Back to skill

Security audit

Amernet AI SaaS

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed message bridge, but it asks for broad account permissions and includes campaign-changing AutoPilot actions that are not clearly surfaced in the user-facing README.

Review this before installing. Only use it where administrators intend every connected-channel message to be processed by the AI SaaS service, and make sure users understand that their messages and channel identifiers are sent externally. Prefer a narrowly scoped, revocable API token if the service supports one, lock the base URL to the trusted HTTPS SaaS origin, and treat AutoPilot deployment or pause requests as business-changing actions that need role checks and explicit confirmation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:15
Finding

Overprivileged API Credential Required for Routine Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15-21 and README.md:15-17
Vulnerability Type: Excessive API permissions and violation of least privilege
Risk Level: High

Vulnerable Code Snippet:

markdown
| Variable | Description |
|---|---|
| `AI_SAAS_API_KEY` | Your API key from the portal (Settings → API Keys). Needs `all` permission. |
| `AI_SAAS_AGENT_ID` | The agent ID to route all messages to (copy from the OpenClaw Integration page). |
| `AI_SAAS_BASE_URL` | Base URL of your AI SaaS instance. Default: `https://saas.salesbay.ai` |

The README separately instructs users to create the same broadly privileged credential:

markdown
1. Open **Settings → API Keys** and create a key with **All** permissions. Copy the key.
2. Open the **Chatbots** page and copy the ID of the chatbot you want to route messages to.

Technical Analysis

The skill requires an API key with all permissions even though its documented routine operations are limited to sending chat messages, retrieving agent status, deleting conversation state, and handling selected AutoPilot requests. This violates the principle of least privilege.

If the key is exposed through configuration disclosure, endpoint redirection, logs, backups, or another local compromise, an attacker may be able to invoke API functionality unrelated to the skill's legitimate purpose. The precise set of additional privileges depends on the server-side meaning of all, but the documentation explicitly establishes that the credential is not narrowly scoped.

Attack Path

  1. A user follows the installation instructions and stores an API key with all permissions in ~/.openclaw/openclaw.json.
  2. An attacker obtains the configuration through local compromise, an exposed backup, accidental logging, or endpoint redirection.
  3. The attacker extracts the bearer token.
  4. The attacker submits authenticated requests directly to other API o ...[truncated 523 chars]
Remediation
View remediation

Remediation Suggestions

  • Introduce a dedicated integration token restricted to the selected agent.
  • Grant only the exact permissions required for chat submission, status retrieval, and conversation reset.
  • Use a separate, explicitly enabled credential for campaign deployment or pause operations.
  • Ensure server-side authorization validates both the token scope and requested agent or tenant.
  • Support token expiration, rotation, and immediate revocation.
  • Update the README and skill instructions so they no longer request an all-permissions key.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:19
Finding

Configurable Base URL Can Exfiltrate Bearer Credentials and Private Messages

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19-20, SKILL.md:41-50, SKILL.md:59-62, SKILL.md:68-70, and SKILL.md:78-89
Vulnerability Type: Unvalidated credential-bearing outbound destination
Risk Level: High

Vulnerable Code Snippet:

markdown
| `AI_SAAS_API_KEY` | Your API key from the portal (Settings → API Keys). Needs `all` permission. |
| `AI_SAAS_AGENT_ID` | The agent ID to route all messages to (copy from the OpenClaw Integration page). |
| `AI_SAAS_BASE_URL` | Base URL of your AI SaaS instance. Default: `https://saas.salesbay.ai` |
markdown
POST ${AI_SAAS_BASE_URL}/api/v1/${TARGET}/chat
Authorization: Bearer ${AI_SAAS_API_KEY}
Content-Type: application/json

{
  "sender_id": "<constructed sender_id>",
  "message": "<user message text>"
}

The same configurable origin is used for conversation deletion, status retrieval, and the Growth Engine assistant:

markdown
DELETE ${AI_SAAS_BASE_URL}/api/v1/${TARGET}/conversations/<sender_id>
Authorization: Bearer ${AI_SAAS_API_KEY}
markdown
GET ${AI_SAAS_BASE_URL}/api/v1/${TARGET}
Authorization: Bearer ${AI_SAAS_API_KEY}
markdown
POST ${AI_SAAS_BASE_URL}/api/v1/drip-agent/chat
Authorization: Bearer ${AI_SAAS_API_KEY}
Content-Type: application/json

{
  "sessionId": "<the same sender_id>",
  "mode": "customer",
  "message": "<user message text>"
}

Technical Analysis

AI_SAAS_BASE_URL controls the destination of requests that include an all-permissions bearer token, channel-specific user identifiers, and complete message contents. The instructions do not require HTTPS, validate the hostname against a trusted allowlist, constrain redirects, or prevent credentials from being forwarded to a different origin.

A malicious or accidentally modified configuration can therefore direct sensitive requests to an attacker-controlled server. Use of ...[truncated 1132 chars]

Remediation
View remediation

Remediation Suggestions

  • Require https:// for all production API endpoints and reject plaintext HTTP.
  • Validate the destination hostname against a strict allowlist or a securely provisioned tenant origin.
  • Reject URLs containing unexpected credentials, ports, path prefixes, fragments, or ambiguous hostname encodings.
  • Disable redirects for authenticated requests or verify that every redirect remains on the exact trusted origin.
  • Never forward the Authorization header across origins.
  • Replace direct channel identifiers with tenant-scoped pseudonymous identifiers where possible.
  • Use a narrowly scoped and short-lived token to reduce the consequences of disclosure.
  • Document the transmission of user messages and identifiers and apply appropriate retention and consent controls.

