Back to skill

Security audit

OpenClaw Manager

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local manager skill, but its unauthenticated sidecar can read and change local work records, and some exports may contain more data than the redaction claims imply.

Install only if you are comfortable running a local manager process that stores chat-derived work state on disk. Keep the sidecar bound to 127.0.0.1, do not enable 0.0.0.0 or :: binding without adding authentication, and review any generated snapshots before sharing because run-evidence exports can include raw message and event data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
src/api/server.ts:23
Finding

Unauthenticated Sidecar API Exposes and Modifies Sensitive Manager State

Content
View full analysis
{ const runtime = await bootstrapManagerRuntime(); const app = express(); app.use(express.json({ limit: '1mb' })); app.get('/health', healthHandler(runtime.store)); app.get('/sessions', async (_req: Request, res: Response) => { res.json(await runtime.sessionService.listSessions()); }); ``` Representative state-changing endpoints are also registered without authentication or authorization: ```ts app.post('/sessions/:id/checkpoint', async (req: Request, res: Response) => { const result = await runtime.sessionService.checkpoint(String(req.params.id), req.body || {}); await runtime.attentionService.refresh(await runtime.sessionService.listSessions()); res.json(result); }); app.post('/sessions/:id/close', async (req: Request, res: Response) => { const session = await runtime.sessionService.close( String(req.params.id), (req.body || {}) as CloseSessionInput ); const fact = await runtime.capabilityFactService.createFromClosure(session, req.body || {}); const snapshot = await runtime.shareService.createSnapshot(session, 'capability_snapshot', { fact_id: fact.fact_id, }); await runtime.attentionService.refresh(await runtime.sessionService.listSessions()); res.json({ session, capability_fact: fact, snapshot, }); }); app.post('/inbound-message', inboundHandler(runtime.shadowService)); ``` The server may explicitly be exposed on all interfaces: ```ts export const resolveBindHost = () => { const configured = (process.env.OPENCLAW_MANAGER_BIND_HOST || DEFAULT_SIDECAR_HOST).trim(); const normalized = normalizeHost(configured); if (is ...[truncated 2704 chars]
Remediation
View remediation
` header on every route except a minimal liveness endpoint. 3. Compare tokens with a timing-safe operation and never place tokens in URLs or logs. 4. Introduce authorization checks for sensitive operations such as session closure, connector ingestion, thread promotion, and evidence export. 5. Refuse `0.0.0.0` and `::` binding unless strong authentication has been configured and explicitly acknowledged. 6. Prefer a Unix-domain socket with restrictive filesystem permissions for local-only deployments where supported. 7. Apply rate limiting, request auditing, and conservative request-size limits. 8. If browser clients are supported, configure a strict origin policy and CSRF protection rather than treating loopback as authentication. 9. Add automated tests verifying that anonymous requests to every non-health endpoint receive `401 Unauthorized` or `403 Forbidden`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
src/storage/fs-store.ts:60
Finding

Unvalidated Session and Run Identifiers Permit Filesystem Path Traversal

Content
View full analysis
{ const session = await runtime.sessionService.getSession(String(req.params.id)); if (!session) { res.status(404).json({ error: 'Session not found.' }); return; } ``` The storage layer directly incorporates those strings into filesystem paths: ```ts sessionDir(sessionId: string) { return path.join(this.sessionsDir, sessionId); } runsDir(sessionId: string) { return path.join(this.sessionDir(sessionId), 'runs'); } runDir(sessionId: string, runId: string) { return path.join(this.runsDir(sessionId), runId); } sessionFile(sessionId: string) { return path.join(this.sessionDir(sessionId), 'session.json'); } summaryFile(sessionId: string) { return path.join(this.sessionDir(sessionId), 'summary.md'); } attentionFile(sessionId: string) { return path.join(this.sessionDir(sessionId), 'attention.json'); } shareDir(sessionId: string) { return path.join(this.sessionDir(sessionId), 'share'); } artifactsDir(sessionId: string) { return path.join(this.sessionDir(sessionId), 'artifacts'); } runFile(sessionId: string, runId: string) { return path.join(this.runDir(sessionId, runId), 'run.json'); } eventsFile(sessionId: string, runId: string) { return path.join(this.runDir(sessionId, runId), 'events.jsonl'); } spoolFile(sessionId: string, runId: string) { return path.join(this.runDir(sessionId, runId), 'spool.jsonl'); } checkpointFile(sessionId: string, runId: string) { return path.join(this.runDir(sessionId, runId), 'checkpoint.json'); } skillTracesFile(sessionId: string, runId: string) { return path.join(this.runDir(sess ...[truncated 3054 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/control-plane/share-service.ts:46
Finding

