Back to skill

Security audit

ZugaShield Security Scanner

Security checks for vulnerabilities and agentic risk

Overview

This security scanner is purpose-aligned, but needs review because it installs and runs an unpinned external Python engine that receives scanned OpenClaw traffic.

Review publisher identity and install source carefully before installing. Pin exact npm and PyPI versions, verify the Python scanner package provenance, and run the scanner under a low-privilege, sandboxed account because it can see messages, tool calls, responses, and memory content when enabled.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
src/shield-client.ts:212
Finding

Unpinned External Scanner Executes with Access to Sensitive Agent Traffic

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:40-44, README.md:31-45, src/preflight.ts:53-56, src/shield-client.ts:212-216
Vulnerability Type: Unpinned third-party runtime dependency and inconsistent package provenance
Risk Level: High

Vulnerable Code and Instructions

SKILL.md:40-44:

bash
pip install "zugashield[mcp]"
npm install zugashield-openclaw-plugin
openclaw plugins install ./node_modules/zugashield-openclaw-plugin
openclaw restart

README.md:31-45:

bash
pip install "zugashield[mcp]"
bash
cd your-openclaw-directory
npm install @zugashield/openclaw-plugin
bash
cd extensions
git clone https://github.com/AntonioCiolworking/zugashield-openclaw-plugin zugashield

src/preflight.ts:53-56:

ts
try {
  await exec(pythonExe, ["-c", "import zugashield_mcp"]);
  result.zugashieldMcp = true;

src/shield-client.ts:212-216:

ts
this.transport = new StdioClientTransport({
  command: this.config.mcp.python_executable,
  args: ["-m", "zugashield_mcp.server"],
  env: this._buildChildEnv(),

Technical Analysis

The documented installation commands do not pin exact npm or Python package versions or verify artifact hashes or signatures. The plugin subsequently imports and persistently executes the separately distributed zugashield_mcp Python module.

This external component receives request text, tool names and arguments, response content, and recalled memory through MCP scan calls. Consequently, the component occupies a highly trusted position despite its implementation not being present in the audited project.

Package identity and provenance are also inconsistent. SKILL.md refers to the unscoped zugashield-openclaw-plugin package and the Zuga-luga project, while README.md refers to @zugashield/openclaw-plugin and an AntonioCiolworking repository. These inconsistencies increase the possibility of ...[truncated 2230 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin exact npm and Python package versions rather than using unconstrained installation commands.
  2. Publish and verify cryptographic hashes for Python wheels and npm release artifacts. Use a locked requirements file with hashes for Python dependencies.
  3. Standardize the package scope, repository owner, homepage, and installation instructions across SKILL.md, README.md, and package.json.
  4. Enable package provenance and signed releases, and document how users can verify publisher identity before installation.
  5. Vendor or independently audit the Python scanner implementation because it processes security-sensitive agent traffic and determines enforcement verdicts.
  6. Run the scanner under a dedicated low-privilege account or sandbox with a read-only filesystem, no access to user home directories, resource limits, and a restricted working directory.
  7. Disable outbound network access by default. If threat-feed access is required, permit only explicitly configured HTTPS destinations and validate their certificates and update signatures.
  8. Consider requiring an absolute, administrator-approved Python executable path rather than resolving a generic python command through PATH.
  9. Add automated release checks that reject mismatched repository URLs, package names, unpinned installation examples, and unsigned artifacts.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (87)

Known Vulnerable Dependency: vitest==3.2.4 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

vitest 3.2.4 is a real vulnerable version with arbitrary file read and possible code execution exposure when the UI server is listening, plus the @vitest/mocker traversal issue. Because this is a dev/test dependency, the main risk is to development or CI environments rather than end-user runtime, but impact can be severe if those environments are exposed or process untrusted test artifacts.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vitest==3.2.4 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest permits/installes a Vitest 3.x release flagged as vulnerable, and the cited advisories include arbitrary file read and possible code execution in test/UI-related components. Even though Vitest is a devDependency, it can materially affect developers, CI runners, and release pipelines if tests or the Vitest UI are used, making this a real supply-chain and build-environment risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Describing test-runner or non-enforcing configuration as a comprehensive multi-channel defense platform creates a false security boundary. Because this skill is explicitly positioned as a security control, inaccurate claims are more dangerous than in ordinary utility plugins.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @hono/node-server==1.19.9 — 3 advisory(ies): CVE-2026-39406 (@hono/node-server: Middleware bypass via repeated slashes in serveStatic); GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode); CVE-2026-29087 (@hono/node-server has authorization bypass for protected static paths via encode)

