openclaw-windows-companion

Warn

Audited by Snyk on Jun 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The skill’s runtime path ingests outsider-authored free text via the WebSocket gateway (e.g., GatewayClient.OnMessage / HandleMessage), where the gateway’s notification/result payloads are not authored by the operating user and are read as JSON/text into the agent’s context.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.90). This skill explicitly enables "Node Mode" that lets a remote OpenClaw agent run arbitrary system commands (system.run), control notifications, take screenshots/camera captures, and otherwise control the Windows host — i.e. it directs the agent to perform actions that can modify or compromise the machine's state even if it doesn't explicitly request sudo/root or user creation.

Issues (3)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 14, 2026, 08:47 AM
Issues
3
Security Audit — snyk — openclaw-windows-companion