Back to skill

Security audit

Proactive Trigger

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly fits a proactive engagement engine, but it stores behavioral profiles and includes unsafe command execution wrappers that need review before installation.

Install only if you are comfortable with a skill that profiles interaction timing, topics, responses, and possibly mood-related signals to decide when the agent should proactively contact you. Review or harden the OpenClaw CLI wrapper before use, require explicit opt-in for proactive messaging, and set clear retention/deletion controls for .openclaw/.soul state files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/openclaw-tools.js:43
Finding

OS Command Injection in the OpenClaw CLI Wrapper

Content
View full analysis

Vulnerability Details

File Location: scripts/openclaw-tools.js:43-62
Vulnerability Type: Shell command injection through unsafe string interpolation
Risk Level: High

Vulnerable Code

js
const paramString = Object.entries(params)
  .map(([key, value]) => {
    if (typeof value === 'boolean') {
      return value ? `--${key}` : '';
    } else if (value !== undefined && value !== null) {
      return `--${key} "${String(value).replace(/"/g, '\\"')}"`;
    }
    return '';
  })
  .filter(Boolean)
  .join(' ');

const command = `openclaw tool ${toolName} ${paramString}`;
console.log(`[CLI模式] 执行: ${command}`);

const output = execSync(command, { 
  encoding: 'utf-8',
  stdio: ['pipe', 'pipe', 'pipe'],
  cwd: WORKSPACE
});

Technical Analysis

The exported callTool() function constructs a shell command by directly interpolating toolName, parameter keys, and parameter values into a string passed to child_process.execSync().

The implementation only escapes double-quote characters in values. This does not prevent shell evaluation inside double quotes. Shell substitutions such as $(command) and backtick substitutions remain active. Parameter names and toolName receive no escaping or validation at all, allowing additional shell metacharacters to be introduced through those fields.

Because execSync() executes the resulting string through a shell, attacker-controlled data can alter the intended command rather than remaining a literal OpenClaw argument. The issue is reachable through the exported callTool() API and through higher-level exported functions that forward values to it, such as getGoalSuggestion(context) and updateContext(key, value).

Attack Path

  1. The OpenClaw executable is present, causing isOpenClawAvailable() to select CLI mode rather than the filesystem fallback.
  2. An integration, plugin, or other caller passes attacker-controlled text to an exported wrapper function or directly to callTool().

...[truncated 1366 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace shell-based execution with an argument-array API:
js
import { execFileSync } from 'node:child_process';

const allowedTools = new Set([
  'signal_publish',
  'signal_query',
  'signal_resolve',
  'context_get',
  'context_update',
  'goal_suggest'
]);

if (!allowedTools.has(toolName)) {
  throw new Error('Unsupported tool name');
}

const args = ['tool', toolName];

for (const [key, value] of Object.entries(params)) {
  if (!/^[A-Za-z0-9_-]+$/.test(key)) {
    throw new Error(`Invalid parameter name: ${key}`);
  }

  if (typeof value === 'boolean') {
    if (value) args.push(`--${key}`);
  } else if (value !== undefined && value !== null) {
    args.push(`--${key}`, String(value));
  }
}

const output = execFileSync('openclaw', args, {
  encoding: 'utf-8',
  stdio: ['pipe', 'pipe', 'pipe'],
  cwd: WORKSPACE,
  shell: false
});
  1. Allowlist supported tool names and parameter names rather than accepting arbitrary identifiers.
  2. Validate value types and enforce reasonable length limits before invoking the CLI.
  3. Avoid logging complete generated commands when arguments may contain private context or signal data.
  4. Add regression tests using values containing $(...), backticks, semicolons, newlines, quotes, and leading option characters. Tests should confirm that these values are passed literally and cannot create side effects.
  5. Prefer a direct OpenClaw library or structured API over command-line invocation when one is available.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/utils/openclaw-tools.js:43
Finding

