Back to skill

Security audit

better-skill-creator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its purpose of managing OpenClaw skills, but its backup, rollback, and installer scripts can overwrite or delete broad local data, so it belongs in Review before use.

Use only in a disposable or well-backed-up skill workspace until fixed. Do not run the installer or rollback scripts with elevated privileges, do not roll back from untrusted backup metadata, inspect exact target paths before confirming deletion, and remove symlinks or secrets from skill directories before backup.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rollback.py:17
Finding

Rollback Can Recursively Delete an Arbitrary Metadata-Defined Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup.py:19
Finding

Backup Follows Symlinks and Can Copy Files Outside the Skill Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/proposal.py:99
Finding

Proposal Identifier Path Traversal Allows Unintended JSON File Modification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.py:47
Finding

Installer Reports Migration Success Without Migrating Data Before Recursive Deletion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/config.py:1
Finding

Missing Import Disables the Advertised Modification Security Gate

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill is explicitly designed to modify existing skills according to a generated plan, which is a self-modification capability with direct impact on trusted agent behavior. This is more dangerous in context because the tool also performs backup, rollback, packaging, and version management, giving it broad write access over skill contents and increasing the blast radius of a bad or manipulated change.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
A[User submits optimization requirements] --> B[Generate optimization plan]
B --> C[User confirms the plan]
C --> D[Automatically back up the current version]
D --> E[Modify skills according to the plan]
E --> F[Automatic diff comparison + risk assessment]
F --> G[Automatically run test cases]
G --> H[Generate new version records + CHANGELOG]

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/init_skill.py (reported line 307)May include surrounding context.

python
# Print next steps
    print(f"\n[OK] Skill '{skill_name}' initialized successfully at {skill_dir}")
    print("\nNext steps:")
    print("1. Edit SKILL.md to complete the TODO items and update the description")
    if resources:
        if include_examples:
            print("2. Customize or delete the example files in scripts/, references/, and assets/")

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_package_skill.py (reported line 67)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_package_skill.py (reported line 92)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/test_package_skill.py (reported line 109)May include surrounding context.

python
def test_skips_symlink_to_external_file(self):
        skill_dir = self.create_skill("symlink-file-skill")
        outside = self.temp_dir / "outside-secret.txt"
        outside.write_text("super-secret\n")
        link = skill_dir / "loot.txt"
        out_dir = self.temp_dir / "out"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented rollback feature can overwrite the current skill state, but the description does not warn users about potential data loss or the need to preserve uncommitted changes first. In a tool explicitly designed to modify and manage skills, this omission can lead to accidental destructive actions and unsafe operator assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The installation flow says historical backups and version records will be automatically migrated, but it does not warn that this may import unexpected data, alter local state, or expose prior artifacts the user did not intend to carry forward. Automatic migration of historical data is sensitive because users may not realize what content is being discovered and moved.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The skill describes automatically running test cases after modifying skills, which is an autonomous action that can execute code or scripts derived from the target skill or its environment. In a security-sensitive setting, automatic test execution increases risk because tests may have side effects, run unsafe code, or operate on untrusted content without an explicit execution gate.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
C --> D[Automatically back up the current version]
D --> E[Modify skills according to the plan]
E --> F[Automatic diff comparison + risk assessment]
F --> G[Automatically run test cases]
G --> H[Generate new version records + CHANGELOG]

### 3. View Version List

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language comments and risk labels exclusively in Chinese, including operational guidance such as approval and risk confirmation settings. The file provides no indication that Chinese is optional, user-selected, or required for a justified region-specific context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing docstrings, help text, and console messages entirely in Chinese, including argument descriptions and status/error output. That creates a language/locale constraint in the skill's natural-language behavior without offering an opt-in or documenting that the tool is intended only for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents its description, errors, prompts, and status messages in Chinese, beginning with the docstring and visible output strings. That forces a specific language/locale on all users without offering any opt-in or alternative, which matches the policy-violation criteria for language choice.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/interactive-rollback.py (reported line 80)May include surrounding context.

python
show_diff = input("\n是否查看该版本与当前版本的差异? (y/N): ")
    if show_diff.lower() == 'y':
        diff_script = os.path.join(os.path.dirname(__file__), "diff.py")
        subprocess.run([
            "python", diff_script,
            args.skill_name,
            selected_version["version_id"]

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/interactive-rollback.py (reported line 94)May include surrounding context.

python
# 执行回滚
    rollback_script = os.path.join(os.path.dirname(__file__), "rollback.py")
    subprocess.run([
        "python", rollback_script,
        args.skill_name,
        selected_version["version_id"]

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing docstrings, status messages, generated markdown content, and CLI help text are consistently in Chinese, which effectively imposes a specific language on users. There is no indication that the skill is region-specific or that users can opt into another language, which matches the language/locale policy-violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code contains multiple natural-language docstrings, status messages, and confirmation prompts only in Chinese, including the CLI description and rollback confirmation text. The file does not provide any user opt-in for language selection or indicate that the skill is intentionally limited to a Chinese-speaking context, which conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/rollback.py (reported line 60)May include surrounding context.

python
# 先备份当前版本
    import subprocess
    subprocess.run([
        "python", os.path.join(os.path.dirname(__file__), "backup.py"),
        target_path,
        "--note", f"auto-backup-before-rollback-to-{args.version_id}"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains all user-facing docstrings, status messages, usage text, and confirmation prompts in Chinese only. The file does not offer any language selection or document that the skill is intentionally limited to a Chinese-speaking or region-specific environment, which creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script presents user-facing comments, prompts, and status messages entirely in Chinese, including installation choices and destructive-action notices. That can violate a language/locale policy when the skill does not offer user opt-in or an alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code hard-codes the command description and user-visible output in Chinese, including the argument description and error message. Under the natural-language policy rule, forcing a specific language without user opt-in is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's natural-language interface strings are entirely in Chinese, including the command description and all argument help text. This imposes a specific language on users without any opt-in or indication that the skill is intentionally limited to a Chinese-speaking context, which matches the locale-policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.