Back to skill

Security audit

Hi Register

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to finish Hi registration, but it grants an external integration sensitive session routing access and persistent push behavior with insufficient local safeguards.

Review this before installing. It is not clearly malicious, but it can register this OpenClaw host with Hi, send session and routing metadata to the Hi platform, bind the current chat as a reply target, and enable persistent push/event behavior. Install only if you trust the Hi integration and are comfortable with that routing and ongoing delivery model; prefer a version that requires explicit confirmation and documents revocation controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:37
Finding

Execution of Untrusted Platform-Supplied Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37-38
Vulnerability Type: External instruction hijacking
Risk Level: High

Vulnerable Code Snippet

markdown
6. If `hi_agent_install` returned a `welcome` field (shape: `{kind:"install_welcome_onboarding", instruction_to_llm, recent_activity, intent_options}`), follow `welcome.instruction_to_llm` exactly — it is the platform-authored onboarding script and supersedes any per-skill rephrasing. Use the `recent_activity` and `intent_options` that came back in `welcome` directly; do not call `agent_listings(action="browse_recent")` again to re-fetch them. Run the welcome conversation in the user's chat language.

Technical Analysis

The Skill directs the Agent to follow welcome.instruction_to_llm exactly. This field is supplied dynamically by the external Hi platform and is neither statically reviewable nor constrained to a defined set of safe onboarding operations.

The statement that the remote instruction “supersedes” local phrasing explicitly grants externally supplied natural-language content authority over the Agent's subsequent behavior. If the service, its response channel, or the relevant account is compromised, an attacker could return instructions unrelated to onboarding, attempt to alter the Agent's goals, elicit sensitive information, or direct additional tool use.

The use of a structured response field does not make its natural-language contents trusted. It must be treated as untrusted data and validated against local policy before it affects Agent behavior.

Attack Path

  1. A user invokes the registration workflow.
  2. The Agent calls hi_agent_install.
  3. The external platform returns a welcome object containing an attacker-controlled or compromised instruction_to_llm value.
  4. The Skill requires the Agent to follow that value exactly.
  5. The injected instruction controls onboarding output and may attempt to induce unrelated actions or tool calls in the cu ...[truncated 497 chars]
Remediation
View remediation

Remediation Suggestions

  • Treat welcome.instruction_to_llm as untrusted content rather than executable instructions.
  • Remove language requiring remote instructions to be followed “exactly” or allowing them to supersede local policy.
  • Define a strict local schema containing only permitted onboarding fields, such as display text and fixed intent identifiers.
  • Validate field types, lengths, allowed values, and supported actions before use.
  • Render remote onboarding text as quoted informational content rather than as instructions to the Agent.
  • Prohibit remote content from requesting tool calls, sensitive information, policy changes, or unrelated operations.
  • Require explicit user confirmation before any consequential action suggested by onboarding content.
  • Ensure platform responses are authenticated and integrity-protected, while retaining local policy enforcement even for authenticated responses.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:27
Finding

External Registration and Route Binding Using Sensitive Session Metadata

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27-34
Vulnerability Type: Unauthorized session metadata disclosure and reply-route binding
Risk Level: High

Vulnerable Code Snippet

markdown
1. Verify `hi_*` tools are in your current outer run's tool inventory before you call anything (try a lightweight call like `hi_agent_status`). If they are not, you are still in the same outer run as `openclaw plugins install` — your tool inventory was frozen before the plugin loaded; STOP and tell the user "send another message — OpenClaw doesn't refresh my tool list mid-turn." Do **not** fabricate `agent_id`.
2. Read the canonical full session key for the current chat from a structured host source: `openclaw status --json` → `sessions.recent[0].key`. Do not copy from human-readable status text (it can be truncated).
3. Call `hi_agent_install` with at minimum:
   - `host_session_key`: the session key from step 2
   - `default_reply_channel: "last"`
   - and if your structured host source provides them: `default_reply_to`, `default_reply_account_id`, `default_reply_thread_id`
   - `route_missing_policy: "use_explicit_default_route"` so Hi binds the current chat as the default reply target

Technical Analysis

The registration workflow obtains the canonical host session key and sends it to the external Hi platform. It may also transmit account, recipient, and thread routing identifiers. The platform then binds the selected chat as a default reply destination.