Snapshots Marked as Redacted Can Contain Raw Message and Event Payloads

Content
View full analysis
`${event.timestamp} ${event.event_type} ${JSON.stringify(event.payload)}`) )} ${renderRecords( 'Spool Preview', spool.map((entry) => `${entry.created_at} ${entry.entry_type} ${JSON.stringify(entry.payload)}`) )} ``` ### Technical Analysis Inbound message content ...[truncated 1893 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description frames the capability reporting as local-manager functionality, but the detected behavior includes telemetry aggregation, anonymized exports containing fact payloads, and capability graph summaries. Undisclosed analytics and export behavior can create data exposure risk because operators may not expect collection, transformation, or export of fact payloads from a skill presented as a local control-plane utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description frames the capability reporting as local-manager functionality, but the detected behavior includes telemetry aggregation, anonymized exports containing fact payloads, and capability graph summaries. Undisclosed analytics and export behavior can create data exposure risk because operators may not expect collection, transformation, or export of fact payloads from a skill presented as a local control-plane utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description frames the capability reporting as local-manager functionality, but the detected behavior includes telemetry aggregation, anonymized exports containing fact payloads, and capability graph summaries. Undisclosed analytics and export behavior can create data exposure risk because operators may not expect collection, transformation, or export of fact payloads from a skill presented as a local control-plane utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description frames the capability reporting as local-manager functionality, but the detected behavior includes telemetry aggregation, anonymized exports containing fact payloads, and capability graph summaries. Undisclosed analytics and export behavior can create data exposure risk because operators may not expect collection, transformation, or export of fact payloads from a skill presented as a local control-plane utility.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
- bootstrap runtime: `src/skill/bootstrap.ts`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- local sidecar API: `src/api/server.ts`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- command registry: `src/skill/commands.ts`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- capability graph: `src/telemetry/capability-graph.ts`

Known Vulnerable Dependency: path-to-regexp==8.3.0 — 2 advisory(ies): CVE-2026-4923 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple w); CVE-2026-4926 (path-to-regexp vulnerable to Denial of Service via sequential optional groups)

High
Category
Supply Chain
Confidence
93% confidence
Finding

path-to-regexp 8.3.0 is flagged for ReDoS/DoS conditions involving crafted route patterns or matching behavior. Because this package is part of the Express routing stack in an HTTP-facing manager/sidecar skill, denial-of-service against request handling is contextually more relevant and could disrupt the local service or automation workflows.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 43)May include surrounding context.

sh
CURRENT_REGISTRY="$(npm config get registry)"
if [[ "$CURRENT_REGISTRY" != "$EXPECTED_REGISTRY" ]]; then
  echo "Warning: npm registry is '$CURRENT_REGISTRY'. This repo pins '$EXPECTED_REGISTRY' via .npmrc." >&2
fi

if grep -q "registry.npmmirror.com" package-lock.json; then

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 54)May include surrounding context.

sh
npm ci
npm run build

if [[ ! -f ".env.local" ]]; then
  cp .env.example .env.local
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 55)May include surrounding context.

sh
npm run build

if [[ ! -f ".env.local" ]]; then
  cp .env.example .env.local
fi

mkdir -p "$STATE_ROOT_VALUE"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 84)May include surrounding context.

sh
npm run build

if [[ ! -f ".env.local" ]]; then
  cp .env.example .env.local
fi

mkdir -p "$STATE_ROOT_VALUE"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 84)May include surrounding context.

