Back to skill

Security audit

Task Auditor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent task-auditing tool, but its script can write outside its intended audit folder when given a crafted task ID.

Install only if you intend to run a Chinese-language task auditor over OpenClaw task logs, and treat task IDs as trusted input until the script validates identifiers and confines all reads and writes to the intended task and memory directories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
audit.sh:25
Finding

Unsanitized Task ID Enables Path Traversal and Unauthorized File Writes

Content
View full analysis
"$report_file" << EOF # 🔍 任务审计报告 **任务 ID**: $task_id **审计时间**: $(date "+%Y-%m-%d %H:%M:%S") **质量评分**: $score/100 ``` ### Technical Analysis The script accepts `TASK_ID` directly from its first command-line argument: ```bash TASK_ID="$1" ``` This value is interpolated into log, source-report, and generated audit-report paths without validation or canonical containment checks. Shell quoting prevents shell metacharacters from causing direct command injection, but it does not prevent filesystem traversal through components such as `../`. Consequently, an attacker who can invoke the script can cause path resolution to escape the intended `completed`, `reports`, or `audits` directories. The `mkdir -p` operation can create attacker-selected directory structures, while the subsequent shell redirection can overwrite a writable file outside the expected audit directory. The destination is constrained to a name ending in `.audit.md`, unless an existing symbolic link at that destination redirects the write elsewhere. The source log and report paths are similarly affected. Their fixed suffixes limit arbitrary file selection, but an attacker can still target matching files outside the intended directories and infer information from the resulting quality score, issue list, and pass/ ...[truncated 1823 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. **Canonicalize and verify every constructed path** Resolve each path and ensure it remains beneath its expected base directory before reading or writing: ```bash AUDITS_DIR="${TASKS_DIR}/audits" mkdir -p -- "$AUDITS_DIR" audit_base=$(realpath -m -- "$AUDITS_DIR") report_file=$(realpath -m -- "${AUDITS_DIR}/${TASK_ID}.audit.md") case "$report_file" in "$audit_base"/*) ;; *) echo "Resolved audit path escapes the audit directory" >&2 exit 1 ;; esac ``` Apply equivalent containment checks to the `completed` and `reports` read paths. 3. **Defend against symbolic-link writes** Refuse output paths that are symbolic links and use a secure creation method that does not follow links. Where supported, use a small helper that opens the destination with `O_NOFOLLOW`, or write to a securely created temporary file within the validated audit directory and atomically rename it after verifying the destination. 4. **Apply restrictive permissions** Set a restrictive umask before creating reports or directories: ```bash umask 077 ``` 5. **Avoid running with unnecessary privileges** Execute the auditor under a dedicated account that can read only the required task artifacts and write only to the audit and alert directories. 6. **Add security regression tests** Tests should verify rejection of: - `../` traversal sequences. - Absolute paths. - Forward and backward path separators. - Empty or dot-only identifiers. - Symbolic-link output targets. - Identifiers that resolve outside each configured base directory. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Most user-facing descriptive content in the README is written in Chinese, and the file does not indicate that this locale is optional or region-specific. This can violate a language/locale policy when a skill implicitly forces a language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that usage scenarios are identified automatically based on the skill's concrete functionality, but it does not actually define any trigger conditions, boundaries, or intended use cases. In an agent skill ecosystem, vague activation guidance can cause the skill to be invoked in unintended contexts, increasing the chance of misuse, over-broad task interception, or unsafe auditing behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill description is written in Chinese and includes no indication that users may interact in another language or choose their preferred locale. Under the policy, a skill that effectively requires a specific language without opt-in should be flagged unless the constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's title/comments and all user-facing messages are in Chinese, including usage, audit results, alerts, and status logs. There is no indication that the skill is region-specific or that users can opt into another language, which creates a locale-policy concern under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The inline comment at L207 states that any score below 90 counts as failure, and the main flow enforces that by sending an alert and returning failed for scores under 90. However, generate_audit_report classifies scores from 80 to 89 as 基本通过 ('basically passed'), which contradicts the documented intent and resulting control flow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases include generic terms such as "quality check" and "audit task," which can plausibly match ordinary user requests unrelated to this specific skill. Overly broad activation increases the chance of unintended invocation, causing the skill to intercept benign conversations and apply its own auditing behavior in contexts where the user did not explicitly request it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all changelog content are written exclusively in Chinese, which indicates a fixed language choice in the skill’s natural-language materials. There is no visible opt-in, alternative language option, or justification that this skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill description and author-facing text are presented in Chinese, while the manifest does not indicate that language choice is optional or region-specific. This may create an implicit language constraint without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and test text are written only in Chinese, which imposes a specific language in user-visible natural-language content. The file does not offer a language choice or document a justified locale restriction, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.