openclaw-tool-executor

Warn

Audited by Snyk on Jun 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). High: the skill’s runtime calls Scalekit Connect APIs (e.g., --get-tool and --execute-tool), and the returned tool metadata/results are printed as JSON/text; if the agent framework feeds those printed strings into the LLM context, they can include outsider-authored content (e.g., provider data or error messages) via the tool_exec.py --get-tool / --execute-tool response bodies.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 05:43 PM
Issues
1
Security Audit — snyk — openclaw-tool-executor