openclaw-relay
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/openclaw_relay.pyconstructs and executes shell commands locally and on remote hosts usingsubprocess.run. Remote commands are wrapped inbash -lcand passed through SSH. - [REMOTE_CODE_EXECUTION]: The skill enables executing Node.js applications and shell commands on remote systems via SSH. While configured with a default host associated with the author, the
--hostparameter allows the agent to target any reachable SSH server. - [DYNAMIC_EXECUTION]: The
run_acpxandrun_openclawfunctions inscripts/openclaw_relay.pydynamically assemble shell functions and complex command strings at runtime for execution on remote machines. - [INDIRECT_PROMPT_INJECTION]: The
publishandaskcommands relay content between different agent sessions, creating a vulnerability where untrusted data from one session is processed as a prompt in another. - Ingestion points: Content provided via the
--message,--text, or--text-filearguments inscripts/openclaw_relay.py. - Boundary markers: Relayed text is interpolated into a prompt template in
build_publish_promptthat provides natural language instructions but lacks robust structural separation or sanitization directives. - Capability inventory: The skill possesses extensive capabilities through
run_localandrun_ssh, which execute shell commands. - Sanitization: Relayed content is not filtered, escaped, or validated before being included in the prompt for the target session.
- [DATA_EXFILTRATION]: The
showandstatuscommands retrieve internal session state, including agent message history and thinking blocks, which could expose sensitive information when relayed between sessions.
Recommendations
- AI detected serious security threats
Audit Metadata