Back to skill

Security audit

Config Security Scanner

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local OpenClaw configuration scanner; users should keep report output paths inside the workspace.

Install only if you are comfortable allowing the skill to read local OpenClaw configuration files and write audit reports. Run it without elevated privileges, keep --output paths inside the workspace using security_report_*.md names, and do not manually run package_skill.py on shared systems.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/security_scan.py:526
Finding

Unrestricted Report Output Path Allows Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/package_skill.py:16
Finding

Predictable Files in Shared Temporary Directory Permit Symlink Overwrite Attacks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a strong mismatch between the declared purpose of a local static security auditor and the detected behavior of a packaging/release tool that creates tarballs, writes into /tmp/skill-packages, and processes distribution metadata. This kind of deceptive presentation is dangerous because it can hide unexpected file creation and repackaging behavior under the cover of a trusted security tool, making review and permission decisions less accurate.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
| `security_scan.py` | Main security scanner | `python3 security_scan.py [options]` |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/permission-management.md (reported line 369)May include surrounding context.

md
### DON'T
- Grant permanent elevated permissions
- Share elevated access credentials
- Skip approval workflows
- Disable audit logging
- Use emergency mode for routine tasks

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest claims this skill is a security scanner for OpenClaw deployments that audits local configuration files with pure static analysis. The actual behavior here is packaging the skill into a tarball and writing a package manifest to disk, which does not perform any security analysis and materially differs from the declared skill behavior.

Content

No source excerpt is available for this finding.

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · scripts/security_scan.py (reported line 229)May include surrounding context.

python
category="CHANNEL",
                    title="Telegram allows all group messages",
                    description="Telegram channel configured with groupPolicy='allow', permitting messages from any group",
                    impact="Anyone can send messages to your OpenClaw instance, potential for spam, abuse, or prompt injection attacks",
                    remediation="Set groupPolicy='allowlist' or 'deny' and explicitly configure allowedGroups",
                    risk_of_fix="LOW - won't break existing 1:1 chats",
                    rollback="Revert groupPolicy to 'allow'",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill metadata omits any explicit tool-scope restrictions even though detected capabilities include environment access, file read/write, and shell. In a security-scanner skill that claims to be pure static analysis with no subprocess execution, this lack of declared constraints materially weakens containment and increases the risk that the skill can exercise broader capabilities than users expect.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

Example Output:

text
🔴 CRITICAL: Tool execution policy is 'allow'
   Impact: Any tool can run arbitrary commands
   Fix: Set tools.exec.policy="deny" or "allowlist"
   Risk: HIGH - may break existing workflows

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · scripts/security_scan.py (reported line 323)May include surrounding context.

python
**Example Output**:
```
🔴 CRITICAL: Tool execution policy is 'allow'
   Impact: Any tool can run arbitrary commands
   Fix: Set tools.exec.policy="deny" or "allowlist"
   Risk: HIGH - may break existing workflows
```

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · clawhub.json (reported line 58)May include surrounding context.

json
"Add permissions declaration in clawhub.json (fileRead, fileWrite, envRead, network:false, subprocess:false)",
        "Add TLS/SSL configuration check and bind-address-missing warning",
        "CLI wrapper now calls scanner directly instead of via subprocess",
        "Rewrite remediation-playbook.md: config-edit-only fixes, system commands marked [OPERATOR]",
        "Rewrite permission-management.md: remove runnable shell commands, add [OPERATOR] labels",
        "Fix SKILL.md: align example output, troubleshooting paths, and safety warnings with config-only scope",
        "Resolves ClawHub suspicious classification and declaration/behaviour mismatches"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/permission-management.md (reported line 226)May include surrounding context.

md
│
       ▼
┌─────────────────┐     ┌──────────────┐
│ Restricted?     │────►│ Auto-approve │
└──────┬──────────┘     └──────────────┘
       │
       ▼

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/permission-management.md (reported line 370)May include surrounding context.

md
### DON'T
- Grant permanent elevated permissions
- Share elevated access credentials
- Skip approval workflows
- Disable audit logging
- Use emergency mode for routine tasks
- Forget to revoke temporary permissions

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/remediation-playbook.md (reported line 15)May include surrounding context.

md
### Rule 1: Never Brick Remote Deployments

**Before ANY config change:**
1. Create a copy of `~/.openclaw/config.json` (e.g. add a `.backup.<timestamp>` suffix)
2. Confirm you have an alternative way to access the host (SSH, console, secondary channel)
3. Test the restore procedure
4. Schedule a maintenance window

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest presents the skill as a read-only security auditor for local configuration analysis, while this file's top-level documentation explicitly states it packages the skill for distribution and ClawHub publishing. That documentation highlights a materially different intent from the skill's declared operational purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill that performs pure static analysis of local OpenClaw configuration files and emphasizes no command execution or probing. This file instead implements a packaging capability that creates output directories and prepares release artifacts, which is not justified by the stated runtime purpose of auditing configurations.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · scripts/security_scan.py (reported line 243)May include surrounding context.

python
finding = Finding(
                        level="HIGH",
                        category="CHANNEL",
                        title="Telegram allowlist is empty",
                        description="groupPolicy='allowlist' but allowedGroups is empty or not configured",
                        impact="No groups can message the bot, may indicate misconfiguration",
                        remediation="Add group IDs to allowedGroups or change groupPolicy",

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · scripts/security_scan.py (reported line 354)May include surrounding context.

python
level="MEDIUM",
                    category="PERMISSION",
                    title=f"Dangerous tool enabled: {tool}",
                    description=f"Tool '{tool}' can execute arbitrary code",
                    impact="Potential for code execution attacks if tool is compromised",
                    remediation=f"Disable {tool} if not needed, or restrict via allowlist",
                    risk_of_fix="MEDIUM - may break functionality",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a scanner that audits local configuration files and emphasizes pure static analysis, which implies read-only analysis with safe remediation guidance. The code additionally creates or overwrites a report file on disk, introducing filesystem modification behavior not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The time-based context example sets "timezone": "Asia/Shanghai", which imposes a specific locale in natural-language/config guidance. The file does not indicate that this is merely an example tied to a region-specific deployment, nor does it offer user/operator choice of timezone.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The docstrings state that all checks derive from local configuration files only, but the implementation also reads the system hostname using platform.node() and includes it in the generated report. That is a direct contradiction to the documented 'configuration files only' claim, even though it is not a high-risk action.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scanner advertises config-only analysis in its documentation, yet it gathers host metadata outside the configuration files and surfaces it in the report. This is a concrete intent-code divergence because the documented input scope is narrower than the actual implementation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The scanner's stated purpose is auditing local OpenClaw configuration files, but it also inspects process environment state via OPENCLAW_CONFIG. Reading environment variables is a broader capability than simple local file analysis and is not declared in the manifest scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This code performs a file write when an output path is provided, but the only surrounding disclosure is the generic '--output report path' argument help. There is no explicit warning in a comment or user-facing message before the write that running the script will create or overwrite a report file on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.