Back to skill

Security audit

Pocket AI Integration

Security checks for vulnerabilities and agentic risk

Overview

This skill performs its stated Pocket AI integration, but it handles highly sensitive recordings and profiles while making conflicting privacy claims about external data transfer.

Install only if you are comfortable letting this skill query Pocket AI's remote API with your bearer token and return sensitive transcript, recording, audio, and profile-derived data. Review Pocket AI's privacy, retention, regional storage, and consent requirements first, especially for legal, HR, client, health, or confidential business conversations. Protect the local API key, avoid sending raw transcripts or sensitive summaries to shared channels, and fix the shell helper's JSON escaping before using it in automation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
search.sh:5
Finding

Unsafe JSON Construction from Command-Line Input

Content
View full analysis

Vulnerability Details

File Location: search.sh:5-11
Vulnerability Type: Improper escaping of user-controlled data in a JSON request body
Risk Level: Medium

bash
QUERY="${1:-meeting}"

curl -s -X POST \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"query\": \"$QUERY\"}" \
  "https://public.heypocketai.com/api/v1/public/search" | jq '.'

Technical Analysis

The script interpolates the user-controlled QUERY value directly into a JSON string without applying JSON escaping. A query containing quotation marks, backslashes, control characters, or JSON syntax can terminate the intended string and modify the structure of the outbound request body.

For example, an argument resembling the following can introduce an additional JSON property:

text
test", "additionalField": "attacker-controlled

This flaw is request-body injection rather than shell command injection. Shell syntax contained inside the expanded variable is not evaluated again by Bash, so the reviewed code does not provide direct operating-system command execution. Nevertheless, the request can be malformed or reshaped by anyone who controls the script argument.

Attack Path

  1. An attacker gains control over, or influences, the value passed as the first argument to search.sh.
  2. The script stores that value in QUERY.
  3. The value is inserted verbatim between JSON quotation marks.
  4. Embedded JSON delimiters terminate or alter the intended query field.
  5. The resulting malformed or attacker-shaped request is authenticated with the victim's Pocket AI API key and sent to the Pocket AI service.
  6. The remote API may reject the request or process attacker-supplied fields, depending on its schema and validation behavior.

Impact Assessment

The attacker can corrupt or manipulate the authenticated JSON request generated by this helper. The immediate scope is limited to ...[truncated 465 chars]

Remediation
View remediation

Remediation Suggestions

Construct the request with a JSON-aware serializer rather than string interpolation. For example:

bash
#!/bin/bash
set -euo pipefail

API_KEY=$(cat ~/.config/pocket-ai/api_key)
QUERY="${1:-meeting}"

jq -n --arg query "$QUERY" '{query: $query}' |
  curl --fail --silent --show-error -X POST \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    --data-binary @- \
    "https://public.heypocketai.com/api/v1/public/search" |
  jq '.'

This ensures that quotation marks, backslashes, newlines, and other special characters are encoded correctly. Additionally:

  • Validate acceptable query length before submission.
  • Use --fail --silent --show-error so HTTP failures are visible.
  • Enable set -euo pipefail to prevent silent continuation after errors.
  • Add automated tests covering quotation marks, backslashes, Unicode, and newline characters.

other

Note
Location
README.md:115
Finding

Misleading Privacy Statement About External Data Transmission

Content
View full analysis

Vulnerability Details

File Location: README.md:115-120
Vulnerability Type: Inaccurate security and privacy documentation
Risk Level: Low

markdown
## Privacy & Security

- All recordings are encrypted end-to-end
- API key stays on your local machine
- No data leaves your infrastructure
- Pocket AI stores data on US servers

The implementation contradicts the claim that the API key stays on the local machine and that no data leaves the user's infrastructure. It sends both the bearer credential and user-provided search queries to an external Pocket AI endpoint:

python
self.session.headers.update({
    "Authorization": f"Bearer {self.api_key}",
    "Content-Type": "application/json"
})

response = self.session.post(
    f"{self.BASE_URL}/public/search",
    json={"query": query}
)

Technical Analysis

A bearer token must be transmitted to the remote API for authentication, and each search term is sent in the HTTPS request body. Responses can contain profile insights, transcript-derived memories, recording metadata, and action items. Thus, the integration necessarily transfers sensitive data across the user's infrastructure boundary.

