Back to skill

Security audit

Skill Reviewer Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a review checklist for OpenClaw skills and does not contain hidden code, persistence, credential use, or destructive behavior.

This skill is reasonable to install for reviewing OpenClaw skills. Before using it, treat its language-matching rule as a preference rather than a hard override, and verify any local validation command path before running it against your skill files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
92% confidence
Finding

The phrase 'IMPORTANT: Always respond...' is an anti-refusal style absolute instruction embedded in the skill definition. Absolute mandates are dangerous because they attempt to lock model behavior and can conflict with higher-priority safety rules or prevent the model from pausing to clarify or decline unsafe requests.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: skill-reviewer-pro
description: Comprehensive skill review and validation for OpenClaw skills. Performs multi-level review: (1) Format validation, (2) Writing quality assessment (structure, description, examples, scoring), (3) Functional verification (templates match OpenClaw specs), (4) Best practices check, (5) Optimization recommendations, (6) Workflow validation (for workflow tools). Use when auditing skills before publishing, evaluating downloaded skills, or improving existing skills. IMPORTANT: Always respond in the same language as the user's request (auto-adapt to user's language).
---

# Skill Reviewer Pro

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
94% confidence
Finding

This is another repeated absolute command directing the model to always respond in the user's language. Repeated anti-refusal phrasing increases the chance the instruction will dominate the skill's behavior and suppress necessary exceptions or clarifications.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
## Language Adaptation

**IMPORTANT: Always respond in the same language as the user's request.**

- If user asks in Chinese → respond in Chinese
- If user asks in English → respond in English

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
95% confidence
Finding

The 'CRITICAL: Always respond...' wording is a strong instruction-shaping mechanism. In adversarial or mixed-instruction environments, this kind of language is risky because it encourages unconditional compliance with skill-local rules rather than balanced adherence to higher-level controls.

Content

Scanner excerpt · SKILL.md (reported line 378)May include surrounding context.

md
## Language Adaptation Guidelines

**CRITICAL: Always respond in the same language as the user's request.**

### Detection Rules

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 435)May include surrounding context.

md
- File names (e.g., "SKILL.md", "IDENTITY.md")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes a response-language policy ('always respond in the same language as the user's request') without offering user override or documenting a business justification. This reduces operator control and can be used to steer model behavior in ways that conflict with higher-priority instructions or deployment policy, especially when repeated as a mandatory rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section repeatedly enforces fixed language-routing rules and removes discretion from the reviewing agent. Repetition strengthens the instruction and makes it more likely the skill will override contextual safety, policy, or user-choice considerations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| Correct CLI commands are used | ❌ Missing | No `openclaw agents add` command |
| Error handling is documented | ❌ Missing | No error handling in any phase |
| Backup and recovery mechanisms exist | ❌ Missing | No backup before config changes |
| Verification steps are included | ❌ Missing | No verification after agent registration |
| Configuration management is documented | ❌ Missing | No auth-profiles.json documentation |
| Failure recovery strategies exist | ❌ Missing | No recovery strategies for any phase |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
| Correct CLI commands are used | ❌ Missing | No `openclaw agents add` command |
| Error handling is documented | ❌ Missing | No error handling in any phase |
| Backup and recovery mechanisms exist | ❌ Missing | No backup before config changes |
| Verification steps are included | ❌ Missing | No verification after agent registration |
| Configuration management is documented | ❌ Missing | No auth-profiles.json documentation |
| Failure recovery strategies exist | ❌ Missing | No recovery strategies for any phase |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 363)May include surrounding context.

md
| Correct CLI commands are used | ❌ Missing | No `openclaw agents add` command |
| Error handling is documented | ❌ Missing | No error handling in any phase |
| Backup and recovery mechanisms exist | ❌ Missing | No backup before config changes |
| Verification steps are included | ❌ Missing | No verification after agent registration |
| Configuration management is documented | ❌ Missing | No auth-profiles.json documentation |
| Failure recovery strategies exist | ❌ Missing | No recovery strategies for any phase |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The detailed language adaptation guidelines impose mandatory detection, mapping, and consistency requirements across the entire workflow. That kind of rigid behavioral constraint is risky in agent skills because it can function as instruction shaping that limits safe refusal, operator override, or multilingual clarification when needed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.