Back to skill

Security audit

1panel-skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it exposes broad authenticated 1Panel management access beyond its read-oriented description.

Install only after deciding that this agent should have trusted operator access to your 1Panel instance. Use a dedicated least-privilege API key, restrict the 1Panel API allowlist to known runtime IPs or a VPN, use HTTPS with certificate validation, avoid ONEPANEL_SKIP_TLS_VERIFY, and treat raw request/sign usage plus logs/config/certificate output as sensitive.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/cli.ts:130
Finding

Generic Signed Request Command Bypasses the Intended Read-Only Security Boundary

Content
View full analysis

Vulnerability Details

File Location: scripts/cli.ts:36-40, scripts/cli.ts:130-153; related security boundary in SKILL.md:23-29
Vulnerability Type: Arbitrary authenticated API request / read-only policy bypass
Risk Level: High
Category: T05: Unauthorized Access and Privilege Escalation

Vulnerable Code:

ts
case 'request':
  await handleRequest(rest);
  return;
ts
async function handleRequest(args: string[]): Promise<void> {
  const [method, path, ...rest] = args;
  if (!method || !path) {
    throw new Error('Usage: request <METHOD> <PATH> [--body-json JSON] [--query-json JSON] [--node NODE]');
  }

  const { flags } = parseArgs(rest);
  const client = createClient(flags);
  const body = parseOptionalJson(flags['body-json']);
  const query = parseOptionalJson(flags['query-json']);
  const operateNode = readOptionalString(flags.node);

  const response = await client.request({
    method: method.toUpperCase() as 'GET' | 'POST' | 'PUT' | 'PATCH' | 'DELETE',
    path,
    body,
    query: isRecord(query) ? (query as Record<string, string | number | boolean | null | undefined>) : undefined,
    operateNode,
  });

  printResponse(response.status, response.data, response.rawBody);
}

Technical Analysis

The Skill documentation presents currently implemented operations as query-oriented and instructs the agent not to fabricate write workflows. Mutation endpoints are described as reserved for future controlled expansion. However, the request CLI command accepts a caller-provided HTTP method, API path, request body, query parameters, and node selection, and then signs the request using the configured 1Panel API key.

No endpoint allowlist, read-only method restriction, mutation confirmation mechanism, or authorization policy is applied. The TypeScript assertion:

ts
method.toUpperCase() as 'GET' | 'POST' | 'PUT' | 'PATCH
...[truncated 1728 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the generic request command from the agent-facing CLI.
  2. If raw requests are required for development, move them to a separate administrative executable that is not exposed as a Skill action.
  3. Enforce an explicit allowlist of approved API paths and methods. Match normalized paths rather than raw caller strings.
  4. Restrict the current agent-facing command to approved read operations. Do not assume that POST is safe merely because some search endpoints use it; authorize method-and-path pairs together.
  5. Validate HTTP methods at runtime instead of relying on a TypeScript assertion.
  6. Require explicit human confirmation and separate credentials before permitting future mutations.
  7. Use a dedicated least-privilege API key whose server-side permissions prevent mutation even if client-side controls are bypassed.
  8. Add security tests proving that unregistered endpoints and reserved mutation paths are rejected.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/client.ts:50
Finding

Plaintext HTTP, Optional TLS Verification Bypass, and Broad API Exposure Enable Credential Interception

Content
View full analysis

Vulnerability Details

File Location: scripts/client.ts:50-64, README.md:91-94, README.md:112-115, SKILL.md:14-18
Vulnerability Type: Insecure management transport and unsafe deployment guidance
Risk Level: High
Category: T09: Insecure Skill Coding Practices

Vulnerable Code:

ts
const url = this.buildUrl(options.path, options.query, options.operateNode);
const body = options.body === undefined ? undefined : JSON.stringify(options.body);
const headers = this.buildHeaders(body);
const isHttps = url.protocol === 'https:';
const transport = isHttps ? https : http;

return new Promise<OnePanelResponse<T>>((resolve, reject) => {
  const request = transport.request(
    {
      protocol: url.protocol,
      hostname: url.hostname,
      port: url.port || (isHttps ? 443 : 80),
      path: `${url.pathname}${url.search}`,
      method: options.method,
      headers,
      rejectUnauthorized: !this.skipTlsVerify,
      timeout: this.timeoutMs,
    },

The deployment documentation additionally recommends or demonstrates insecure configurations:

md
5. Add your client IP or allow all for testing:
   - IPv4: `0.0.0.0/0`
   - IPv6: `::/0`
bash
export ONEPANEL_BASE_URL="http://192.168.1.2:9999"
export ONEPANEL_API_KEY="YOUR_1PANEL_API_KEY"
export ONEPANEL_TIMEOUT_MS="30000"
export ONEPANEL_SKIP_TLS_VERIFY="false"

Technical Analysis

The client selects the plaintext http transport whenever the configured base URL uses the http: scheme. It does not reject insecure schemes for remote management endpoints. For HTTPS connections, ONEPANEL_SKIP_TLS_VERIFY can disable certificate validation through rejectUnauthorized: false.

