Back to skill

Security audit

报错回顾 - 自动分析并修复工具报错

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear error-review purpose, but it tells the agent to read detailed session tool history and automatically modify persistent agent guidance and skills without confirmation.

Install only if you are comfortable with a skill that can inspect detailed current-session tool failures and automatically write to user skill files and TOOLS.md. Prefer revising it to show a proposed diff, redact sensitive details, restrict exact target paths, and require explicit approval before any persistent change.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:79
Finding

Overbroad Collection of Sensitive Session History

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:101
Finding

Unconfirmed Persistent Memory and Skill Modification Enables Durable Instruction Poisoning

Content
View full analysis
100),提示用户手动清理 5. 用 `edit` 工具做文本替换(如遇复杂引号嵌套,分多次 `edit` 完成,每次匹配一小段) ### Step 5:修改(直接执行) 无需用户确认,直接执行修改。 ``` ### Technical Analysis The Skill directs the agent to convert session-derived conclusions into persistent content in `~/.openclaw/workspace/TOOLS.md` and to modify matching `SKILL.md` files. It explicitly requires these changes to be performed without user confirmation. Error messages and surrounding tool context are untrusted inputs. They may originate from external services, files, commands, or user-controlled parameters. Automatically interpreting those inputs as durable operational guidance creates a memory-poisoning boundary: misleading or attacker-influenced errors can be generalized into rules that affect future sessions. The path search is also based on a Skill name and may return an unintended matching file. Although the instructions exclude one system directory, they do not establish a precise allowlist, verify the selected Skill's identity, constrain the permitted changes, create a backup, or require review of a proposed diff. ### Attack Path 1. An attacker or untrusted external resource influences a tool error or its surrounding context. 2. The user invokes the error-review Skill. 3. The Skill reads the affected error and classifies it as a missing environment rule, model mistake, or defective Skill ...[truncated 1235 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to 'directly execute modifications' without user confirmation is a strong unsafe-action pattern because it permits persistent state changes from a conversational trigger alone. In practice, this can silently rewrite documentation or skills, propagating mistakes or attacker-influenced content into future sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly gathers all current-session tool errors, including prior tool-call arguments and error contents, then persists summaries into TOOLS.md. Tool arguments and error messages often contain secrets, internal paths, tokens, or sensitive operational context; retaining them without minimization or consent creates a data exposure and long-term privacy risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The execution flow and report template instruct the agent to surface and store error-derived information but do not require any redaction or sensitivity filtering. Even summarized entries can leak confidential filenames, environment details, credentials embedded in errors, or operational mistakes back to the user and into persistent files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s stated purpose is to review session errors, but it authorizes persistent modification of SKILL.md and TOOLS.md based on inferred root causes, without any approval gate. This creates an integrity risk: transient tool failures, model misclassification, or adversarially induced errors could cause durable changes to operational documentation that affect future behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes filesystem discovery of skills under ~/.openclaw/skills and maintenance of persistent documentation, which exceeds what is necessary for a simple 'error review' capability. Broad discovery plus write behavior expands attack surface and can be abused to alter unrelated skills or environment documentation based on untrusted session content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires the final reply to be presented in Chinese, but the file does not indicate that the user can choose another language or opt in to this locale constraint. This is a natural-language policy issue because it forces a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.