Back to skill

Security audit

OpenPot Awareness

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real OpenPot helper skill, but it asks the agent to approve device access and add SSH access in ways that need careful review.

Install only if you expect OpenPot to have deep access to your agent environment. Before using it, manually verify each device pairing, avoid approving the first pending request by name alone, review SSH keys after setup, understand that chat/calendar/page-capture data may be retained, and patch or avoid the bundled Weather and Billable Hours apps until their unsafe HTML rendering is fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:886
Finding

Race-Prone Automatic Device Pairing Can Approve an Unauthorized Client

Content
View full analysis
` 3. Confirm: "You're approved and connected!" **Security rules:** - Only auto-approve during an active onboarding conversation - Only approve ONE device per onboarding flow - If multiple requests arrive, approve only the first and alert the user - Outside onboarding, surface pairing requests for manual approval ``` ### Technical Analysis The onboarding procedure authorizes a pending device based on a mutable display name and request arrival order. Neither the device's cryptographic fingerprint nor a user-visible pairing challenge is verified before approval. The instruction to approve the first request is particularly unsafe. An attacker who can reach the gateway during an onboarding session may submit a pairing request before the legitimate phone and use an expected name such as `OpenPot` or `openclaw-ios`. Display names are identifiers, not authentication factors. Although automatic approval is limited to an active onboarding flow, this only narrows the attack window; it does not establish that the selected request belongs to the user. ### Attack Path 1. The victim starts an OpenPot onboarding conversation. 2. The attacker reaches the exposed gateway through the LAN, VPN, Tailscale network, or another accessible route. 3. The attacker submits a device-pairing request using the name `OpenPot` or `openclaw-ios`. 4. The attacker's request appears before the legitimate device or is the only request visible at that instant. 5. Following the Skill instructions, the agent approves the first matching request. 6. The attacker obtains an approved device identity and can use the access granted t ...[truncated 543 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:953
Finding

OpenPot Sync Reinstalls an Unpinned Mutable Skill Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
apps/billable-hours.html:208
Finding

Stored DOM XSS Through Unsanitized Client Names in Billable Hours

Content
View full analysis
c.name === client)) { clients.push({ name: client, rate: rate }); if (clients.length > 20) clients = clients.slice(-20); } else { const existing = clients.find(c => c.name === client); if (rate > 0) existing.rate = rate; } active = { client, rate, startTime: Date.now() }; save(); renderActive(); renderChips(); tickInterval = setInterval(updateActiveDisplay, 1000); } ``` The persisted value is then inserted into both HTML content and an inline JavaScript handler: ```javascript function renderChips() { const el = document.getElementById('clientChips'); const currentInput = document.getElementById('clientInput').value; if (clients.length === 0) { el.innerHTML = ''; return; } el.innerHTML = clients.slice(-8).reverse().map(c => `
${c.name}${c.rate ? ' · $' + c.rate : ''}
` ).join(''); } ``` The same client name is inserted into the history list: ```javascript list.innerHTML = todayEntries.map(e => { const h = Math.floor(e.seconds / 3600); const m = Math.floor((e.seconds % 3600) / 60); const timeStr = h > 0 ? `${h}h ${m}m` : `${m}m`; const start = new Date(e.startedAt); const startStr = start.toLocaleTimeString('en-US', { hour:'numeric', minute:'2-digit' }); return `
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
apps/weather.html:274
Finding