HTTPS protects data in transit but does not mean that the data remains local. The statement that Pocket AI stores data on US servers also directly conflicts with the absolute assertion that no data leaves the user's infrastructure.

Attack Path

  1. A user relies on the README's assertion that credentials and data remain local.
  2. The user submits a sensitive query containing names, legal matters, business strategy, health information, or other confidential context.
  3. The client sends the query and bearer token over HTTPS to public.heypocketai.com.
  4. The service processes the query and returns potentially sensitive transcript-derived information.
  5. The CLI may print that information to standard output, where it can be captured by ...[truncated 793 chars]
Remediation
View remediation

Remediation Suggestions

Replace the absolute privacy claims with an accurate data-flow disclosure. For example:

markdown
## Privacy & Security

- The API key is stored locally but is transmitted over HTTPS to Pocket AI as a bearer credential for each API request.
- Search queries are transmitted to and processed by Pocket AI.
- API responses may contain sensitive transcript excerpts, profile insights, recording metadata, and action items.
- Pocket AI stores relevant service data on US servers; consult Pocket AI's current privacy and retention documentation.
- Command-line output may be recorded by terminal logs or downstream automation.
- Protect the local API-key file with permissions such as `chmod 600`.

The documentation should also identify:

  • The external service hostname.
  • Categories of transmitted and returned data.
  • Applicable retention, deletion, and regional-storage policies.
  • Whether end-to-end encryption remains applicable while server-side semantic search is performed.
  • The risk of printing transcript and profile content to standard output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README makes a materially misleading privacy assurance: it claims that no data leaves the user's infrastructure while also stating Pocket AI stores data on US servers and the integration performs semantic search and transcript retrieval against that service. For a tool handling sensitive recordings, this can cause users to expose confidential or regulated data under false assumptions about data locality and third-party processing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples explicitly promote inference of a user's mental state, priorities, frustrations, and overload signals from personal data. This is profiling of sensitive behavioral/contextual information without any declared necessity, safeguards, or user-consent framing, making it materially more dangerous in an agent skill that may operationalize such inferences.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The capability 'Dynamic user profile from conversations' indicates behavioral or personal profiling derived from recorded speech, but the manifest provides no explicit disclosure, consent language, or safeguards. In a skill targeted at attorneys, executives, and consultants, such profiling can expose highly sensitive personal, business, or privileged information and creates elevated privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes broad search across recordings, action-item extraction, and profile-building from conversations without warning about consent, confidentiality, wiretap/recording laws, or workplace privacy constraints. In contexts like legal, executive, and personnel discussions, missing these warnings increases the likelihood of unlawful or unsafe collection and processing of highly sensitive speech data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 66)May include surrounding context.

  1. Get your API key from Pocket AI app → Settings → API
  2. Store the key:
    bash
    mkdir -p ~/.config/pocket-ai
    echo "pk_your_key_here" > ~/.config/pocket-ai/api_key
    chmod 600 ~/.config/pocket-ai/api_key
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 68)May include surrounding context.

bash
   mkdir -p ~/.config/pocket-ai
   echo "pk_your_key_here" > ~/.config/pocket-ai/api_key
   chmod 600 ~/.config/pocket-ai/api_key
  1. Copy skill files to your OpenClaw workspace:
    bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The privacy section gives strong reassuring statements while downplaying key risk factors, including storage on US servers and the sensitivity of recorded meetings, legal calls, and internal conversations. This can mislead users about cross-border transfer, third-party access, and regulatory exposure when handling personal, privileged, or corporate-confidential data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Search across ALL recordings by meaning, not just keywords.