sh
TARGET_DIR="$CODEX_HOME_VALUE/skills/openclaw-manager"
  mkdir -p "$TARGET_DIR"
  if command -v rsync >/dev/null 2>&1; then
    rsync -a --delete --exclude node_modules --exclude dist --exclude .git --exclude .env --exclude .env.local "$REPO_ROOT/" "$TARGET_DIR/"
  else
    cp -R "$REPO_ROOT"/. "$TARGET_DIR"/
    rm -rf "$TARGET_DIR/node_modules" "$TARGET_DIR/dist" "$TARGET_DIR/.git"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The fallback path uses cp -R into a user-controlled TARGET_DIR and then performs rm -rf on subpaths under that target. Although quoted and limited to appended subdirectories, the script does not validate CODEX_HOME_VALUE/TARGET_DIR, so an unexpected or sensitive destination could be modified or partially deleted if the caller supplies a dangerous path.

Content

Scanner excerpt · scripts/install.sh (reported line 87)May include surrounding context.

sh
rsync -a --delete --exclude node_modules --exclude dist --exclude .git --exclude .env --exclude .env.local "$REPO_ROOT/" "$TARGET_DIR/"
  else
    cp -R "$REPO_ROOT"/. "$TARGET_DIR"/
    rm -rf "$TARGET_DIR/node_modules" "$TARGET_DIR/dist" "$TARGET_DIR/.git"
  fi
fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises capabilities related to a local control plane, sidecar operation, connectors, and telemetry, yet it does not declare any explicit tool scope or allowed-tools policy in SKILL.md. For a skill that appears to require environment and network access, missing scope increases the chance of overbroad execution privileges and makes review and containment materially harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The health endpoint returns sensitive operational metadata including the internal filesystem state root, bind host, port, and autostart consent setting. Even if intended for local use, exposing these values to any caller increases information disclosure risk by helping an attacker map the environment, locate stored data, and understand service topology for follow-on attacks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes multiple Chinese-only phrase lists for noise, task intent, context, and blocker detection, which embeds a locale-specific behavior into classification logic. Because there is no accompanying opt-in, fallback, or documented justification that this classifier is intentionally limited to a Chinese locale, this creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code persists normalized inbound message fields including content, attachments, and metadata to a file-backed spool. In this file, there is no confirmation prompt, logging, comment, or docstring explaining that potentially sensitive user data will be stored, which matches the missing-warning criterion for code files handling file writes and user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The /share command creates and returns session snapshots without any visible confirmation, disclosure, or policy check in this command path. Because snapshots may contain task state, run evidence, or capability data, an accidental or unauthorized invocation could expose sensitive session information more easily than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code launches a detached background sidecar process, suppresses its stdio, and immediately unreferences it, which makes the process persistent and largely invisible to the user. In a skill context, that reduces user awareness and operator control, increasing the risk of stealthy long-running behavior, unexpected resource use, or continued local service exposure even after the parent workflow exits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The service persists trace records to disk via appendJsonl, and nearby logic also records input and output summaries associated with session and run identifiers. In this file there is no confirmation prompt, warning comment, docstring, or other visible disclosure that user-derived telemetry is being stored and emitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The append calls send structured telemetry including skill name, role, input summary, output summary, outcome, and latency to an external service component. Because this is a code file and no inline disclosure, prompt, or explanatory comment is present here, the data transmission lacks visible user warning under the specified criteria.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==2.2.2 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
82% confidence
Finding

body-parser 2.2.2 is flagged with a denial-of-service advisory tied to invalid limit handling. In a lockfile this is a real supply-chain exposure because the vulnerable version is pinned transitively through express, though the practical impact depends on whether request body parsing is used with attacker-controlled inputs and unsafe limit configuration.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.4 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
78% confidence
Finding

esbuild 0.27.4 includes a reported arbitrary file-read issue affecting its development server on Windows. This is a real dependency risk in the dev toolchain, but it is less dangerous here because esbuild is marked as a devDependency and the vulnerable condition generally requires running the dev server in a specific Windows development context.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/skill/sidecar-launcher.ts:18