The authentication scheme sends a timestamp and an MD5-derived token with each request. Although the raw API key is not directly transmitted, transport confidentiality and server authentication remain ne ...[truncated 1899 chars]

Remediation
View remediation

Remediation Suggestions

  1. Reject non-HTTPS base URLs by default.
  2. If plaintext transport is necessary for development, permit it only for loopback addresses under an explicit development-only option.
  3. Remove ONEPANEL_SKIP_TLS_VERIFY from normal agent-facing operation, or restrict it to a clearly isolated development build.
  4. Support a custom trusted certificate authority instead of disabling certificate verification.
  5. Replace documentation examples with an https:// endpoint and explain proper certificate deployment.
  6. Remove the recommendation to use 0.0.0.0/0 and ::/0. Require a narrow allowlist containing only the runtime's known outbound addresses.
  7. Add firewall or VPN restrictions around the 1Panel management endpoint.
  8. Use a least-privilege API key and rotate it immediately after suspected interception.
  9. Where server compatibility permits, use a modern message-authentication construction with nonce and request-body binding to improve replay resistance.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/client.ts:67
Finding

Unbounded Response Buffering Permits Memory-Exhaustion Denial of Service

Content
View full analysis

Vulnerability Details

File Location: scripts/client.ts:67-75; affected log action example at scripts/modules/containers.ts:91-110
Vulnerability Type: Unbounded memory allocation while processing HTTP responses
Risk Level: Medium
Category: T09: Insecure Skill Coding Practices

Vulnerable Code:

ts
(response) => {
  const chunks: Buffer[] = [];
  response.on('data', (chunk) => {
    chunks.push(Buffer.isBuffer(chunk) ? chunk : Buffer.from(chunk));
  });
  response.on('end', () => {
    const rawBody = Buffer.concat(chunks).toString('utf8');
    const normalizedHeaders = normalizeHeaders(response.headers);
    const data = parseResponseBody<T>(rawBody, normalizedHeaders['content-type']);

The container log action can request a continuing response:

ts
return client.request<string>({
  method: 'GET',
  path: '/api/v2/containers/search/log',
  operateNode: input.operateNode,
  query: {
    container: input.container,
    compose: input.compose,
    since: input.since,
    follow: input.follow ?? false,
    tail: input.tail ?? '200',
    timestamp: input.timestamp ?? false,
  },
});

Technical Analysis

Every response chunk is retained in the chunks array until the server ends the response. The complete body is then copied again by Buffer.concat and converted into a UTF-8 string. This creates multiple in-memory representations and provides no maximum response size.

The problem is especially relevant to container log retrieval, which is described as streaming and supports a caller-controlled follow option. If follow is enabled, the response may remain open and continually append data. The configured request timeout does not reliably bound an actively transmitting response because data can continue arriving while the connection remains active.

A malicious or compromised server can exploit the same weakness through any end ...[truncated 1127 chars]

Remediation
View remediation

Remediation Suggestions

  1. Track the cumulative number of response bytes and abort the request when a configured maximum is exceeded.
  2. Set conservative endpoint-specific limits, with stricter defaults for agent output.
  3. Implement genuine streaming for log endpoints instead of collecting the complete response in memory.
  4. Apply backpressure and bounded queues when forwarding streamed output.
  5. Limit or disable follow: true for agent-triggered requests. If enabled, enforce a maximum duration and byte count.
  6. Validate and cap caller-controlled tail, pageSize, and similar volume parameters.
  7. Avoid retaining both the complete Buffer and string representation when only one is required.
  8. Add tests using oversized and never-ending responses to verify that the client terminates safely.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (34)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The setup guidance recommends allowing all IPs for testing using 0.0.0.0/0 and ::/0, which materially weakens the protection boundary around a management API. For a panel that exposes infrastructure status and potentially administrative operations, broad IP allowlisting can enable unauthorized remote access if the API key is leaked or otherwise misused.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is described as query/inspection-oriented, but the reported CLI behavior supports arbitrary authenticated API requests, including attacker-chosen HTTP methods and paths. In an agent setting, that mismatch is dangerous because callers or prompt injections may route the agent into performing write, delete, restart, or other privileged operations under the guise of a read-only skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is described as query/inspection-oriented, but the reported CLI behavior supports arbitrary authenticated API requests, including attacker-chosen HTTP methods and paths. In an agent setting, that mismatch is dangerous because callers or prompt injections may route the agent into performing write, delete, restart, or other privileged operations under the guise of a read-only skill.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- [scripts/client.ts](scripts/client.ts)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
- [scripts/cli.ts](scripts/cli.ts)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
- The repository can ship prebuilt runtime files under `dist/`, so normal use should call `node dist/scripts/cli.js ...` directly without rebuilding first.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request command allows callers to send arbitrary authenticated HTTP methods and paths to the 1Panel API, bypassing the skill’s declared query/inspection scope and any module-level allowlist. In an agent/runtime context, this expands capability from constrained read-oriented actions to potentially destructive administrative operations, including writes, deletes, or access to undocumented endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises broad access to logs, configs, certificates, process data, and system inspection surfaces without any warning that these operations may expose secrets, tokens, personal data, or infrastructure details. In an agent skill context, normalizing these capabilities as routine inspection increases the chance of oversharing sensitive operational data to users, agents, or logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to place the 1Panel API key in an environment variable but does not include dedicated secret-handling guidance. In practice, environment variables are often exposed through shell history, process listings in some environments, CI logs, crash dumps, or inherited subprocesses, making accidental credential disclosure more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README explicitly recommends allowing the 1Panel API from 0.0.0.0/0 and ::/0 during testing, which effectively exposes a privileged management API to the entire internet if paired with a reachable instance. Even for a read-focused skill, the API key grants sensitive operational visibility and may also enable broader actions depending on server-side permissions or future expansion, making this an unsafe hardening regression in deployment guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation advises opening the 1Panel API whitelist to the whole internet without a strong warning, which normalizes an insecure configuration for operators who may copy-paste setup steps. Because this skill interfaces with infrastructure management endpoints and uses API-key-based authentication, broad network exposure materially increases the chance of unauthorized access, brute-force discovery, or abuse if keys leak.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 103)May include surrounding context.

