openclaw-relay

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/openclaw_relay.py constructs and executes shell commands locally and on remote hosts using subprocess.run. Remote commands are wrapped in bash -lc and passed through SSH.
  • [REMOTE_CODE_EXECUTION]: The skill enables executing Node.js applications and shell commands on remote systems via SSH. While configured with a default host associated with the author, the --host parameter allows the agent to target any reachable SSH server.
  • [DYNAMIC_EXECUTION]: The run_acpx and run_openclaw functions in scripts/openclaw_relay.py dynamically assemble shell functions and complex command strings at runtime for execution on remote machines.
  • [INDIRECT_PROMPT_INJECTION]: The publish and ask commands relay content between different agent sessions, creating a vulnerability where untrusted data from one session is processed as a prompt in another.
  • Ingestion points: Content provided via the --message, --text, or --text-file arguments in scripts/openclaw_relay.py.
  • Boundary markers: Relayed text is interpolated into a prompt template in build_publish_prompt that provides natural language instructions but lacks robust structural separation or sanitization directives.
  • Capability inventory: The skill possesses extensive capabilities through run_local and run_ssh, which execute shell commands.
  • Sanitization: Relayed content is not filtered, escaped, or validated before being included in the prompt for the target session.
  • [DATA_EXFILTRATION]: The show and status commands retrieve internal session state, including agent message history and thinking blocks, which could expose sensitive information when relayed between sessions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — openclaw-relay