Back to skill

Security audit

OpenClaw Chinese Laoshi Ops

Security checks for vulnerabilities and agentic risk

Overview

This looks like an instruction-only Chinese lesson skill, but it is incomplete because it advertises bundled lesson and prompt assets that are not actually included.

Review this before installing and ask the publisher to either include the missing course-data and system-prompts assets or revise the skill so it no longer claims they are bundled. Do not allow repository commands or Drive sync unless the exact command is shown, the source repo documents it, and you intentionally provide the local mount path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
and GitHub publication should assume anyone can read `SKILL.md`.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/release-gates.md (reported line 19)May include surrounding context.

md
- absolute local paths from macOS, Linux, or Windows home directories
- loopback or debugging endpoints such as `localhost`, `127.0.0.1`, `ws://`,
  `wss://`, or `devtools/browser`
- secret-shaped strings such as API keys, GitHub personal access tokens, or
  inline passwords
- known Drive file IDs copied from the project manifests
- drift between the public skill copy and the bundled plugin copy

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language metadata repeatedly frames the skill as specifically for Chinese lesson operations (e.g. "Chinese Laoshi Ops" and "Use Chinese Laoshi Ops"), which signals a fixed language/locale expectation. The file does not mention user choice, opt-in, or a documented region-specific justification, so this appears to violate the language/locale policy constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.