Back to skill

Security audit

Hivebrite By Altf1be

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Hivebrite admin CLI, but it needs review because it handles powerful admin credentials and live community actions without enough safeguards around secret destinations and token storage.

Install only if you are authorized to administer the target Hivebrite tenant. Use least-privilege or short-lived credentials where possible, verify HIVEBRITE_BASE_URL carefully, prefer HTTPS tenant URLs, protect or avoid .env files, and clear the OAuth cache if credentials change. Treat create/update/delete/send commands as live production actions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hivebrite.mjs:82
Finding

Administrative credentials and bearer tokens can be transmitted to an unvalidated network destination

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hivebrite.mjs:45
Finding

OAuth access and refresh tokens are cached without explicit restrictive permissions or tenant binding

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/hivebrite.mjs (reported line 23)May include surrounding context.

js
import { config } from 'dotenv';
import { Command } from 'commander';

// ── Load .env ────────────────────────────────────────────────────────────────

config();

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises network access and use of environment-based secrets but does not declare an explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, this weakens user visibility and policy enforcement, making it easier for a high-impact admin skill to access secrets and external APIs without clear consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exposes broad administrative, financial, and destructive operations across a live community platform, including deleting users, changing memberships, sending email campaigns, and modifying payment-related records, but it lacks an upfront warning about operating on production data. This increases the chance of accidental misuse by users or agents and can cause irreversible business and privacy impact.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The setup guidance explicitly suggests storing admin credentials or bearer tokens in a local .env file, which creates session persistence on disk and increases the chance of compromise through accidental commits, local disclosure, backups, or multi-user host access. Given this skill targets an administrative API, stolen credentials could enable broad unauthorized actions and data access.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

Setup

  1. Obtain API credentials from your Hivebrite admin panel (Settings > Integrations or API).
  2. Set environment variables (or create .env in {baseDir}):
text
# Required — your Hivebrite instance URL

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation instructs users to place highly sensitive credentials in environment variables or a local .env file and later notes token caching, but it does not warn about local secret exposure, file permissions, shell history leakage, or accidental commit risk. For an admin API skill, these secrets can grant broad access to user data and destructive operations if exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code posts sensitive credentials, including client secret and potentially the admin email/password grant, to a remote endpoint. While the file has technical comments about OAuth, it does not provide any explicit user-facing warning, confirmation, or disclosure that running the CLI will transmit stored credentials to the Hivebrite server.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill writes access and refresh tokens to a predictable path under the user's home directory without setting restrictive file permissions or clearly disclosing persistent credential storage. On multi-user systems, shared environments, or lax umask settings, this can expose reusable admin tokens and enable unauthorized API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command sends an emailing campaign immediately with no confirmation gate, dry-run mode, or prominent warning, even though this is an externally visible bulk action from an admin account. Accidental invocation could trigger unwanted mass communication, reputational harm, and potential compliance issues.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 33)May include surrounding context.

json
"url": "https://github.com/ALT-F1-OpenClaw/openclaw-skill-hivebrite-by-altf1be.git"
  },
  "dependencies": {
    "commander": "^12.0.0",
    "dotenv": "^16.0.0"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 34)May include surrounding context.

json
},
  "dependencies": {
    "commander": "^12.0.0",
    "dotenv": "^16.0.0"
  },
  "engines": {
    "node": ">=18.0.0"

Static analysis

Detected: suspicious.env_credential_access, suspicious.potential_exfiltration

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/hivebrite.mjs:35

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/hivebrite.mjs:67