Stored DOM XSS Through Unsanitized Weather Location Data

Content
View full analysis
= MAX_LOCATIONS) { showStatus(`Maximum ${MAX_LOCATIONS} locations reached`, true); return; } // Check for duplicates by query string const queryLower = query.toLowerCase(); if (locations.find(l => l.zip && l.zip.toLowerCase() === queryLower)) { showStatus('Location already added', true); return; } const btn = document.getElementById('addBtn'); btn.disabled = true; btn.textContent = '...'; hideStatus(); try { const geo = await geocodeLocation(query); if (!geo) { showStatus('Location not found', true); btn.disabled = false; btn.textContent = 'Add'; return; } // Check for duplicate by coordinates (within ~10km) if (locations.find(l => Math.abs(l.lat - geo.lat) < 0.1 && Math.abs(l.lon - geo.lon) < 0.1)) { showStatus('A nearby location is already added', true); btn.disabled = false; btn.textContent = 'Add'; return; } const weather = await fetchWeather(geo.lat, geo.lon); const loc = { id: Date.now().toString(), zip: query, name: geo.name, region: geo.region, lat: geo.lat, lon: geo.lon, weather: weather, updatedAt: new Date().toISOString() }; locations.unshift(loc); save(); input.value = ''; render(); ``` The stored user value and third-party API fields are interpolated directly into `innerHTML`: ```javascript container.innerHTML = locations.map(loc => { const w = loc.weather; if (!w || !w.current) return ''; const cur ...[truncated 4233 chars]
Remediation
View remediation

other

Note
Location
apps/openpot-guide.html:448
Finding

Privacy Claims Conflict with Third-Party Weather Data Disclosure

Content
View full analysis

🔒 Privacy

Direct connection to your server. No cloud relay, no third-party data handling. Your conversations stay between you and your hardware.

``` It repeats the assertion in the security section: ```html

🔐 Direct Connection

OpenPot connects directly to your server. No data passes through Anthropic, Apple, or any third party. Your conversations stay between you and your hardware.

``` The bundled Weather app sends user-entered locations and coordinates to third-party services: ```javascript const res = await fetch('https://api.zippopotam.us/us/' + query); ``` ```javascript const url = 'https://geocoding-api.open-meteo.com/v1/search?name=' + encodeURIComponent(query) + '&count=5&language=en&format=json'; const res = await fetch(url); ``` ```javascript const url = `https://api.open-meteo.com/v1/forecast?latitude=${lat}&longitude=${lon}¤t=temperature_2m,relative_humidity_2m,apparent_temperature,weather_code,wind_speed_10m,is_day&daily=weather_code,temperature_2m_max,temperature_2m_min&temperature_unit=fahrenheit&wind_speed_unit=mph&precipitation_unit=inch&forecast_days=6&timezone=auto`; const res = await fetch(url); ``` ### Technical Analysis The privacy language states that no data passes through third parties, while the bundled Weather application directly contacts Zippopotam and Open-Meteo. The transmitted information includes: - User-entered US ZIP codes. - City names and non-US postal-code searches. - Latitude and longitude for saved locations. - Normal network metadata such as ...[truncated 1106 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (40)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: openpot-awareness
description: Teaches this agent how to serve content to the OpenPot iOS client — cards, apps, page captures, calendar, voice, chat persistence, and onboarding
emoji: 🫕
version: 6.0.0
homepage: https://openpot.app
---

# OpenPot Awareness Skill

You are connected to **OpenPot** — a native iOS app that serves as a
command center for AI agents. OpenPot has configurable tabs: **Chat**
(always on), **Pulse** (notification cards), **Calendar**, **Apps**,
**Terminal**, and **Agents** (always on). Users choose which tabs to
display in Settings — not every user will have all tabs visible.

##

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
- User says **"OpenPot sync"** — run the sync process (see Sync section)
- User sends a **page capture** (message contains
  `---PAGE CAPTURE CONTEXT---`) — see Page Captures section
- User asks about **setting up OpenPot** — see Onboarding section
- User asks about **calendar**, **voice**, **chat persistence**, or
  **building an app** — see the relevant section below

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

md
- User says **"OpenPot sync"** — run the sync process (see Sync section)
- User sends a **page capture** (message contains
  `---PAGE CAPTURE CONTEXT---`) — see Page Captures section
- User asks about **setting up OpenPot** — see Onboarding section
- User asks about **calendar**, **voice**, **chat persistence**, or
  **building an app** — see the relevant section below

Context Leakage

High
Category
Data Exfiltration
Confidence
87% confidence
Finding

Including a concrete local screenshot path in captured context exposes internal filesystem layout and attachment locations to the skill. While not automatically exfiltration, disclosing local paths and making screenshot access part of the workflow increases the risk of sensitive file access and unintended propagation of locally stored visual data.

