Back to skill

Security audit

wger OpenClaw Fitness Skill

Security checks for vulnerabilities and agentic risk

Overview

This wger integration is not deceptive, but it can read and change sensitive fitness data and lacks enough guardrails for account writes and self-hosting.

Review this before installing if you plan to connect a real wger account. Use a limited token, require explicit approval before any create/update action, avoid putting tokens directly in commands, and harden any self-hosted deployment with unique secrets, loopback or VPN-only exposure, HTTPS, and pinned container versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/selfhost.md:3
Finding

Insecure Self-Hosting Defaults Expose Credentials and Sensitive Fitness Data

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/selfhost.md:15
Finding

Mutable Container Image Tag Permits Unreviewed Dependency Changes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tainted flow: 'headers' from os.getenv (line 15, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/create_log.py (reported line 21)May include surrounding context.

python
'workout': workout_id,
        'exercises': exercises  # List of dicts: [{'reps': 10, 'weight': 135, 'exercise': exercise_id}]
    }
    response = requests.post(f'{BASE_URL}workoutlog/', json=data, headers=headers)
    if response.status_code in [200, 201]:
        print(f"Log created: {response.json()}")
    else:

Tainted flow: 'headers' from os.getenv (line 16, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/view_logs.py (reported line 20)May include surrounding context.

python
url = f'{BASE_URL}workoutlog/?limit={limit}&format=json'
    if workout_id:
        url += f'&workout={workout_id}'
    response = requests.get(url, headers=headers)
    if response.status_code == 200:
        data = response.json()
        print(json.dumps(data, indent=2))

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description uses very broad trigger wording such as general fitness/gym/wger queries and multiple action categories, which increases the chance the skill is invoked in situations the user did not clearly intend. Because the skill supports authenticated API writes, overbroad activation can lead to unintended account modifications rather than merely informational responses.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill explicitly transmits user fitness data to an external API and routes analysis through subagents, which is a genuine data egress concern. While external transmission is expected for an API integration skill, the danger is increased by the lack of clear consent, data-minimization guidance, and privacy boundaries around what is sent to third parties or additional agents.

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
# wger Fitness Manager

wger is an open-source fitness tracker with REST API for routines, logs, nutrition, and progress. This skill handles API interactions for seamless integration with OpenClaw (exec/curl for calls, subagents for analysis).

## Setup (One-Time)
- API Base: https://wger.de/api/v2/ (or self-hosted URL).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup text encourages passing an API token in commands and examples without warning about shell history, logs, process inspection, or transcript exposure. Even when an environment variable is shown, the wording normalizes credential handling in command context that may leak secrets in agent logs or operational telemetry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section instructs the agent to perform authenticated POST and PATCH operations that modify workouts, logs, and nutrition data without any warning or requirement for explicit user confirmation. In an agentic environment, that creates a real risk of silent or mistaken state-changing actions against the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file describes bringing up a web service and accessing its API endpoint, but it does not clearly warn users about authentication, default exposure risks, or protecting any personal fitness data the service may hold. Although line L31 suggests securing with Tailscale/VPN, it is phrased as a brief recommendation rather than a user warning about privacy and system integrity implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/create_log.py (reported line 21)May include surrounding context.

python
'workout': workout_id,
        'exercises': exercises  # List of dicts: [{'reps': 10, 'weight': 135, 'exercise': exercise_id}]
    }
    response = requests.post(f'{BASE_URL}workoutlog/', json=data, headers=headers)
    if response.status_code in [200, 201]:
        print(f"Log created: {response.json()}")
    else:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script retrieves workout log data using an API token and prints the full API response to stdout without any minimization, warning, or access control. In shared environments, terminals, logs, shell history workflows, or agent pipelines, this can disclose potentially sensitive personal fitness data to unintended viewers.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The when-to-use section includes broad trigger phrases and automation language like crons/subagents, but it does not define limits for when autonomous actions are appropriate. That ambiguity is risky because the skill can perform external authenticated operations and may be selected for loosely related requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes POST and PATCH endpoints that create or modify user workout and nutrition records, but it does not include any user-facing warning about data-changing behavior. For markdown files, omissions around behaviors that affect user data should be flagged when the description presents those operations without disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.