High
Category
Supply Chain
Confidence
95% confidence
Finding

@hono/node-server 1.19.9 is pinned in the lockfile and is reported with multiple high-severity static file handling flaws, including path traversal and authorization/middleware bypass conditions. Even though this is a dependency manifest rather than executable code, the skill advertises security-scanning functionality and pulls in a server stack transitively through the MCP SDK, so shipping known vulnerable server components increases risk if any hosted endpoint or static serving path is exposed.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: express-rate-limit==8.2.1 — 1 advisory(ies): CVE-2026-30827 (express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting o)

High
Category
Supply Chain
Confidence
91% confidence
Finding

express-rate-limit 8.2.1 is flagged for bypass via IPv4-mapped IPv6 handling, which can let attackers evade per-client throttling. In a network-facing plugin or MCP service, this can materially weaken abuse protections and facilitate brute force, scraping, or request-flooding against downstream functionality.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
88% confidence
Finding

fast-uri 3.1.0 is present and the advisory set includes host confusion and SSRF-relevant parsing flaws. Because this skill claims to be a security scanner across multiple channels, any component that validates or canonicalizes attacker-controlled URLs incorrectly could directly undermine SSRF protections or host allow/deny logic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: hono==4.11.9 — 16 advisory(ies): CVE-2026-56762 (Hono missing validation of cookie name on write path in setCookie()); CVE-2026-47676 (Hono: app.mount() strips mount prefix using undecoded path, causing incorrect ro); CVE-2026-47675 (Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie) +13 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

hono 4.11.9 is explicitly pinned and is reported with numerous advisories affecting cookies, routing, and related request handling. Given the plugin's security-sensitive branding and likely network-facing integration path through the MCP SDK, widespread framework-level flaws increase the chance of bypasses, incorrect routing, or unsafe header/cookie handling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.0.1 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
84% confidence
Finding

ip-address 10.0.1 is a real vulnerable version with reported parsing ambiguity and HTML/XSS issues. In a tool claiming SSRF and network-security protections, incorrect IP normalization is especially risky because attackers can abuse parser discrepancies to bypass private-address checks or host restrictions.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
80% confidence
Finding

nanoid 3.3.11 is included as a dev dependency through tooling and the advisories center on edge-case infinite loops or integer handling. This is likely less relevant to production runtime, but if build tooling or developer services accept attacker-controlled size parameters, it could still produce denial of service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: path-to-regexp==8.3.0 — 2 advisory(ies): CVE-2026-4923 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple w); CVE-2026-4926 (path-to-regexp vulnerable to Denial of Service via sequential optional groups)

High
Category
Supply Chain
Confidence
90% confidence
Finding

path-to-regexp 8.3.0 is flagged for ReDoS/DoS conditions in route pattern processing. Since this dependency sits in the HTTP routing stack, maliciously crafted paths may trigger excessive computation and degrade availability for any exposed service endpoint.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==4.0.3 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
81% confidence
Finding

picomatch 4.0.3 is present in development tooling and carries matching-bypass and ReDoS concerns. This is most dangerous where untrusted glob patterns are accepted, which is more likely in tooling, test, or dev-server scenarios than in the core runtime of the skill.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.6 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
83% confidence
Finding

postcss 8.5.6 is a real vulnerable version with advisories including arbitrary file read and XSS vectors, but it is a dev-toolchain dependency here. Risk is lower for production execution, yet still meaningful if build pipelines, preview servers, or developer tooling process attacker-influenced CSS or source map inputs.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: rollup==4.57.1 — 1 advisory(ies): CVE-2026-27606 (Rollup 4 has Arbitrary File Write via Path Traversal)

High
Category
Supply Chain
Confidence
80% confidence
Finding

rollup 4.57.1 is a vulnerable dev/build dependency with an arbitrary file write path traversal issue. While typically not exploitable in production runtime, compromise of build or CI contexts can still be serious because it may permit overwriting files during bundling workflows.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vite==7.3.1 — 5 advisory(ies): CVE-2026-39365 (Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling); CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-39363 (Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket) +2 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

vite 7.3.1 is present with multiple high-severity dev-server file read and path traversal issues. These are especially relevant if maintainers run exposed preview/dev services or process untrusted project content, though they are less likely to affect the packaged skill at runtime.

Content

No source excerpt is available for this finding.

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · test/hooks.test.ts (reported line 33)May include surrounding context.

ts
category: "prompt_injection",
        level: "critical",
        description: "Instruction override detected",
        evidence: "ignore previous instructions",
        confidence: 0.95,
        signature_id: "PI-001",
      },

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/preflight.ts:31