Back to skill

Security audit

Admapix Repo

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: query an external ad analytics API with your API key, with data-sharing and install cautions but no hidden destructive behavior found.

Install only if you are comfortable sending ad-analysis queries, app names, filters, and your configured API key to the AdMapix/SkillBoss service. Avoid personal identifiers or confidential campaign names in prompts, and use a pinned or verified install command for controlled environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:17
Finding

Unpinned Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 17-20
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

bash
## Install

```bash
npx clawhub install admapix
text

### Technical Analysis

The installation instructions invoke `clawhub` through `npx` without specifying a reviewed package version or integrity constraint. If the package is not already available locally, `npx` can retrieve and execute the version currently resolved by the npm registry.

Because the repository does not include a lockfile, package integrity hash, vendored installer, or other mechanism that binds this command to an audited release, the code executed at installation time can differ from the code originally reviewed. This creates a supply-chain trust dependency on the package registry, package publisher account, DNS/TLS infrastructure, and the latest resolved package release.

The command is documented rather than automatically executed by the Skill. Exploitation therefore requires a user or deployment process to follow the installation instructions.

### Attack Path

1. An attacker compromises the `clawhub` package, its publisher account, or an associated package-distribution channel.
2. The attacker publishes a malicious version that is selected by the unpinned `npx clawhub` invocation.
3. A user or automated deployment follows the documented installation command.
4. `npx` downloads and executes the attacker-controlled package.
5. The malicious package runs with the privileges and environment access of the installing user.

### Impact Assessment

Successful exploitation could permit arbitrary local code execution under the installing user's account. Depending on that account's privileges and environment, the malicious installer could read accessible files and environment variables, steal API credentials, modify user configuration, install additional components, or tamper with other project
...[truncated 269 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to a specifically reviewed release:
    bash
    npx --yes clawhub@<reviewed-version> install admapix
    
  2. Document the expected npm publisher, package registry, and release provenance so users can verify that they are retrieving the intended package.
  3. Publish and verify package integrity or signed provenance where supported.
  4. Prefer a locked installation workflow for automated deployments rather than resolving the latest release at execution time.
  5. Run the installation using a minimally privileged account and avoid exposing unrelated secrets in its environment.
  6. Apply the same correction to the equivalent command in README_CN.md, lines 17-20.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
Findings (24)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

md
**Reuse data:** If the user asks follow-up questions about already-fetched data, analyze existing results first. Only make new API calls when needed.

## Output Guidelines

1. **Language consistency** — ALL output (headers, labels, insights, hints, errors, disclaimers) must match the user's detected language. See "Language Handling" section above.
2. **Route-appropriate output** — Don't force H5 links on analytical questions; don't dump tables for browsing

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub install admapix without pinning a specific package version. This allows whatever version is current at execution time to be fetched and run, which creates a supply-chain risk if the package is compromised, a malicious version is published, or a breaking change introduces unsafe behavior. Because this is an installation command that may execute code on the user's machine, the risk is real rather than purely informational.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to install the skill via npx clawhub install admapix without pinning a specific package/version. This creates a supply-chain risk because users may fetch a newer or tampered dependency at install time, and npx executes downloaded code. In this context, the skill is installed from a command in documentation, so the risk is real even though the file itself is only a README.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example invocation phrases are broad natural-language requests such as '分析一下 Temu' or '全面分析 Temu 的广告策略', without a clear namespace or explicit trigger boundary. In assistant ecosystems, overly generic triggers can overlap with normal conversation and cause unintended skill activation, potentially sending user queries to the skill or external API when the user did not mean to invoke it. Because this skill performs external data lookups and analysis, accidental invocation increases privacy and misuse risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description contains a very large set of broad trigger terms spanning multiple related but distinct intents. This can cause the skill to activate on queries the user did not clearly direct to this tool, increasing the chance of unintended external API calls and disclosure of user prompts or inferred app/business interests to a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to detect the user's language from the first message and maintain it, which imposes a language choice automatically rather than offering a user-controlled preference. This is a natural-language locale policy concern because the user is not explicitly asked to confirm or choose the language.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill is explicitly designed to transmit user-derived query parameters and an API credential to api.skillboss.co. This is expected functionality, but it is still a real data egress boundary: user requests, search terms, app names, and analysis targets are sent to a third-party service, which may be sensitive in competitive-intelligence contexts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

bash
# GET
curl -s "https://api.skillboss.co/api/data/{endpoint}?{params}" \
  -H "X-API-Key: $SKILLBOSS_API_KEY"

# POST

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill is explicitly designed to transmit user-derived query parameters and an API credential to api.skillboss.co. This is expected functionality, but it is still a real data egress boundary: user requests, search terms, app names, and analysis targets are sent to a third-party service, which may be sensitive in competitive-intelligence contexts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

bash
# GET
curl -s "https://api.skillboss.co/api/data/{endpoint}?{params}" \
  -H "X-API-Key: $SKILLBOSS_API_KEY"

# POST

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
-H "X-API-Key: $SKILLBOSS_API_KEY"

# POST
curl -s -X POST "https://api.skillboss.co/api/data/{endpoint}" \
  -H "X-API-Key: $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{...}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The API supports sending a delivery object containing externalUserId and related channel context for H5 page generation, but the documentation provides no privacy, consent, minimization, or retention guidance. That creates a real risk that integrators will transmit user-identifying context to a third party without adequate user notice or controls, leading to privacy violations and regulatory exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 122)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 139)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 177)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 191)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 192)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 193)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 194)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Defaulting ambiguous requests to Creative Search means uncertain user input is automatically routed into a network-backed action rather than asking for clarification. In this skill's context, that can send unintended search terms to the external API and produce misleading results from the wrong data domain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation directs users to send a unified_product_id and related app-analysis parameters to an external third-party API (api.admapix.com) using an API key, but it provides no warning that these identifiers, filters, and query patterns may be transmitted off-platform and logged by that service. While the data shown is not inherently highly sensitive, the omission can mislead users about data handling and creates privacy, compliance, and operational exposure if internal or customer-linked identifiers are submitted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file includes Chinese text in the title and example invocations such as "Temu 最近下载量怎么样?" while not stating that language selection is optional or user-driven. Under the locale-policy rule, forcing or assuming a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation states that query.country_info.country_name is the country name in Chinese, which imposes a specific locale in the skill's natural-language interface expectations. Because no user choice or opt-in is offered here, this can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file instructs use of an API key via the X-API-Key header, which involves handling sensitive credentials and transmitting them to a remote service. Although the file documents how authentication works, it does not include any warning or disclosure about protecting the key, avoiding exposure in logs, or the fact that requests send authenticated data to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file documents authentication via X-API-Key: $SKILLBOSS_API_KEY, which indicates the skill will use sensitive credentials in requests. Under the markdown warning criteria, there is no accompanying warning about credential use, privacy implications, or safe handling of the API key.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file's invocation guidance maps only Chinese user utterances to API behaviors, which can amount to an implicit language constraint. There is no explicit opt-in, alternative language support, or statement that the skill is intentionally limited to Chinese-language usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.