Back to plugin

Security audit

Websidian

Security checks for vulnerabilities and agentic risk

Overview

The plugin’s sensitive behavior is disclosed and matches its purpose: it makes configured Markdown vaults visible in OpenClaw and guards risky note writes.

Install only if you want OpenClaw memory or configured vault folders readable through the authenticated Websidian UI. Keep vault paths scoped to content folders, leave editing disabled unless needed, and review any approval prompt before allowing instruction-file changes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/websidian/SKILL.md (reported line 59)May include surrounding context.

md
Never create or edit agent instruction files (`SKILL.md`, `SOUL.md`, `AGENTS.md`, `MEMORY.md`, `USER.md`,

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/supervisor.js:166
Evidence
const child = spawn(cmd, args, { cwd, env, shell, windowsHide: true, stdio: ['ignore', logFd ?? 'ignore', logFd ?? 'ignore'] });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
runtime/src/fetch-skills.js:13
Evidence
const git = (args, cwd) => spawnSync('git', args, { cwd, stdio: 'inherit', windowsHide: true });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
runtime/src/hooks.js:23
Evidence
execFile(file, args, { cwd, timeout: timeoutMs, windowsHide: true, maxBuffer: 4 * 1024 * 1024 }, (err, stdout, stderr) => {

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
lib/proxy.js:77
Evidence
export function expectedCredential(cfg, ui, env = process.env) {

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
lib/supervisor.js:293
Evidence
const env = { ...process.env };