T08 · Insecure Dependencies

Warning
Location
README.md:9
Finding

Mutable Global Installation of an Unpinned Dependency

Content
View full analysis

Vulnerability Details

File Location: README.md:9
Vulnerability Type: Unpinned global package installation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- [OpenClaw](https://openclaw.ai) installed and running (`npm install -g openclaw@latest`)

Technical Analysis

The installation instruction selects the mutable latest npm distribution tag rather than an exact reviewed version. Consequently, the code installed by users can change after the skill has been audited. A global npm installation may also execute package lifecycle scripts with the permissions available to the user's global npm environment.

The project history contains no evidence that the named package is currently malicious. The risk arises from the non-reproducible installation method and the resulting exposure to a future upstream package, account, or release compromise.

Attack Path

  1. An upstream maintainer account, publication pipeline, or package release is compromised, or an incompatible release is assigned to latest.
  2. The attacker publishes a modified package version under the expected package name.
  3. A user follows the README and executes npm install -g openclaw@latest.
  4. npm resolves the mutable tag to the compromised version.
  5. Malicious package files or lifecycle scripts execute with the permissions available during global installation.

Impact Assessment

Successful supply-chain compromise could result in arbitrary code execution under the installing user's account. A global installation may affect all projects using the command and can expose local configuration, API credentials, messaging data, and other user-accessible files.

Remediation
View remediation

Remediation Suggestions

  • Pin OpenClaw to an exact, reviewed version rather than @latest.
  • Provide an integrity hash, signed release verification procedure, or trusted lockfile.
  • Review package lifecycle scripts before recommending installation.
  • Avoid global installation where practical; use an isolated environment with minimum privileges.
  • Establish a controlled upgrade process that tests and reviews each new version before changing the documented pin.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:73
Finding

Chat-Routing Skill Includes Undisclosed Campaign Deployment and Pause Capabilities

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:73-95
Vulnerability Type: Undeclared expansion into consequential remote operations
Risk Level: High

Vulnerable Code Snippet:

markdown
### AI Growth Engine (AutoPilot) commands

When the user's message is about the **AI Growth Engine / AutoPilot** — e.g. "deploy autopilot", "turn on the healthcare autopilot", "what's my growth engine status", "is autopilot ready", "pause autopilot", "how are my campaigns doing" — do NOT send it to the default agent above. Instead route it to the Growth Engine assistant:

POST ${AI_SAAS_BASE_URL}/api/v1/drip-agent/chat
Authorization: Bearer ${AI_SAAS_API_KEY}
Content-Type: application/json

{
  "sessionId": "<the same sender_id>",
  "mode": "customer",
  "message": "<user message text>"
}

Parse `data.reply` and return it to the user. The response may also include `data.toolCalls` (a list of actions the assistant took, e.g. "Deployed autopilot …") — you can surface a short confirmation from these.

**Important:** deploying or pausing an autopilot is a real action. The assistant will ask the user to confirm the exact pipeline first — relay that question and only send a follow-up "yes" after the user actually confirms. If a deploy is blocked (e.g. a prerequisite is missing), relay the reason the assistant returns.

Technical Analysis

The package description and README primarily present the skill as a chatbot message-forwarding integration. The skill instructions additionally route selected natural-language messages to a separate assistant capable of deploying or pausing AutoPilot campaigns.

The instructions include a confirmation step, which reduces accidental activation, but authorization and confirmation are delegated to a remote conversational assistant. The skill does not define local role checks, structured action validation, pipeline ownership verification, replay protection, or an independen ...[truncated 1237 chars]

Remediation
View remediation

Remediation Suggestions

  • Disclose campaign deployment and pause capabilities prominently in README.md, package metadata, and installation documentation.
  • Move consequential Growth Engine operations into a separate, disabled-by-default skill or explicit feature flag.
  • Use an action-specific token that cannot access unrelated account resources.
  • Enforce server-side tenant, user, role, pipeline ownership, and action authorization checks.
  • Replace free-form affirmative responses with structured confirmations bound to the exact action, pipeline, tenant, and expiration time.
  • Require a second confirmation for high-impact operations and prevent replay of prior approvals.
  • Record immutable audit events identifying the requester, approved action, target pipeline, and result.
  • Do not rely solely on a remote language model to determine whether authorization or confirmation is valid.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · README.md (reported line 66)May include surrounding context.

md
| Command | Action |
|---|---|
| `/reset` | Clear conversation history for the current user |
| `/status` | Check if the AI SaaS chatbot is active |

## How It Works

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is designed to trigger on ANY inbound message from any connected channel and automatically forward the full message to an external SaaS endpoint. This creates a broad, implicit data exfiltration surface and can cause unintended handling of sensitive or unrelated conversations, especially because the skill is not user-invocable and appears to sit transparently in the message path.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 15)May include surrounding context.

md
### 1. Get your credentials from the AI SaaS portal

1. Open **Settings → API Keys** and create a key with **All** permissions. Copy the key.
2. Open the **Chatbots** page and copy the ID of the chatbot you want to route messages to.

You can also visit **Settings → OpenClaw** in the portal for a guided setup that generates the config for you.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions tell users to create an API key with 'All' permissions, which violates least-privilege principles and increases blast radius if the credential is leaked or misused. A broadly scoped key in a messaging bridge could allow unintended access to chatbot management or other backend capabilities beyond simple message routing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that all messages from connected channels are automatically forwarded to the AI SaaS backend, but it does not warn deployers to disclose this data flow to end users or consider privacy, consent, and retention implications. In a messaging integration context, this can cause unintentional transmission of sensitive personal, business, or regulated data to a third-party backend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly sends user message text plus a stable cross-message identifier derived from channel and user ID to an external API, but it provides no explicit user-facing privacy notice or consent mechanism. This can expose personal data, conversation contents, and persistent identifiers to a third party without transparency, which is especially risky across messaging platforms where users may not expect external processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.