Back to skill

Security audit

Context Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill describes a useful context-monitoring purpose, but it asks users to create persistent hourly agent execution and run an unaudited PowerShell script path with execution-policy bypass.

Review this before installing. Do not enable the cron command or PowerShell bypass unless you have the actual scripts, have verified their contents and hashes, understand what conversation data may be compressed or lost, and know how to disable the scheduled task.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:61
Finding

Persistent Hourly Execution Through an OpenClaw Scheduled Task

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 61
Vulnerability Type: Persistent scheduled Agent execution
Risk Level: High

Vulnerable Code

bash
openclaw cron add --name context-monitor --cron "0 * * * *" --agent main --message "Execute the context-monitor skill"

The displayed task message has been translated into English; the source contains an equivalent non-English instruction.

Technical Analysis

The installation instructions direct the user to create an hourly scheduled task targeting the main Agent. The task survives the initial Skill invocation and repeatedly instructs the Agent to execute the Skill.

The audited package contains only SKILL.md. The referenced monitor.ps1, compress.ps1, and configuration files are absent. Consequently, the package cannot provide the documented monitoring and compression implementation, while the scheduled Agent invocation remains persistent. If executable files are subsequently introduced at the documented locations, the recurring task could cause them to be processed or executed without a new explicit installation decision.

Attack Path

  1. A user trusts the installation instructions in SKILL.md.
  2. The user runs the supplied openclaw cron add command.
  3. OpenClaw creates an hourly task associated with the main Agent.
  4. The task continues across sessions and repeatedly requests execution of the Skill.
  5. If content at the expected Skill path is later replaced or supplemented, subsequent scheduled invocations may process that changed content automatically.

Impact Assessment

The task obtains persistent execution within the authority and tool scope available to the main Agent. Potential consequences include recurring resource consumption, repeated unwanted Agent activity, and automatic invocation of content introduced after the initial review. The exact system impact depends on the privileges and tools granted to the `ma ...[truncated 177 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove automatic scheduled-task registration from the default setup procedure.
  • Provide the complete, auditable monitoring implementation before offering recurring execution.
  • Require explicit informed consent before creating any persistent task.
  • Use a dedicated least-privileged Agent rather than the main Agent.
  • Pin the scheduled task to integrity-verified content and reject execution if file hashes change.
  • Document how to inspect, disable, and remove the scheduled task.
  • Add rate limits, failure cutoffs, and bounded resource consumption.
  • Prefer a manual or nonpersistent execution mode as the secure default.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:50
Finding

PowerShell Execution-Policy Bypass Used to Run an Absent Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 50-54 and 89-93
Vulnerability Type: Unsafe PowerShell execution configuration
Risk Level: Medium

Vulnerable Code

Primary execution instruction at line 54:

powershell
powershell -ExecutionPolicy Bypass -File workspace/skills/context-monitor/monitor.ps1

Troubleshooting instruction at line 93:

powershell
Set-ExecutionPolicy -ExecutionPolicy Bypass -Scope Process

Technical Analysis

Both instructions bypass PowerShell execution-policy checks. Although execution policy is not a complete security boundary, bypassing it removes a defense-in-depth mechanism that can prevent or warn about untrusted scripts.

The risk is increased because monitor.ps1 is not present in the audited package. The command therefore refers to unaudited content at a predictable relative path. If another user, package, process, or attacker can create or replace that file before execution, the user may run arbitrary PowerShell commands under their current account privileges.

The relative path also makes behavior dependent on the current working directory. This increases the possibility of resolving an unintended script where directory contents are attacker-controlled.

Attack Path

  1. A user follows the manual-execution or troubleshooting instructions.
  2. PowerShell execution-policy checks are bypassed for the launched process.
  3. An attacker or another local component places a malicious monitor.ps1 at the expected relative path, or influences the working directory so the path resolves to attacker-controlled content.
  4. The user runs the documented command.
  5. The substituted script executes with the permissions of the user who launched PowerShell.

Impact Assessment

Successful exploitation permits arbitrary PowerShell execution with the invoking user's privileges. Depending on those privileges, an attacker could read or modify user-accessi ...[truncated 368 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not use -ExecutionPolicy Bypass or instruct users to change execution policy.
  • Include every referenced script in the package so it can be reviewed with the Skill.
  • Sign PowerShell scripts and require signature validation where supported.
  • Use a canonical absolute path derived from a trusted installation directory rather than a working-directory-relative path.
  • Verify the script against a pinned cryptographic hash before execution.
  • Validate directory ownership and permissions to prevent script replacement.
  • Run the script with the minimum necessary operating-system and application privileges.
  • Fail securely when the expected script is missing or its integrity cannot be verified.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes automatic compression of old conversations once thresholds are exceeded, but it does not clearly disclose that conversation history may be irreversibly altered, summarized, or lost. In a context-management skill, that omission is security-relevant because users or operators may enable automation without understanding the effect on auditability, retained instructions, or recovery of prior data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents all operational instructions, warnings, and usage details in Chinese only. Under the stated policy, forcing a single language without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.