Back to skill

Security audit

Moltguard 6.8.16

Security checks for vulnerabilities and agentic risk

Overview

MoltGuard appears purpose-aligned as a security plugin, but it asks users to install unaudited external code that can process sensitive agent data and store API credentials with limited scoping details.

Review this before installing. It may send sensitive prompt, command, file-derived, PII, or secret-related security data to a Core service, creates and stores an API key under the user's OpenClaw credentials directory, and installs external plugin code that was not included in this artifact review. Prefer a pinned, verified plugin version, confirm the Core endpoint you trust, and protect or rotate the stored API key as you would any credential.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:82
Finding

External Security Processing and Credential Storage Lack Documented Data-Minimization Safeguards

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The onboarding flow explicitly states that credentials are saved under ~/.openclaw/credentials/moltguard/ and the claim flow exposes an Agent ID and API Key, but the skill provides no warning about local secret storage, file permission expectations, shared-machine risk, or the sensitivity of account-linking tokens. In a security-focused skill, omission of these warnings is dangerous because users may disclose or leave credentials accessible to other local users or processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The enterprise enrollment instructions tell the user to run a local script with a custom Core URL, which changes the service endpoint and therefore trust boundary/network destination, but do not warn about the security implications of redirecting telemetry or enforcement to another server. This is especially risky in a security product because a misconfigured or malicious endpoint could capture data, alter protections, or weaken detection coverage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown tells the user to run an uninstall script and notes that it removes configuration, plugin files, and credentials, but it does not prominently warn that this is a destructive local operation. For markdown guidance, actions that delete files or credentials should include a clear caution so users understand the impact before proceeding.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.