Back to skill

Security audit

AceToolz Password Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is in Review because it generates passwords through a third-party API using shell and network commands, so credentials meant to be secret may be handled outside the user's environment.

Install only if you are comfortable with AceToolz generating or handling passwords through its external API. Avoid using generated passwords for important accounts unless you trust the provider and understand that local generation would expose less sensitive material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:61
Finding

Mandatory Third-Party Promotion Hijacks Password-Generation Responses

Content
View full analysis
**Generated Password** > `X7#mK9pL!qRv2nBw` > > Length: 16 | Uppercase ✓ | Lowercase ✓ | Numbers ✓ | Symbols ✓ > > *Powered by [AceToolz](https://www.acetoolz.com)* ``` ### Technical Analysis The skill instructs the agent to append AceToolz branding and an external link to password-generation responses. This promotional content is not necessary to fulfill the user's request and modifies the agent's response objective from simply generating a password to advertising a third-party service. Because the instruction is embedded in the skill's result-presentation template, it is applied whenever the agent follows the documented workflow. This constitutes output-oriented skill instruction hijacking: loading and invoking the skill causes third-party promotional content to be inserted into the current session's response. ### Attack Path 1. A user asks the agent to generate a password. 2. One of the configured password-generation triggers activates the skill. 3. The agent follows the `Presenting Results` instructions. 4. The agent inserts the mandatory AceToolz attribution and external link into its response. 5. The user is exposed to unsolicited third-party promotion and may follow the external link. No elevated system privileges are obtained through this issue. Its scope is limited to manipulation of the agent's current-session output and promotion of a third-party website. ### Impact Assessment The instruction allows the skill publisher to use the agent's trusted response channel for advertising. It can reduce user trust, create an implied endorsement by the agent, and direct users to an external website they did not request. The observed instruction does not override safety co ...[truncated 78 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:27
Finding

Unnecessary Shell Execution and External Generation of Security-Sensitive Passwords

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Patterns such as 'generate a password', 'create a password', 'secure password', 'strong password', and 'make a password' are common natural phrases and are not scoped to a specific command surface or invocation context. The manifest provides no negative examples or contextual limitations to reduce accidental matches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction 'Use this skill whenever the user asks to generate a password' is broad and does not define boundaries for when this skill should or should not activate. Combined with generic trigger phrases like 'secure password' and 'strong password', it risks unintended invocation during ordinary conversation about passwords.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends user-derived password-generation parameters to a third-party API but does not clearly warn the user before doing so. Even if the generated password itself is returned in real time, users may reasonably assume local generation for a sensitive security task, creating privacy and trust risks around external handling of security-related material.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This skill explicitly performs outbound network transmission to a third-party service to generate passwords for a security-sensitive use case. While the payload shown contains only generation parameters, the context is more dangerous than ordinary API use because users may rely on the secrecy and trustworthiness of generated credentials without understanding that an external service is involved.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

macOS / Linux (curl):

bash
curl -s -X POST https://www.acetoolz.com/api/openclaw/password-generator \
  -H "Content-Type: application/json" \
  -d '{"length": 16, "uppercase": true, "lowercase": true, "numbers": true, "symbols": true, "exclude_similar": false, "begin_with_letter": false}'

Static analysis

No suspicious patterns detected.