Back to skill

Security audit

Identity Trust

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for decentralized identity work, but needs Review because it installs mutable external code and creates persistent local identity credentials and keys with limited safety guidance.

Review before installing. Use a pinned package version or reviewed commit in a sandboxed, unprivileged environment, protect ~/.openclaw/identity/ with strict permissions, avoid syncing or exporting that directory casually, and require explicit user confirmation before creating DIDs, issuing credentials, exporting data, or enabling network resolution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned External Package Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:28-52; mirrored in SKILL-EN.md:28-52 and SKILL-ZH.md:28-52
Vulnerability Type: Unpinned third-party package and source installation
Risk Level: Medium

Vulnerable Code

bash
# Install globally for CLI access
npm install -g openclaw-identity-trust

# Verify installation
identity-trust --version
bash
# Clone repository
git clone https://github.com/ZhenRobotics/openclaw-identity-trust.git
cd openclaw-identity-trust

# Install dependencies
npm install

# Build
npm run build
bash
# Check CLI is working
identity-trust info

# Create your first DID
identity-trust did create

Technical Analysis

The Skill directs users or agents to retrieve and execute mutable third-party code without pinning an exact npm package version, repository commit, dependency lock state, or integrity digest.

npm install -g openclaw-identity-trust resolves the package version at installation time and may execute npm lifecycle scripts. The global installation also exposes package-provided command aliases across the user's environment. The alternative GitHub procedure clones the current default branch and subsequently runs npm install and npm run build, allowing both repository content and transitive dependencies to differ from what was reviewed.

The audited artifact contains documentation only. It does not include the referenced implementation, package manifest, lockfile, installation scripts, or cryptographic integrity metadata. Consequently, the external package's implementation and security claims cannot be verified from this project.

This finding does not establish that the current external package is malicious. It establishes an unsafe supply-chain boundary in which code executed later is not cryptographically or immutably tied to the reviewed Skill.

Attack Path

  1. A user or AI agent loads the Skill and follows its re ...[truncated 1505 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm dependency to a reviewed, exact version rather than relying on the latest matching release:

    bash
    npm install --global openclaw-identity-trust@1.0.0
    
  2. Pin source installations to a reviewed commit hash and verify the checked-out revision before installation:

    bash
    git clone https://github.com/ZhenRobotics/openclaw-identity-trust.git
    cd openclaw-identity-trust
    git checkout --detach <reviewed-commit-hash>
    test "$(git rev-parse HEAD)" = "<reviewed-commit-hash>"
    
  3. Publish and verify signed release artifacts or cryptographic checksums. Document the expected digest in the Skill so the retrieved artifact can be tied to the audited version.

  4. Include the implementation, package.json, and a committed lockfile in the audit scope. Use deterministic installation such as npm ci rather than unconstrained npm install.

  5. Review all lifecycle and build scripts before execution. Where compatible with the package, initially install dependencies with lifecycle scripts disabled:

    bash
    npm ci --ignore-scripts
    
  6. Avoid global installation where possible. Use a dedicated project environment, container, or otherwise sandboxed unprivileged account with restricted filesystem and network access.

  7. Require explicit user confirmation before installing external code, generating DIDs, or creating persistent key material.

  8. Protect the identity storage directory with restrictive filesystem permissions, and use a dedicated keystore or operating-system-backed secret store rather than relying solely on a general JSON file.

  9. Apply the same corrected installation instructions consistently to SKILL.md, SKILL-EN.md, and SKILL-ZH.md.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The documented storage of issued and received credentials in a predictable local file path creates a credential access risk, especially on shared systems or where filesystem permissions are weak. Verifiable credentials often contain identity attributes or authorization-related claims, so unauthorized read access can leak sensitive data and facilitate profiling, replay, or downstream trust abuse.

Content

Scanner excerpt · SKILL-EN.md (reported line 413)May include surrounding context.

text
~/.openclaw/identity/
├── dids.json          # Stored DID documents
├── credentials.json   # Issued/received credentials
└── keys.json          # Encrypted private keys

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill documents persistent storage of credentials in a predictable local path (~/.openclaw/identity/credentials.json) alongside DID data and encrypted private keys. In an agent environment, predictable storage of sensitive identity artifacts can enable unauthorized local access, credential scraping, or privacy leakage if host permissions, sandboxing, or export behavior are weak.

