Back to skill

Security audit

Inspirai Project

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it handles Discord bot credentials unsafely and can send or change project data with broad natural-language triggers.

Before installing, confirm you are comfortable sending project ideas, assignments, and status queries to the configured Discord workspace. Do not run the helper's config command unless the token output is removed or redacted, and rotate the Discord bot token if it may already have been printed in logs or transcripts. Prefer explicit /project:* invocations and review archive actions before allowing them to update local project records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
discord-threads.py:105
Finding

Discord Bot Token Exposed Through the Config Command

Content
View full analysis

Vulnerability Details

File Location: discord-threads.py, lines 105–137
Vulnerability Type: Sensitive credential disclosure through standard output
Risk Level: High

Vulnerable Code

python
def load_openclaw_discord_config():
    """从 openclaw.json 提取 Discord 配置"""
    import os
    config_path = os.path.expanduser("~/.openclaw/openclaw.json")
    with open(config_path) as f:
        config = json.load(f)

    discord = config.get("channels", {}).get("discord", {})
    accounts = discord.get("accounts", {})
    default_account = accounts.get("default", {})
    token = default_account.get("token", "")

    # 从 bindings 提取 agent -> channel 映射
    channel_map = {}
    for binding in config.get("bindings", []):
        agent_id = binding.get("agentId")
        match = binding.get("match", {})
        peer = match.get("peer", {})
        if peer.get("kind") == "channel" and agent_id:
            channel_map[agent_id] = peer["id"]

    guild_id = ""
    for gid in default_account.get("guilds", {}):
        guild_id = gid
        break

    return {
        "token": token,
        "guild_id": guild_id,
        "channel_map": channel_map,
    }


if __name__ == "__main__":
    parser = argparse.ArgumentParser(description="Discord Thread 批量操作")
    sub = parser.add_subparsers(dest="command")

    # create: 从 JSON stdin 批量创建
    p_create = sub.add_parser("create", help="批量创建项目 Thread")
    p_create.add_argument("project_name", help="项目名")
    p_create.add_argument("--input", help="JSON 文件路径 (或 stdin)")

    # status: 查询 Thread 最新消息
    p_status = sub.add_parser("status", help="查询项目 Thread 状态")
    p_status.add_argument("--input", help="JSON 文件路径 (或 stdin)")

    # config: 输出当前 Discord 配置
    p_config = sub.add_parser("config", help="输出 OpenClaw Discord 配置")

    args = parser.parse_args()

    if args.command == "config":
        cfg = load_openclaw_discor
...[truncated 2042 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the token from the object returned by any command intended for display.

  • Make the config command return only non-secret information, for example:

    python
    print(json.dumps({
        "token_configured": bool(cfg["token"]),
        "guild_id": cfg["guild_id"],
        "channel_map": cfg["channel_map"],
    }, indent=2, ensure_ascii=False))
    
  • Keep credential retrieval private to the functions that perform authenticated Discord API operations.

  • Separate public configuration metadata from secret authentication state using distinct data structures.

  • Redact authorization credentials from all logs, exceptions, diagnostics, and debugging output.

  • Restrict ~/.openclaw/openclaw.json to the owning user, such as with file mode 0600.

  • Rotate the Discord bot token if the vulnerable config command has previously been invoked in a logged environment.

  • Add an automated test asserting that command output never contains the configured token.

T09 · Insecure Skill Coding Practices

Warning
Location
skills/init/SKILL.md:82
Finding

Skill Instructions Expose the Discord Bot Token in Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Locations:

  • skills/init/SKILL.md, lines 82–87 and 106–111
  • skills/discuss/SKILL.md, lines 65–70
  • skills/status/SKILL.md, lines 48–51

Vulnerability Type: Insecure credential handling in executable Skill instructions
Risk Level: Medium

Vulnerable Code

skills/init/SKILL.md, lines 82–87:

bash
curl -X POST "https://discord.com/api/v10/channels/{channel_id}/threads" \
  -H "Authorization: Bot {token}" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "[{项目名}] {agent职能}",
    "type": 11,
    "auto_archive_duration": 10080
  }'

skills/init/SKILL.md, lines 106–111:

bash
curl -X POST "https://discord.com/api/v10/channels/{thread_id}/messages" \
  -H "Authorization: Bot {token}" \
  -H "Content-Type: application/json" \
  -d '{
    "content": "📋 **项目**: {项目名}\n\n**你的任务**: {根据 agent 职能生成的具体任务描述}\n\n**项目背景**: {用户的原始想法描述}\n\n**协作成员**: {其他参与 agent 列表}\n\n请开始工作,有问题随时沟通。"
  }'

skills/discuss/SKILL.md, lines 65–70:

bash
curl -X POST "https://discord.com/api/v10/channels/{channel_id}/messages" \
  -H "Authorization: Bot {token}" \
  -H "Content-Type: application/json" \
  -d '{
    "content": "💬 **Boss 想讨论**:\n\n{话题描述}\n\n请给出你的专业分析和建议。"
  }'

skills/status/SKILL.md, lines 48–51:

bash
curl -s "https://discord.com/api/v10/channels/{thread_id}/messages?limit=1" \
  -H "Authorization: Bot {token}"

Technical Analysis

These Skill documents instruct an executing Agent to interpolate the Discord bot token directly into a curl header argument. Although the request is sent over HTTPS to Discord's official API and network access is necessary for the declared functionality, placing the token in process arguments is not necessary.

