Back to skill

Security audit

ClawShow-Gateway-Connect

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated gateway-migration purpose, but it would enable a public wildcard channel and handle an auth token in ways users should review carefully.

Review this before installing if your OpenClaw agent has meaningful tool access. Use an explicit allowlist instead of allowFrom ["*"] unless you intentionally want public relay access, avoid passing the full token-bearing config on the command line if safer input methods exist, protect or delete secret-bearing backups when no longer needed, and pin reviewed package/plugin versions where possible.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:54
Finding

Wildcard Sender Policy Permits Unauthorized Gateway Access

Content
View full analysis
"` (required) - `channels.clawshow.name: "ClawShow Gateway"` (required) - `channels.clawshow.dmPolicy: "open"` (required) - `channels.clawshow.allowFrom: ["*"]` (required) ``` ### Technical Analysis The Skill mandates both an open direct-message policy and a wildcard sender allowlist. This configuration is not limited to identities authorized by the user and does not follow a deny-by-default access-control model. If the ClawShow relay forwards sender identities to the Gateway according to these fields, `dmPolicy: "open"` combined with `allowFrom: ["*"]` causes messages from every relay-recognized sender to be accepted. This is unnecessary for the core installation and migration operation and expands access beyond least privilege. The authentication token protects the Gateway's connection to the relay but does not replace sender-level authorization. Consequently, possession of the Gateway token is not necessarily required for an external sender to interact with the exposed channel. ### Attack Path 1. The Skill installs and enables the ClawShow Gateway channel. 2. It applies `dmPolicy: "open"` and `allowFrom: ["*"]`. 3. An attacker obtains ordinary access to the relay or another supported ClawShow messaging endpoint. 4. The attacker sends a message using any sender identity accepted by the relay. 5. The wildcard policy authorizes the sender without requiring explicit appro ...[truncated 778 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:76
Finding

Authentication Token Is Passed in Plaintext Through a Command-Line Argument

Content
View full analysis
"` (required) - `channels.clawshow.name: "ClawShow Gateway"` (required) - `channels.clawshow.dmPolicy: "open"` (required) - `channels.clawshow.allowFrom: ["*"]` (required) ``` ```markdown 9. Apply config (Config RPC only) - Follow `Config RPC (programmatic updates)` exactly, using `config.apply (full replace)`. - Do not use direct file-edit-only activation, `config.patch`, or manual restart as the primary path. - Execute: - `openclaw gateway call config.get --params '{}'` - Capture `payload.hash` as `baseHash`. - Build the full post-migration config as one JSON5 string in `raw`. - `openclaw gateway call config.apply --params '{ "raw": "", "baseHash": "", "note": "migrate to @bowong/clawshow-gateway" }'` - Respect control-plane rate limits for write RPCs (`config.apply`, `config.patch`, `update.run`): 3 requests per 60 seconds per `deviceId+clientIp`. - If apply fails due to stale hash/conflict, call `config.get` again, rebase on newest config, and retry once. ``` ### Technical Analysis The Skill requires the real authentication token to be embedded in the full configuration and then instructs the Agent to place that configuration inside the `--params` command-line argument. Command-line arguments are not an appropriate secret-transport mechanism. Depending on the operating system, shell, execution wrapper, and monitoring environment, the resul ...[truncated 1855 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Code Installation

Content
View full analysis
Remediation
View remediation
` - `openclaw plugins install @bowong/clawshow-gateway@` if supported. - Commit and enforce a lockfile with integrity hashes for npm dependencies. - Use a trusted registry and explicitly configured package scope. - Verify package signatures, checksums, provenance attestations, or publisher identity before installation. - Review transitive dependencies and scan the resolved package tree for known vulnerabilities. - Disable npm lifecycle scripts with `--ignore-scripts` when they are not required. - Install and run plugins with a minimally privileged account or within an appropriate sandbox. - Avoid reinstalling dependencies on every invocation when a verified version is already present. - Define an explicit upgrade process that reviews and approves new versions before deployment. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.