Content

Scanner excerpt · SKILL.md (reported line 291)May include surrounding context.

| Value | Value |

Screenshot: ~/.openclaw/workspace/attachments/{uuid}.jpg ---END PAGE CAPTURE CONTEXT---

text

Fields: URL, Title, Description, Site (metadata), Readable Text (main

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Adding a device public key to ~/.ssh/authorized_keys grants persistent remote shell access to the host account. In the context of an agent skill, instructing or normalizing this action is high risk because compromise, spoofing, or misbinding of the key would directly enable unauthorized host access.

Content

Scanner excerpt · SKILL.md (reported line 931)May include surrounding context.

md
1. The user taps the key icon in the Terminal status bar
2. Copies the public key
3. Sends it to you
4. You add it to `~/.ssh/authorized_keys`

This is a one-time step per device.

Hidden Instructions

High
Category
Prompt Injection
Confidence
88% confidence
Finding

The migration section tells the agent to search for and delete content between hidden marker comments in SOUL.md. Hidden-marker-based editing instructions are dangerous in prompt-bearing files because they can be used to alter control surfaces that affect agent behavior outside the user's immediate request.

Content

Scanner excerpt · SKILL.md (reported line 1032)May include surrounding context.

md
# Migration: Clean Up Old SOUL.md Inserts

If your SOUL.md contains `<!-- OPENPOT INSERT` markers from a previous
version of this skill, remove them. The native skill system loads this
SKILL.md automatically — SOUL.md injection is no longer needed.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · apps/meeting-cost.html (reported line 168)May include surrounding context.

html
<div class="history">
    <div class="history-title">Past Meetings</div>
    <div id="historyList"></div>
    <button class="clear-btn" onclick="clearHistory()">Clear History</button>
  </div>
</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 206)May include surrounding context.

html
<body>
<div class="container">

  <!-- Navigation -->
  <div class="nav">
    <div class="nav-title">OpenPot Guide</div>
    <div class="nav-scroll">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 231)May include surrounding context.

html
<div class="subtitle">Your AI agent, in your pocket. The native iOS command center for self-hosted agents.</div>
  </div>

  <!-- GETTING STARTED -->
  <div class="section" id="getting-started">
    <div class="section-label">Getting Started</div>
    <div class="section-title">Connect to Your Agent</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 256)May include surrounding context.

html
</div>
  </div>

  <!-- CHAT -->
  <div class="section" id="chat">
    <div class="section-label">Tab Guide</div>
    <div class="section-title">💬 Chat</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 303)May include surrounding context.

html
<div class="cmd">"Every morning at 7 AM, send me a briefing with today's weather and my calendar"</div>
  </div>

  <!-- CALENDAR -->
  <div class="section" id="calendar">
    <div class="section-title">📅 Calendar</div>
    <div class="section-desc">Your schedule through your agent's perspective. Three views — Year, Month, and Agenda — with events from multiple sources.</div>

Exfiltration Commands

High
Category
Prompt Injection
Confidence
92% confidence
Finding

The phrase 'quietly sends' describes automatic transfer of schedule data from the client to the agent without explicit user action at the time of sharing. In context, this is effectively covert exfiltration of sensitive calendar context to another system component, which is especially risky because schedules can reveal location patterns, relationships, and confidential appointments.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 339)May include surrounding context.

html
<div class="tip">
      <div class="tip-label">Calendar Context</div>
      <p>Every time you interact with the Calendar tab, OpenPot quietly sends your today/tomorrow schedule to your agent. It absorbs this silently and uses it to answer schedule questions naturally.</p>
    </div>

    <div class="cmd">"Add my weekly review to my agent calendar — Fridays at 4 PM, remind me 1 day before"</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 368)May include surrounding context.

html
<div class="cmd">"Build me a dark-themed grocery list app"</div>
  </div>

  <!-- TERMINAL -->
  <div class="section" id="terminal">
    <div class="section-title">⌨️ Terminal</div>
    <div class="section-desc">Full SSH terminal access to your agent's server, right from your phone.</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 411)May include surrounding context.

