Back to skill

Security audit

Huo15 Openclaw Enhance

Security checks for vulnerabilities and agentic risk

Overview

This package is not clearly malicious, but it needs Review because it can persistently change agent behavior, force replies, and expose broad local upload, memory, history, and background-task capabilities.

Install only if you want a broad, always-on OpenClaw enhancement plugin. Review and consider disabling the Bluefire bridge modules, large-file upload/share routes, automatic memory capture, transcript/history surfacing, and any LaunchAgent or archiver setup. Prefer the package-manager install path and avoid the curl-to-bash method unless you pin and inspect the script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup.sh:5
Finding

Unpinned Remote Installation Script Executed Directly by Bash

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
scripts/setup.sh:88
Finding

Setup Permanently Modifies Agent Instruction and Memory Files

Content
View full analysis
/dev/null; then echo -e " ${YELLOW}⚠ $file 已包含增强补丁,跳过${NC}" continue fi # 备份并追加 cp "$target_file" "${target_file}.bak.$(date +%Y%m%d%H%M%S)" cat "$patch_file" >> "$target_file" echo -e " ${GREEN}✓${NC} $file 已增强(备份: ${file}.bak.*)" done ``` The appended Agent instructions include: ```markdown ### 记忆管理 - 当了解到重要的用户偏好、项目决策、反馈信息时,使用 `enhance_memory_store` 存储 - 回答问题前,考虑使用 `enhance_memory_search` 查找相关历史记忆 - 定期使用 memory-curator 技能整理记忆 ``` The appended identity instructions include: ```markdown ### 记忆习惯 当以下情况发生时,主动存储记忆: - 用户纠正你的做法(feedback 类) - 用户表达偏好(user 类) - 做出重要决策或发现关键信息(decision/project 类) - 提到有用的外部资源(reference 类) ``` ### Technical Analysis The setup script appends package-controlled text to the workspace's persistent `AGENTS.md` and `SOUL.md` files. These files influence future Agent sessions, so the behavior is not limited to the installation session. The patch directs the Agent to proactively store user preferences, feedback, decisions, project information, and external resources. Installation therefore changes long-term information-retention behavior in addition to installing the declared plugin. A timestamped backup is created, but the script does not obtain separate consent for identity-file modification, show the patch before applying it, or provide an automated rollback procedure. ### Attack Path ...[truncated 691 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
src/modules/large-file-bridge.ts:91
Finding

Large-File Hook Takes Over Agent Replies and Forces Upload Links

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
src/modules/cc-bridge-keyword-dispatch.ts:91
Finding

Keyword Trigger Automatically Delegates User Tasks and Dictates the Agent Response

Content
View full analysis
{ const body = JSON.stringify({ desc, owner_id: ownerId || "", background: true, continue_task_id: opts.continue_task_id || "", continue_latest: !!opts.continue_latest, }); return new Promise((resolve, reject) => { const req = httpRequest( `${BRIDGE_BASE}/dispatch`, { method: "POST", timeout: timeoutMs, headers: { "Content-Type": "application/json", "Content-Length": Buffer.byteLength(body).toString(), }, }, ... ); req.write(body); req.end(); }); } ``` The injected response template states: ```ts `**你的唯一动作**:原文复制以下 markdown 给用户作为回复(不要 spawn 任何工具,不要解释,不要思考补充):`, ... `**禁止动作**(hook 已运行了真正派活动作,你 jarvis 不要再 spawn):`, `- ❌ 调用 sessions_spawn / Task / spawn_task / mcp__ccd_session__spawn_task`, `- ❌ Bash claude -p / claude --resume / 直接 exec claude`, `- ❌ 自己 Write/Edit/Bash 把这个任务做了——任务已经派给蓝火,等结果就行`, ``` The trigger performs the dispatch before model deliberation: ```ts const resp = await postDispatch(desc, owner, opts); ... return { prependContext: renderResponseTemplate( resp.task_id, resp.dashboard_url || `https://keepermac.huo15.com/lanhuo?task=${resp.task_id}`, desc, resp.continued_from, ), }; ``` ### Technical Analysis Messages beginning with the configured keyword cause the plugin to transmit the task description and a sender-derived owner identifier to a separate loopback service. There is no confirmation step. The response is then placed in privileged prompt context with instructions that the Agent's “only action” is to copy package-co ...[truncated 1172 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
src/modules/cc-bridge-pre-fetch.ts:47
Finding