The Skill does not require informed user consent immediately before this disclosure and route binding. It also assumes that sessions.recent[0] represents the invoking chat. A “most recent” entry is not necessarily a secure identity binding: concurrent activity, background sessions, or ordering changes could cause the wrong session to be selected.

The canonical session key is more sensitive than a narrowly scoped opaque registration token because it directly identifies host sessio ...[truncated 1406 chars]

Remediation
View remediation

Remediation Suggestions

  • Require explicit, informed user consent before transmitting any session or routing metadata to an external service.
  • Obtain the invoking session identity directly from trusted invocation context rather than selecting sessions.recent[0].
  • Verify that the selected session, account, recipient, and thread correspond to the current user and conversation.
  • Replace the canonical session key with a short-lived, opaque, single-purpose registration token.
  • Scope the token to the intended platform, route, operation, and expiration time.
  • Omit optional default_reply_to, account, and thread identifiers unless the user specifically enables route binding.
  • Display the proposed external destination and reply route before registration and require confirmation.
  • Provide an accessible mechanism to inspect, change, and revoke the route binding.
  • Document data retention, access controls, and deletion behavior for all metadata transmitted to the external platform.

T06 · System Persistence

Error
Location
SKILL.md:50
Finding

Persistent External Hooks and Event Subscriptions Enabled During Registration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 50-54
Vulnerability Type: Persistent external push-delivery channel
Risk Level: High

Vulnerable Code Snippet

markdown
| | `openclaw plugins install clawhub:hirey` | `hi_agent_install` (this tool) |
|---|---|---|
| Where it runs | OpenClaw CLI (system) | Hi platform (agent runtime) |
| What it does | Lands the plugin tarball on disk + registers it with the gateway | Registers an AGENT identity for this OpenClaw host on the Hi platform; sets up hooks for push delivery; activates installation; subscribes to event topics |
| When | Stage A (turn 1) | Stage B (turn 2) |
| Required tool inventory | available in any LLM run | only in LLM runs whose inventory was materialized AFTER the plugin loaded |

Technical Analysis

The Agent-side registration operation does more than establish a one-time identity. It also sets up hooks for push delivery, activates the installation, and subscribes to event topics. These features create an ongoing externally triggered communication path that can remain relevant after the immediate registration interaction.

The Skill does not define which event topics are subscribed to, what permissions delivered events possess, how events are authenticated, how long hooks remain active, or how users can revoke them. Registration therefore bundles persistent asynchronous capabilities into a general setup action without describing least-privilege boundaries.

If the external service, hook credentials, or event publication controls are compromised, forged or malicious events could be delivered through a trusted integration channel. The actual actions available to such events depend on runtime enforcement and are not specified in the reviewed file.

Attack Path

  1. A user initiates Hi registration.
  2. hi_agent_install registers an Agent identity for the host.
  3. The operation activates the installation, creates push-delivery hooks, and subscribes the installa ...[truncated 838 chars]
Remediation
View remediation

Remediation Suggestions

  • Separate basic identity registration from hook creation, activation, and event subscription.
  • Keep push hooks and subscriptions disabled by default.
  • Obtain distinct user consent for every persistent or asynchronous capability.
  • Enumerate requested event topics and allow users to select the minimum necessary set.
  • Authenticate every event with scoped credentials and verify integrity, freshness, audience, and replay protection.
  • Apply strict authorization at event-processing time; receipt of an event must not itself authorize tool use or privileged actions.
  • Use short-lived, rotatable hook credentials and narrowly scoped subscription tokens.
  • Provide commands or controls to list active hooks and subscriptions and to revoke them immediately.
  • Define expiration, retention, audit logging, and incident-response requirements.
  • Require confirmation before externally delivered events cause consequential actions.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger guidance includes very broad phrases like 'set up', 'register', 'activate', and 'connect' that can appear in many unrelated conversations. This can cause the skill to auto-invoke outside its intended install context, increasing the chance of unintended registration actions or confusing tool execution in a security-sensitive setup flow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Allowing activation on a 'fresh message' or 'anything else' after install is overly ambiguous because nearly any follow-up user message could trigger the registration flow. In this context, the skill performs agent registration and binds reply routing, so accidental invocation could create unintended state changes or mislead the user about what action is being taken.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.