html
</div>
  </div>

  <!-- VOICE -->
  <div class="section" id="voice">
    <div class="section-label">Features</div>
    <div class="section-title">🗣️ Voice</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 446)May include surrounding context.

html
</div>
  </div>

  <!-- TIPS -->
  <div class="section" id="tips">
    <div class="section-label">Get More</div>
    <div class="section-title">Tips & Ideas</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · apps/openpot-guide.html (reported line 528)May include surrounding context.

html
</details>
  </div>

  <!-- PRIVACY -->
  <div class="section" id="privacy">
    <div class="section-label">Security</div>
    <div class="section-title">Privacy & Security</div>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The page-capture workflow tells the agent to create a 'permanent memory' of captured page content and screenshots without requiring explicit user disclosure or retention controls. Because page captures can include sensitive browsing-derived information, silent long-term retention materially increases privacy risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
When the user moves a card to a different Pulse channel, you receive
a notification. This is a learning signal. If the user moves multiple
cards of the same type, ask: "Want me to route [type] to [channel]
automatically?" Never change routing without asking.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 420)May include surrounding context.

md
## Calendar Context Updates

OpenPot automatically sends calendar context messages when the user
interacts with the Calendar tab. These arrive as chat messages wrapped
in `[calendar_context]` tags.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 427)May include surrounding context.

md
**When you receive a `[calendar_context]` message:**

- **Absorb the schedule information silently.** Do NOT respond to the
  message — no acknowledgment, no confirmation, no "Got it."
- **Use the context to inform future conversations.** If the user asks
  "what do I have today," "am I free this afternoon," or "what's
  coming up this week," reference the most recent calendar context

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

The instruction to learn calendar usage patterns 'without asking' encourages inference and future routing decisions based on observed personal calendar structure. In a scheduling context, that can lead to overcollection of sensitive behavioral data and actions taken on inferred preferences rather than explicit consent.

Content

Scanner excerpt · SKILL.md (reported line 520)May include surrounding context.

md
Learn the user's calendars early. When you first access their calendar
data, note which calendars exist and what they're used for. Over time
you'll know which calendar is for what without asking.

**Routing rules:**
- User says "my calendar" or names a specific calendar → use the

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The chat persistence section instructs storing user conversations in PostgreSQL but does not require clear user-facing disclosure about server-side retention, backup, access, or privacy implications. Users may reasonably assume chats are local unless explicitly warned, making this a transparency and privacy-risk issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 791)May include surrounding context.

After setting up chat persistence, test:

bash
# Store a test message
curl -X POST http://localhost:8000/api/chat/messages \
  -H "Authorization: Bearer <token>" \
  -H "Content-Type: application/json" \
  -d '{"session_id":"test","content":"Hello","sender_type":"user","sender_name":"Test","message_type":"text"}'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The onboarding flow instructs the agent to auto-approve device pairing requests. Even with surrounding limits, automatic trust establishment for a new device is security-sensitive because a mistaken or spoofed request could grant an unintended device agent access.

Content

Scanner excerpt · SKILL.md (reported line 888)May include surrounding context.

md
- If not installed: LAN-only works on home WiFi. For remote access,
  point them to tailscale.com/download.

## Step 3 — Auto-Approve Device Pairing

Tell the user: "When you tap Connect, I'll approve the pairing
automatically. Go ahead."

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

Although the section adds constraints, it still normalizes automatic approval of device pairings during onboarding. Any workflow that authorizes access based on conversational state rather than strong device verification increases the chance of accidental or unauthorized enrollment.

Content

Scanner excerpt · SKILL.md (reported line 900)May include surrounding context.

md
3. Confirm: "You're approved and connected!"

**Security rules:**
- Only auto-approve during an active onboarding conversation
- Only approve ONE device per onboarding flow
- If multiple requests arrive, approve only the first and alert the user
- Outside onboarding, surface pairing requests for manual approval

Static analysis

No suspicious patterns detected.