bash
curl -s -X POST \
  -H "Authorization: Bearer $(cat ~/.config/pocket-ai/api_key)" \
  -H "Content-Type: application/json" \
  -d '{"query": "your company manufacturing decisions"}' \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The integration guidance encourages using meeting transcripts and inferred insights to drive scheduling, tasking, and operations-channel posting, but it does not place strong guardrails on minimizing, redacting, or restricting highly sensitive content before reuse. Because the underlying data source is recordings of calls, meetings, and personal thoughts, downstream sharing can easily expose confidential business, personal, or regulated information to other systems or audiences.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example explicitly reads an API key from a local config file and uses it in a shell command, normalizing direct credential access in documentation without any justification or safety guidance. Even as an example, this encourages patterns that expose secrets to local shell history, process inspection, or misuse by downstream automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation combines local secret retrieval with authenticated transmission of meeting and profile-related data to a remote API, but includes no privacy notice, credential-handling warning, or safe operational guidance. This omission increases the chance that users will copy-paste insecure patterns and expose sensitive personal or organizational information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This command performs authenticated external transmission to a public API endpoint, carrying a query intended to retrieve action items from user memories. While the transmission appears to be the product's intended function rather than overtly malicious behavior, it still exposes sensitive work data to a remote service and is therefore security-relevant.

Content

Scanner excerpt · examples.md (reported line 8)May include surrounding context.

1. What action items do I have?

bash
API_KEY=$(cat ~/.config/pocket-ai/api_key)
curl -s -X POST -H "Authorization: Bearer $API_KEY" -H "Content-Type: application/json" \
  -d '{"query": "action items tasks todo follow up"}' \
  "https://public.heypocketai.com/api/v1/public/search" | \
  python3 -c "import sys,json; d=json.load(sys.stdin); [print(f'• {l.split(\"Action item:\")[1].strip()}') for m in d.get('data',{}).get('relevantMemories',[]) for l in m.get('content','').split('\n') if 'Action item:' in l]"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These examples send authenticated requests to an external service using queries over potentially sensitive memory data, but the documentation provides no stated purpose, consent model, or data-handling boundary. In a skill context, demonstrating remote retrieval against a public endpoint can facilitate unnecessary external data access and normalization of broad authenticated searches.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example sends an authenticated search about company discussions and decisions to an external endpoint, which can involve confidential business information. In documentation without contextual safeguards, it normalizes externalizing internal business context and may lead users to share sensitive organizational data more broadly than intended.

Content

Scanner excerpt · examples.md (reported line 16)May include surrounding context.

2. What did I discuss about your company?

bash
curl -s -X POST -H "Authorization: Bearer $API_KEY" -H "Content-Type: application/json" \
  -d '{"query": "your company manufacturing team decisions"}' \
  "https://public.heypocketai.com/api/v1/public/search"

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This external query targets conversations with a named individual and company, demonstrating person-specific retrieval against a remote service. That makes the example more dangerous because it models lookup of identifiable interpersonal data without privacy framing, increasing the risk of unauthorized profiling or disclosure.

Content

Scanner excerpt · examples.md (reported line 31)May include surrounding context.

4. Find conversations with a specific person

bash
curl -s -X POST -H "Authorization: Bearer $API_KEY" -H "Content-Type: application/json" \
  -d '{"query": "conversations with Dylan Acquisition.com"}' \
  "https://public.heypocketai.com/api/v1/public/search"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest advertises transcription, semantic search, meeting context awareness, and conversation-derived intelligence, all of which imply processing highly sensitive voice and meeting data. Presenting these capabilities without any explicit privacy notice, consent expectations, retention guidance, or sensitive-data handling disclosure can mislead users and encourage deployment in contexts involving confidential, legal, or personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The client sends user-provided queries to a remote Pocket AI service, and later methods retrieve and expose recordings, profile insights, and memories derived from potentially sensitive meeting transcripts. Although the module docstring describes functionality, there is no explicit warning, confirmation, or privacy disclosure that user queries and related data are being sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script accesses a sensitive credential from ~/.config/pocket-ai/api_key and immediately uses it in a network request. There is no confirmation prompt, visible logging, or explanatory warning in the script comments indicating that credentials will be read and transmitted to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · search.sh (reported line 8)May include surrounding context.

sh
API_KEY=$(cat ~/.config/pocket-ai/api_key)
QUERY="${1:-meeting}"

curl -s -X POST \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"query\": \"$QUERY\"}" \

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The installation instructions tell users to place an API key in a local file but do not clearly label it as a sensitive credential or warn against sharing, committing, or exposing that file. While the example does use restrictive permissions, the documentation still omits basic operational guidance that would reduce accidental credential leakage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.