Security audit
AIPASS
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only skill that tells the agent to use AIPASS credential tools without exposing secrets, and its safeguards are clear and purpose-aligned.
Install this only if you intend to use AIPASS as the broker for credentials. You should still review the separate AIPASS native app and OpenClaw tool plugin, because those components perform the actual credential access and enforcement.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