OS Command Injection in the Duplicated Utility OpenClaw CLI Wrapper

Content
View full analysis

Vulnerability Details

File Location: scripts/utils/openclaw-tools.js:43-62
Vulnerability Type: Shell command injection through unsafe string interpolation
Risk Level: High

Vulnerable Code

js
const paramString = Object.entries(params)
  .map(([key, value]) => {
    if (typeof value === 'boolean') {
      return value ? `--${key}` : '';
    } else if (value !== undefined && value !== null) {
      return `--${key} "${String(value).replace(/"/g, '\\"')}"`;
    }
    return '';
  })
  .filter(Boolean)
  .join(' ');

const command = `openclaw tool ${toolName} ${paramString}`;
console.log(`[CLI模式] 执行: ${command}`);

const output = execSync(command, { 
  encoding: 'utf-8',
  stdio: ['pipe', 'pipe', 'pipe'],
  cwd: WORKSPACE
});

Technical Analysis

This file duplicates the vulnerable OpenClaw wrapper from scripts/openclaw-tools.js. It assembles an operating-system command from untrusted strings and executes it with execSync().

Replacing double quotes with escaped double quotes is insufficient shell escaping. Command substitutions using $(...) or backticks are still evaluated inside double-quoted shell arguments. In addition, toolName and parameter keys are inserted without any escaping or allowlist validation.

This duplicate is actively relevant because scripts/test-basic.js imports from scripts/utils/openclaw-tools.js, and other integrations may import the same utility path. Fixing only the top-level copy would therefore leave an independently exploitable command-execution path.

Attack Path

  1. Code imports scripts/utils/openclaw-tools.js and invokes an exported wrapper.
  2. The local OpenClaw executable passes the availability checks, enabling CLI mode.
  3. Attacker-controlled content reaches toolName, a parameter key, or a parameter value.
  4. The content includes shell syntax such as command substitution.
  5. The wrapper concatenates the content into the openclaw tool ... command.
  6. execSync() passes the ...[truncated 708 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the duplicated implementation and maintain a single hardened OpenClaw wrapper.
  2. Replace execSync() with execFileSync() or spawnSync() using an explicit argument array and shell: false.
  3. Allowlist tool names and accepted parameter keys.
  4. Validate argument types and impose length limits before execution.
  5. Never attempt to secure shell command construction using ad hoc character replacement.
  6. Update every import to reference the single hardened module.
  7. Add automated tests for both former import paths to ensure shell metacharacters are treated as literal argument content.
  8. Use static-analysis rules that prohibit string-form execSync() calls and flag command construction through template literals.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (47)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Direct read/write access to local signal queues and archive files, plus batch processing and cleanup of history, is infrastructure-level functionality rather than simple trigger assessment. Presenting this as a high-level proactive trigger skill obscures its ability to modify durable shared state, which can affect other components and create integrity risks across the system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Direct read/write access to local signal queues and archive files, plus batch processing and cleanup of history, is infrastructure-level functionality rather than simple trigger assessment. Presenting this as a high-level proactive trigger skill obscures its ability to modify durable shared state, which can affect other components and create integrity risks across the system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Direct read/write access to local signal queues and archive files, plus batch processing and cleanup of history, is infrastructure-level functionality rather than simple trigger assessment. Presenting this as a high-level proactive trigger skill obscures its ability to modify durable shared state, which can affect other components and create integrity risks across the system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Direct read/write access to local signal queues and archive files, plus batch processing and cleanup of history, is infrastructure-level functionality rather than simple trigger assessment. Presenting this as a high-level proactive trigger skill obscures its ability to modify durable shared state, which can affect other components and create integrity risks across the system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Direct read/write access to local signal queues and archive files, plus batch processing and cleanup of history, is infrastructure-level functionality rather than simple trigger assessment. Presenting this as a high-level proactive trigger skill obscures its ability to modify durable shared state, which can affect other components and create integrity risks across the system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Direct read/write access to local signal queues and archive files, plus batch processing and cleanup of history, is infrastructure-level functionality rather than simple trigger assessment. Presenting this as a high-level proactive trigger skill obscures its ability to modify durable shared state, which can affect other components and create integrity risks across the system.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
node scripts/trigger.js <命令> [选项]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
node scripts/trigger.js <命令> [选项]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
node scripts/trigger.js <命令> [选项]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
node scripts/trigger.js <命令> [选项]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
node scripts/trigger.js <命令> [选项]

