Back to skill

Security audit

Deep Infra

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its DeepInfra routing purpose, but its setup guidance includes an unsafe API-key command-line pattern that could expose a user’s credential.

Review the auth setup before installing. Do not paste a real DeepInfra API key into a command-line argument; use a safer environment or secret-store flow, and avoid logging or saving the key. Install only if you are comfortable sending prompts to DeepInfra for inference and with local routing notes being kept under `~/deep-infra/`.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
auth-and-provider.md:27
Finding

API Key Exposed Through Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: auth-and-provider.md, lines 27-37
Vulnerability Type: API credential exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

bash
## OpenClaw CLI Setup

```bash
openclaw onboard --deepinfra-api-key <key>

Or set the environment variable directly:

bash
export DEEPINFRA_API_KEY="<your-deepinfra-api-key>"
text

### Technical Analysis

The onboarding example instructs users to supply a DeepInfra API key as a command-line argument. Secrets passed in this manner may be exposed through:

- Shell command history.
- Process argument inspection while the command is running.
- Terminal session recording.
- Operating-system audit logs.
- Endpoint monitoring and diagnostic telemetry.
- Support bundles that collect process invocation details.

This guidance conflicts with the Skill's stated objective of preventing secret leakage. Although the document also provides an environment-variable alternative, presenting the command-line method as the primary OpenClaw setup procedure may lead users to adopt the less secure option.

### Attack Path

1. A user copies the documented command and replaces the placeholder with a valid DeepInfra API key.
2. The complete command is stored in shell history, captured by telemetry, or temporarily exposed in the process argument list.
3. A local user, monitoring agent, log reader, or support-system operator obtains the exposed argument.
4. The attacker extracts the API key.
5. The attacker submits unauthorized DeepInfra API requests using the victim's account until the key is revoked or its account-side limits are reached.

### Impact Assessment

Successful exploitation grants the attacker the API permissions associated with the exposed DeepInfra key. Depending on account configuration, this may permit unauthorized model inference, consumption of the victim's usage quot
...[truncated 258 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the command-line argument example for supplying a real API key.
  2. Prefer retrieving the credential from DEEPINFRA_API_KEY without reproducing its value in generated commands, output, notes, or logs.
  3. If interactive onboarding is required, accept the key through a hidden terminal prompt or standard input rather than through process arguments.
  4. Add an explicit warning that users must not place API keys directly in shell commands or shell history.
  5. Ensure onboarding code never logs the credential and does not include it in error messages, process titles, or diagnostic output.
  6. Recommend restrictive access controls for any local credential store and provide key-rotation instructions for users who previously followed the unsafe example.

T09 · Insecure Skill Coding Practices

Note
Location
auth-and-provider.md:7
Finding

Authentication Verification Commands Do Not Authenticate

Content
View full analysis

Vulnerability Details

File Location: auth-and-provider.md, lines 7-16; duplicated as a health check in fallback-reliability.md, lines 27-33
Vulnerability Type: Incorrect authentication validation
Risk Level: Low

Vulnerable Code

From auth-and-provider.md:

markdown
## Verification Flow

1. Confirm `DEEPINFRA_API_KEY` is present in the environment.
2. Run a lightweight models request to confirm API availability.
3. Record only pass/fail and timestamp in memory.

## Minimal Request Pattern

```bash
curl -sS https://api.deepinfra.com/v1/openai/models | jq '.data | length'
text

The related health check in `fallback-reliability.md` uses the same unauthenticated pattern:

```markdown
## Quick Health Check

```bash
curl -sS https://api.deepinfra.com/v1/openai/models | jq '.data[0].id'

If this fails consistently, avoid changing routing policy until connectivity and auth are confirmed.

text

### Technical Analysis

The Skill requires authentication to be explicitly verified before routing changes are applied, but the documented verification requests do not send the `Authorization: Bearer` header. Checking whether `DEEPINFRA_API_KEY` exists only confirms that a variable is present; it does not establish that the key is valid, unexpired, unrevoked, or authorized for the intended API operation.