Depending on the execution environment, command-line arguments may be exposed through process inspection, shell tracing, command telemetry, audit systems, deb ...[truncated 1612 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace direct curl examples with calls to discord-threads.py or another dedicated client that reads the token internally and never places it in command-line arguments.
  • Centralize all Discord authentication in one reviewed helper function.
  • If shell-based requests are unavoidable, provide the authorization header through a protected configuration file or file descriptor rather than direct argument interpolation.
  • Ensure any temporary credential-bearing file is created with mode 0600, is inaccessible to other users, and is securely removed immediately after use.
  • Disable shell tracing and prevent command telemetry from recording secret-bearing operations.
  • Avoid printing generated commands or including authorization headers in Agent transcripts.
  • Apply minimal Discord permissions to the bot and restrict its access to only the channels required by this Skill.
  • Rotate the bot token if prior executions may have retained the complete commands in logs or transcripts.
  • Update all affected Skill documents consistently so an Agent is never instructed to expose the token in a command template.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The config subcommand prints the full Discord configuration returned by load_openclaw_discord_config(), including the bot token and channel mappings. Exposing secrets and internal routing data is not necessary for normal project-thread creation/status behavior, and any caller able to invoke this tool could harvest reusable credentials for broader Discord API access.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very broad natural-language phrases like '讨论一下', '聊聊', '我有个想法', 'discuss', and 'brainstorm', which are likely to match ordinary conversation rather than an explicit command. In a skill that forwards user content to Discord, accidental invocation can cause unintended routing and disclosure of user text to external channels without clear intent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes Discord-integrated automation and references an external helper script, which implies network-capable actions, but it declares no explicit tool scope or permission boundaries. Without an allowed-tools or permissions declaration, an agent may invoke broader capabilities than users expect, increasing the risk of unintended network actions or thread creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad natural-language phrases like '讨论一下', 'discuss', and 'project status', which can match common conversational requests and cause accidental invocation. In a skill that can route discussions and create project threads, unintended activation can lead to unauthorized or confusing external actions in Discord.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description does not clearly warn users that invoking the skill may create Discord threads, route messages across agent channels, and distribute tasks automatically. Lack of upfront disclosure undermines informed consent and can cause data-sharing or operational side effects that users did not intend.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The tool reads local OpenClaw configuration to obtain the Discord bot token and agent-to-channel bindings. Reading credentials locally is expected for Discord automation, but it also grants this skill access to sensitive account material beyond pure text processing, which increases blast radius if the tool is misused or extended to expose that data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Discord token is read from local config and can then be printed verbatim through the config path, with no redaction or warning. A leaked bot token can let an attacker impersonate the bot, read or send messages where it has access, create threads, and persist unauthorized activity until the token is rotated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs sending the discussion topic to Discord channels but does not provide a clear user-facing warning that the content will be shared externally with other agents/users. This creates a privacy and data-handling risk, especially because early-stage discussions may contain sensitive business, personal, or security-related information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill performs external transmission by POSTing user-supplied discussion content to the Discord API. While external messaging is part of the feature, it is still security-relevant because it exports potentially sensitive data to a third-party service and can be triggered in combination with the broad activation phrases described above.

Content

Scanner excerpt · skills/discuss/SKILL.md (reported line 59)May include surrounding context.

在推荐的 Agent 频道中发送消息:

bash
curl -X POST "https://discord.com/api/v10/channels/{channel_id}/messages" \
  -H "Authorization: Bot {token}" \
  -H "Content-Type: application/json" \
  -d '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad natural-language phrases like '讨论一下', 'discuss', and 'create project', which can match ordinary conversation and unintentionally activate a workflow that creates Discord threads and dispatches tasks. Because the skill performs external side effects, overly broad activation increases the chance of accidental data disclosure and unintended project creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description does not prominently warn users that their project ideas, task assignments, and collaborator lists will be transmitted to Discord and that project metadata will be persisted locally in ~/.claude/projects.json. This lack of transparency undermines informed consent and can lead to unintentional sharing of sensitive business information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill explicitly instructs sending project names and related task context to the Discord API using a bot token, which is a true external transmission channel. In this skill's context, the transmitted content can include sensitive project ideas, internal role mappings, and user-provided descriptions, making accidental or unauthorized disclosure materially risky if users are not clearly warned or if channel mappings are misconfigured.

Content

Scanner excerpt · skills/init/SKILL.md (reported line 74)May include surrounding context.

bash
# 使用 Discord API 创建 Thread
curl -X POST "https://discord.com/api/v10/channels/{channel_id}/threads" \
  -H "Authorization: Bot {token}" \
  -H "Content-Type: application/json" \
  -d '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad conversational language such as 'project status' and '有什么项目在进行', which can overlap with ordinary discussion and cause unintended invocation. In an agent environment, overly generic triggers increase the risk that the skill runs and reads local project metadata or performs follow-on actions without the user intentionally selecting the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a status/view command, but it also performs a state-changing action by archiving a project in projects.json. This mismatch violates least surprise and can cause unintended data lifecycle changes when a user believes they are only querying status, especially if the command is invoked from natural-language routing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes archiving a project when the user says phrases like '这个项目做完了' or '归档', but it does not require a clear confirmation step before updating projects.json. Because archiving is a destructive state transition and the triggers are natural-language based, accidental or context-misread input could silently alter project records.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill name, description, and command documentation are primarily presented in Chinese without indicating that users may choose another language. This can amount to a language-policy issue when the skill implicitly assumes a specific language or locale instead of offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

User-facing strings such as the module description, command descriptions, and status messages are presented exclusively in Chinese, with no indication that language is configurable or optional. Under the stated policy, forcing a locale/language without offering choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.