace) — v1 walked ~/.review-agent/users/<oid>/...;
    v2 reads the current workspace's owner.json / USER.md.
  - workspace_root() — the peer workspace root. Defaults to cwd (where the

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan.py (reported line 44)May include surrounding context.

python
Centralizes lookups that v1 hardcoded for hermes:
  - load_openrouter_key() — v1 read ~/.hermes/.env; v2 reads openclaw.json
    (~/.openclaw/openclaw.json → models.providers.openrouter.apiKey) with
    .env fallback for transitional setups.
  - resolve_responder(workspace) — v1 walked ~/.review-agent/users/<oid>/...;
    v2 reads the current workspace's owner.json / USER.md.
  - workspace_root() — the peer workspace root. Defaults to cwd (where the

Credential Access

High
Category
Privilege Escalation
Confidence
73% confidence
Finding

The code reads a legacy ~/.hermes/.env file from the user's home directory and extracts OPENROUTER_API_KEY. While this is likely intended as backward-compatible configuration loading, it expands the trust boundary by consuming secrets from an additional file outside the current workspace, which can inadvertently use sensitive credentials in broader channel contexts where the skill runs in the main agent rather than a per-peer isolated subagent.

Content

Scanner excerpt · scripts/_platform.py (reported line 48)May include surrounding context.

python
except Exception:
            pass

    # Legacy .hermes/.env
    hermes_env = Path.home() / ".hermes" / ".env"
    if hermes_env.exists():
        for line in hermes_env.read_text().splitlines():

Credential Access

High
Category
Privilege Escalation
Confidence
75% confidence
Finding

This code opens and parses ~/.hermes/.env to recover an API key, which is a form of local credential access. In this skill's context, the risk is elevated because the agent may operate without per-peer isolation on some channels, so loading host-level credentials from the operator's home directory can unintentionally expose privileged account usage across conversations or environments if other parts of the skill misuse the loaded key.

Content

Scanner excerpt · scripts/_platform.py (reported line 49)May include surrounding context.

python
pass

    # Legacy .hermes/.env
    hermes_env = Path.home() / ".hermes" / ".env"
    if hermes_env.exists():
        for line in hermes_env.read_text().splitlines():
            if line.startswith("OPENROUTER_API_KEY="):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file documents an operation that deletes all peer data and labels it as irreversible, but it does not provide a stronger user warning about backup/recovery implications or an explicit caution before execution. For destructive admin actions affecting user data, the skill description should include a clear warning so operators understand the impact before running the command.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The troubleshooting guidance tells the operator to verify SOUL.md contains the Chinese phrase "不要填 target 字段," indicating a fixed-language requirement embedded in the skill's behavior or prompts. Because the file does not offer a language choice or explain why Chinese is required, this appears to be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares significant capabilities and operational behavior involving shell execution, filesystem access, network access, and environment/config usage, but does not define an explicit tool/permission scope. In an agent framework, missing least-privilege boundaries increases the chance that the runtime grants broader access than required, enabling accidental or unauthorized file reads, writes, command execution, or outbound communication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Triggering on any attachment is overly broad for a skill that can ingest files, invoke external parsers, and create persistent session artifacts. This can cause unintended processing of sensitive or malicious files, accidental activation in unrelated conversations, and unnecessary exposure to risky file formats or URLs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The rule that any non-exit reply in an active session should invoke the skill is ambiguous and can capture unrelated user messages. In channels without per-peer isolation, this increases the risk of cross-context processing, accidental disclosure within the wrong session, or unauthorized progression of a workflow based on stray messages.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Earlier guidance says each finding must be a question or a gap-filling instruction and not written as doing the work for the requester. The later Q&A mappings prescribe direct imperative rewrites such as changing the ask to a specific phrasing and adding fixed background content, which conflicts with the stated questioning-only discipline.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow allows the agent to directly edit Lark or Google Drive documents, which materially expands its write capability beyond advisory review. In channels where the skill may run without strict per-peer isolation, a mis-scoped session, prompt confusion, or authorization mistake could cause unauthorized modification of third-party documents or corruption of business records.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains natural-language policy-relevant guidance showing a required delivery style example in Chinese ("前 3 行没说要什么。建议改成 X。") while the rest of the document is in English. Because no user opt-in, language selection mechanism, or justification for a Chinese-only locale is provided, this can force a specific language unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation defines automatic delivery of review outputs to third parties such as a boss, email recipients, and local archives, which materially expands the skill from private coaching into data exfiltration and surveillance of user-submitted drafts and conversations. In this skill context, the risk is elevated because users may reasonably expect confidential pre-meeting coaching, while summaries, finals, conversations, annotations, and dissent can be routed externally on close.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.