If the model-catalog endpoint permits an unauthenticated response, the commands can succeed regardless of the credential's validity. The resulting pass condition therefore verifies endpoint reachability and response shape, not authentication. In addition, `curl -sS` does not fail solely because an HTTP error status was returned, so a parseable error response could also produce misleading results depending on its structure.

### Attack Path

1. The environment contains an invalid, expired, revoked, truncated, or attacker-modified `DEEPINFRA_API_KEY`.
2. The Agent confirms only that the envi
...[truncated 1088 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the unauthenticated check with a minimal authenticated request:
bash
curl --fail --silent --show-error \
  -H "Authorization: Bearer $DEEPINFRA_API_KEY" \
  https://api.deepinfra.com/v1/openai/models |
  jq '.data | length'
  1. Check that DEEPINFRA_API_KEY is nonempty before issuing the request.
  2. Use --fail or --fail-with-body and explicitly validate the HTTP status so authorization failures cannot be recorded as successful checks.
  3. Validate the expected response schema instead of treating any parseable response as success.
  4. Ensure shell tracing is disabled and never print request headers or the expanded credential.
  5. Distinguish authentication checks from connectivity checks in logs and persistent memory.
  6. Update the duplicated health check in fallback-reliability.md so it either performs authenticated validation or is clearly labeled as a connectivity-only test.
  7. Add negative tests covering missing, malformed, expired, and revoked credentials before routing changes are finalized.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · cost-guardrails.md (reported line 5)May include surrounding context.

md
## Budget-First Operations

Set budget limits before scaling usage. DeepInfra generally offers competitive pricing for open-source models, but costs can still drift without guardrails.

| Control | Why it matters | Suggested baseline |
|---------|----------------|--------------------|

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
- Using same-family fallback chain only -> cascading failures during model-specific incidents.
- Ignoring token limits for long inputs -> truncated responses and hidden quality loss.
- Changing routing and budgets simultaneously -> unclear root cause when quality drops.
- Running without verification prompts -> broken routing detected only after user-facing failures.

## External Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Minimal Request Pattern

bash
curl -sS https://api.deepinfra.com/v1/openai/models | jq '.data | length'

Provider Wiring Checklist

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

Minimal Request Pattern

bash
curl -sS https://api.deepinfra.com/v1/openai/models | jq '.data | length'

Provider Wiring Checklist

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · auth-and-provider.md (reported line 16)May include surrounding context.

Minimal Request Pattern

bash
curl -sS https://api.deepinfra.com/v1/openai/models | jq '.data | length'

Provider Wiring Checklist

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · auth-and-provider.md (reported line 21)May include surrounding context.

Minimal Request Pattern

bash
curl -sS https://api.deepinfra.com/v1/openai/models | jq '.data | length'

Provider Wiring Checklist

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · fallback-reliability.md (reported line 30)May include surrounding context.

Minimal Request Pattern

bash
curl -sS https://api.deepinfra.com/v1/openai/models | jq '.data | length'

Provider Wiring Checklist

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation section leaves invocation criteria blank and undefined, which can cause the skill to activate in unintended contexts or fail open when routing decisions are needed. In an infrastructure/model-routing skill, ambiguous activation is risky because it may apply provider, auth, or fallback behavior to unrelated tasks without clear user intent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · memory-template.md (reported line 56)May include surrounding context.

md
|-------|---------|----------|
| `ongoing` | Context still evolving | Continue learning from real routing events |
| `complete` | Baseline policy is stable | Minimize setup questions and execute directly |
| `paused` | User paused setup prompts | Use existing policy without asking for new setup details |
| `never_ask` | User declined setup | Never request setup details again |

## Principles

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to persist user- and environment-specific notes in ~/deep-infra/memory.md without any requirement to disclose storage, obtain consent, define retention, or limit sensitive content. This creates a privacy and data-governance risk because configuration details, budget limits, incidents, and provider information may be stored unexpectedly and later exposed to other runs, tools, or users on the same system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file instructs users to verify DEEPINFRA_API_KEY and run a request against api.deepinfra.com, which affects privacy and external network behavior. While the document mentions zero secret leakage in notes, it does not explicitly warn that verification involves contacting a third-party service and using credentials from the environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.