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module probes for and executes an external CLI via shell commands, which is a powerful capability not justified by the stated purpose of a trigger engine. Even though parameters are partially quoted later, shell invocation and ambient execution rights create command-execution and privilege-boundary risks, especially in shared or user-influenced environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module probes for and invokes an external CLI via shell commands even though this skill is described as a proactive-trigger engine, not a system integration layer. Because both toolName and params are incorporated into a shell command string passed to execSync, this expands the attack surface to command execution and unexpected side effects if any upstream input is influenced by untrusted data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill includes message-sending behavior and writes outbound content to a log, which goes beyond timing evaluation into active user interaction. In this context, that is dangerous because a compromised or overreaching trigger module could autonomously send unwanted messages, spam users, or produce manipulative interventions without a separate policy gate.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares executable entry points (node scripts/trigger.js ...) but does not declare any tool scope or permissions, while analysis indicates environment access. Missing capability declarations weaken reviewability and sandbox policy enforcement, making it easier for the skill to access resources users and reviewers did not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says the skill triggers on '用户沉默、兴趣衰减、主动干预时机成熟' without defining thresholds, boundaries, or exclusion conditions. These terms are subjective and could overlap with normal conversation states, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents the description, commands, and usage guidance primarily in Chinese, which effectively imposes a language requirement on users. There is no indication that users can opt into another language or that the Chinese-only presentation is required for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown skill file presents all user-facing instructions in Chinese and does not indicate that users may choose another language or locale. Under the policy for natural-language violations, forcing a specific language without opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The topic registry stores persistent behavioral data including timestamps, mention history, trigger history, and inferred 'user_interest' scores, creating a long-lived profile of the user. In the context of an engine designed to decide when to proactively engage the user, this increases privacy risk and potential misuse because retention, transparency, and deletion boundaries are not defined.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document specifies automatic extraction of keywords, semantic clustering, and registration of user topics from conversations, which constitutes profiling of user behavior and interests. In a proactive-trigger skill, this is more sensitive because the derived profile is used to drive unsolicited interventions, yet the design includes no user notice, consent, or minimization controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill consumes mood-related signals such as emotional fluctuation or fatigue to influence triggering behavior, which involves sensitive inferred emotional-state data. Using such signals without transparent disclosure and consent is risky because it enables behavioral adaptation based on user vulnerability, and in this proactive-intervention context it can make nudging more intrusive or manipulative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly defines storage of detailed behavioral telemetry, including silence timing, rejection history, acceptance rate, and preferred interaction times, but provides no user-facing disclosure, consent model, retention limit, or minimization rule. In a proactive-triggering skill, this data can be used to profile user habits and optimize re-engagement in ways users may not expect, increasing privacy risk and the chance of manipulative contact patterns if mishandled or over-retained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all instructional content are written entirely in Chinese, which imposes a language choice in the skill documentation without any visible opt-in, alternative locale, or stated regional justification. Under the policy rules, a skill that forces one language or locale without user choice should be flagged.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger history stores detailed behavioral telemetry, including message content, timestamps, response classification, and response-time analytics, which exceeds what is needed merely to decide whether and when to trigger. Persisting this level of interaction history enables profiling of user behavior and preferences, increasing privacy exposure if the data is reused, over-retained, or accessed by other components.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented pre-trigger checks require data from other skills, including mood state and value-conflict evaluation, even though this skill’s stated purpose is only to decide trigger timing from silence, interest decay, and topic heat. This expands data access beyond necessity, creating an unjustified cross-skill dependency that can expose sensitive inferred data and increase privacy and misuse risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-tools.js:20

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/utils/openclaw-tools.js:20