Content

Scanner excerpt · SKILL-ZH.md (reported line 413)May include surrounding context.

text
~/.openclaw/identity/
├── dids.json          # 存储的 DID 文档
├── credentials.json   # 签发/接收的凭证
└── keys.json          # 加密的私钥

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 413)May include surrounding context.

text
~/.openclaw/identity/
├── dids.json          # Stored DID documents
├── credentials.json   # Issued/received credentials
└── keys.json          # Encrypted private keys

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger conditions are broad enough to activate on generic terms like 'identity' or 'trust', which can cause the skill to engage in unrelated conversations and unnecessarily expose identity-management capabilities. In an agent ecosystem, overbroad routing increases the chance of sensitive operations being invoked in the wrong context, including DID creation, credential handling, or trust evaluation without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill states that keys and identity data are stored locally but does not prominently warn that these artifacts are highly sensitive and may enable impersonation or unauthorized credential issuance if exposed. Because this is a security-focused identity skill dealing with private keys, insufficient warning and guidance materially increase the risk of unsafe deployment and operator misunderstanding.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This duplicate RA2 finding points to the same onboarding pattern that encourages immediate DID creation, resulting in persistent local identity state. In a security-sensitive agent ecosystem, persistence should be intentional and user-approved, not implied by a quick-start flow.

Content

Scanner excerpt · SKILL-ZH.md (reported line 61)May include surrounding context.

identity-trust info

创建你的第一个 DID

identity-trust did create

text

## 🚀 使用方法

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This duplicate RA2 finding points to the same onboarding pattern that encourages immediate DID creation, resulting in persistent local identity state. In a security-sensitive agent ecosystem, persistence should be intentional and user-approved, not implied by a quick-start flow.

Content

Scanner excerpt · SKILL-ZH.md (reported line 61)May include surrounding context.

identity-trust info

创建你的第一个 DID

identity-trust did create

text

## 🚀 使用方法

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger conditions include very broad terms such as “身份” and “信任”, which are likely to overlap with many ordinary conversations unrelated to decentralized identity. In an agent setting, this can cause the skill to activate unexpectedly and steer the system into identity creation, credential handling, or trust-evaluation flows without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation describes local private-key storage, data export capability, and optional network-based DID resolution, but it does not present a clear, centralized warning about the security implications of these features. Users may underestimate the sensitivity of keys, credentials, and exported identity data, increasing the chance of accidental exposure or unsafe deployment choices.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The example workflow for agent identity creation and credential issuance promotes creation of persistent agent identity artifacts and associated credentials, which can establish long-lived session-like state. In contexts where agents should remain stateless or privacy-preserving, this persistence can enable tracking, unintended reuse, or trust decisions based on stale artifacts.

Content

Scanner excerpt · SKILL-ZH.md (reported line 332)May include surrounding context.

bash
# 创建 Agent DID
identity-trust did create --method key

# 签发能力凭证
identity-trust vc issue \

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL-EN.md (reported line 20)May include surrounding context.

md
## 📋 Overview

Identity Trust provides a complete solution for decentralized identity management, enabling AI agents to:
- Create and manage Decentralized Identifiers (DIDs)
- Issue and verify W3C-compliant Verifiable Credentials
- Establish trust relationships between agents
- Manage cryptographic keys securely

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
## 📋 Overview

Identity Trust provides a complete solution for decentralized identity management, enabling AI agents to:
- Create and manage Decentralized Identifiers (DIDs)
- Issue and verify W3C-compliant Verifiable Credentials
- Establish trust relationships between agents
- Manage cryptographic keys securely

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises local key and identity storage but does not prominently warn, before creation/storage actions, that private keys and credentials are sensitive secrets whose compromise can enable impersonation or credential misuse. Users or downstream agents may persist sensitive material by default without understanding the security consequences or local hardening requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger rules are broad enough to activate on common terms like 'identity' and 'trust', which can cause the skill to engage in routine conversations where decentralized identity tooling was not intended. In an agent ecosystem, over-triggering a security-sensitive skill increases the chance of unnecessary DID creation, credential handling, or trust-evaluation actions being invoked without clear user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL-EN.md (reported line 296)May include surrounding context.

md
const storage = new LocalStorage();
await storage.initialize();

// Create a DID
const { did, document, keyPair } = await generateDID('key', {
  keyType: 'Ed25519'
});

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 296)May include surrounding context.

md
const storage = new LocalStorage();
await storage.initialize();

// Create a DID
const { did, document, keyPair } = await generateDID('key', {
  keyType: 'Ed25519'
});

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 适用于所有文件类型。该技能文档从标题、说明到触发条件与操作指引均仅以中文提供,没有提供用户可选择的语言版本,也未说明这是面向特定中文区域或受众的限制,构成潜在的语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.