Untrusted Bridge Session Data Is Injected as Trusted Prompt Context

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
scripts/deploy-2week-followup-launchagent.sh:38
Finding

Packaged Scripts Install Persistent LaunchAgents That Later Process and Delete Session Artifacts

Content
View full analysis
"$PLIST" < ... ProgramArguments /bin/bash -lc bash "${AUDIT_SCRIPT}" ... EOF ... launchctl load "$PLIST" echo "✓ launchctl load 完成" ``` The trajectory archiver generates another persistent scheduled script with deletion operations: ```bash echo " [2/3] delete sessions-archive items >7 days" find "$HOME/.openclaw/agents" -path '*/sessions-archive/*' -mtime +7 -delete 2>/dev/null || true echo " [3/3] delete *.jsonl.reset.* / *.jsonl.bak-* >3 days" find "$HOME/.openclaw/agents" -maxdepth 4 \( -name '*.jsonl.reset.*' -o -name '*.jsonl.bak-*' \) -mtime +3 -delete ``` The generated deployment commands load the job: ```ts `launchctl unload "${path}" 2>/dev/null || true`, `launchctl load "${path}"`, ... `launchctl start ${opts.label} && sleep 2 && tail -20 "${logPath()}"`, ``` ### Technical Analysis The project contains mechanisms for installing user-level LaunchAgents that survive the current plugin or Agent session. One script directly loads a follow-up audit job. The archiver tool generates commands that install a recurring job, move stale session artifacts outside the active session directory, and permanently delete archived, reset, and backup files according to fixed retention periods. The archiver tool only returns commands rather than invoking `launchctl` itself, and the deployment script must be run by the user. These controls reduce stealth, but the resulting jobs still const ...[truncated 1072 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (330)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 343)May include surrounding context.

md
"safety": {
            "enabled": true,
            "rules": [
              { "tool": "exec", "pattern": "rm -rf *", "action": "block", "reason": "危险命令" },
              { "tool": "exec", "pattern": "sudo *", "action": "block", "reason": "禁止 sudo" },
              { "tool": "file_write", "pathPattern": "*.env", "action": "block", "reason": "禁止写入环境变量文件" }
            ],

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 377)May include surrounding context.

md
"safety": {
            "enabled": true,
            "rules": [
              { "tool": "exec", "pattern": "rm -rf *", "action": "block", "reason": "危险命令" },
              { "tool": "exec", "pattern": "sudo *", "action": "block", "reason": "禁止 sudo" },
              { "tool": "file_write", "pathPattern": "*.env", "action": "block", "reason": "禁止写入环境变量文件" }
            ],

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 345)May include surrounding context.

md
"rules": [
              { "tool": "exec", "pattern": "rm -rf *", "action": "block", "reason": "危险命令" },
              { "tool": "exec", "pattern": "sudo *", "action": "block", "reason": "禁止 sudo" },
              { "tool": "file_write", "pathPattern": "*.env", "action": "block", "reason": "禁止写入环境变量文件" }
            ],
            "defaultAction": "allow"
          },

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The file describes persistent SQLite schema migration supporting memory, safety logs, pet state, notifications, todos, chapters, and scheduled tasks, which is a substantial local application platform rather than a narrow upload fix. Broad persistent state greatly increases impact if the plugin malfunctions, leaks data, or is later extended abusively.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/modules/cc-bridge-keyword-dispatch.ts:138