推荐本地安装方式:

bash
mkdir -p ~/.openclaw/skills
ln -s /path/to/1Panel-skills ~/.openclaw/skills/1panel-skills

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.zh-CN.md (reported line 103)May include surrounding context.

推荐本地安装方式:

bash
mkdir -p ~/.openclaw/skills
ln -s /path/to/1Panel-skills ~/.openclaw/skills/1panel-skills

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares environment-variable requirements for sensitive connection material such as ONEPANEL_API_KEY and runtime TLS behavior, but it does not declare any explicit tool scope or permission boundary. That creates an under-specified trust boundary where an agent runtime may expose secrets or enable network-capable execution without clear policy controls, increasing the chance of unintended secret access or misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI exposes a generic request command that allows callers to send arbitrary authenticated API requests to any path, which bypasses the skill's stated scoped, inspection-oriented interface. In an agent/runtime context, this expands authority from curated read-oriented actions to effectively broad API access, increasing the chance of unintended or unsafe operations if the underlying 1Panel API includes mutating endpoints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
63% confidence
Finding

The manifest emphasizes query and inspection interfaces and says mutation definitions are reserved for later expansion. This CLI blindly executes any registered action from imported modules, so if modules include mutating actions, the CLI already enables them despite the manifest's narrower description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Printing authentication headers to stdout can leak sensitive derived credentials into shell history, logs, CI output, agent transcripts, or other observability pipelines. In an agent-integrated environment, these outputs may be captured and reused by other tools or users during the token validity period.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

handleRequest accepts arbitrary HTTP method, path, body, and query data and sends them with the configured 1Panel credentials, functioning as a general-purpose authenticated API proxy. In the context of a scoped operations skill, this defeats least privilege and can be used to reach sensitive or state-changing endpoints outside the reviewed action surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs outbound network requests and attaches derived authentication headers based on the API key, but there is no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that the skill sends data to a remote 1Panel service. For code files, outbound transmission of user or system data should have some visible disclosure unless clearly documented as the skill's stated purpose, which is not evident in this file alone.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module is described and implemented as a read-oriented node-inspection skill, but its exported metadata also advertises a reserved mutation for license binding. Even if not currently executable through the action list, embedding a privileged state-changing endpoint in the module broadens the declared capability surface and can enable accidental future exposure, misuse by tooling that introspects metadata, or privilege creep inconsistent with least privilege.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The reserved capability targets license binding, which is unrelated to the stated purpose of node inspection and status reads. This mismatch increases risk because operators and automated systems may trust the module as observational only, while hidden or future-enabled metadata points to a sensitive administrative function that could alter licensing or node entitlement state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The sign command generates valid authentication headers from the configured API key and prints them for standalone reuse, effectively turning the skill into a credential-derived token minting utility. This broadens access beyond intended in-skill execution and can facilitate unauthorized or unmonitored use of the remote administrative API by other tools or prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The request command sends user-supplied method, path, query, body, and optional node data to a remote service via client.request, but this command path contains no confirmation, warning, or user-facing disclosure about transmitting data or invoking potentially destructive API operations. The help text also presents request as a generic capability without cautioning that it may modify remote system state depending on the HTTP method and endpoint used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The run command loads input, creates a client, and invokes action.execute(client, finalInput) against the remote OnePanel service, but there is no user-facing disclosure here about network access or that some actions may be state-changing. Because the action behavior is dynamic by module/action, users are not warned at this callsite before a potentially impactful operation is performed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs outbound network requests and may send query parameters and JSON request bodies to a remote server, but there is no confirmation prompt, user-facing logging, or explanatory comment/docstring in this file disclosing that behavior. Because network transmission can expose user or system data, the lack of any visible warning meets the missing-user-warning criteria for code files.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/scripts/cli.js:153

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/scripts/client.js:19

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/cli.ts:196

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/client.ts:32