Back to skill

Security audit

Research

Security checks for vulnerabilities and agentic risk

Overview

This research skill is coherent, but it needs Review because setup asks users to run an unverified remote installer and broadly persist an API key in shell startup files.

Review the setup before installing. Prefer a pinned or package-manager uv install instead of curl | sh, do not add the API key loader to ~/.bashrc, use a command-scoped environment variable or secret manager, avoid sudo unless you intentionally want system-wide installation, and assume research prompts and findings will be saved locally and may be sent to Parallel AI for deep research.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SETUP.md:62
Finding

Unverified Remote Installer Is Piped Directly into a Shell

Content
View full analysis

Vulnerability Details

File Location: SETUP.md:62
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code:

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

Technical Analysis

The setup instructions retrieve a mutable installation script from an external URL and pipe it directly into sh. The command does not pin a release, verify a cryptographic checksum or signature, preserve the script for inspection, or otherwise ensure that the executed content matches the content reviewed during this audit.

Although astral.sh is associated with the declared uv dependency, trust in the current domain does not eliminate the supply-chain risk. A compromised hosting account, upstream infrastructure, DNS or delivery path, or a future modification of the installer could cause arbitrary commands to execute. This behavior exceeds the minimum privilege necessary to install a dependency because a verified, version-pinned artifact could be used instead.

Attack Path

  1. An attacker compromises the remote installer, its hosting infrastructure, or another component of its delivery chain.
  2. The user follows the documented setup command.
  3. curl downloads the attacker-controlled response from the mutable URL.
  4. The pipe passes the response directly to sh without verification or an opportunity for inspection.
  5. The payload executes with all privileges available to the user running the setup command.
  6. The payload can access user-readable data, modify user-owned files, steal credentials, establish persistence, or retrieve additional payloads.

Impact Assessment

Successful exploitation provides arbitrary command execution under the installing user's account. The payload could read the Parallel AI API key and other user-accessible credentials, alter shell configuration, modify research documents, replace user-level executables, or create persist ...[truncated 202 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe network responses directly into a shell.
  • Pin uv to a reviewed release and obtain it through a trusted package manager or an official, versioned release artifact.
  • Download the artifact separately, using a command that fails on HTTP and transport errors.
  • Verify a publisher signature or a cryptographic checksum obtained through an independently authenticated channel before execution.
  • Preserve the downloaded file so the user can inspect it before running it.
  • Execute installation with ordinary user privileges and avoid recommending elevated execution unless it is strictly necessary.
  • Document the expected version, artifact URL, checksum, verification procedure, and installation destination.

T09 · Insecure Skill Coding Practices

Warning
Location
SETUP.md:26
Finding

API Key Is Persistently Exported to Every Future Shell Session

Content
View full analysis

Vulnerability Details

File Location: SETUP.md:26-35
Vulnerability Type: Overly broad credential persistence and unsafe environment-file parsing
Risk Level: Medium

Vulnerable Code:

bash
# Create secrets directory
mkdir -p ~/.secrets/parallel_ai

# Save your API key
echo "PARALLEL_API_KEY=your_key_here" > ~/.secrets/parallel_ai/.env
chmod 600 ~/.secrets/parallel_ai/.env

# Add to your shell profile (~/.bashrc or ~/.zshrc)
echo 'export $(cat ~/.secrets/parallel_ai/.env | xargs)' >> ~/.bashrc
source ~/.bashrc

Technical Analysis

The secret file is correctly restricted to mode 0600, which limits direct file access. However, the setup then permanently appends a generic environment-loading command to ~/.bashrc. Consequently, the API key is exported into every subsequent Bash session and inherited by unrelated child processes launched from those sessions.

The construction export $(cat ... | xargs) is also not a robust environment-file parser. xargs performs tokenization and quote processing, so whitespace, quoting, backslashes, or other unusual characters in a value may be transformed. The command is generic rather than restricted to the single expected variable. If additional entries are ever placed in the file, they will also be exported broadly.

Modifying the shell startup profile is unnecessary for the Skill's declared functionality. The credential only needs to be available when invoking parallel-research, so command-scoped loading or a dedicated credential manager would satisfy the requirement with less exposure. Repeating the documented setup also appends duplicate startup entries.

Attack Path

  1. The user saves the Parallel AI key in the documented environment file.
  2. The setup appends the generic export expression to ~/.bashrc.
  3. Every future interactive Bash session reads the file and exports its contents.
  4. Any unrelated, compromised, or untrusted process st ...[truncated 1147 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not append a generic secret-loading command to ~/.bashrc or another global shell startup file.
  • Load the key only for the command that needs it, or use an operating-system credential manager or dedicated secret-management service.
  • If a file must be used, retain mode 0600 and ensure the containing directory is accessible only to the user, such as with mode 0700.
  • Parse only the expected PARALLEL_API_KEY field using a strict format rather than cat | xargs.
  • Validate that the file contains exactly one supported variable and reject malformed input.
  • Avoid placing the secret directly in command-line arguments, where it may appear in shell history or process listings.
  • Document key rotation and revocation procedures for suspected exposure.
  • Remove previously appended duplicate startup entries and unset the key from unrelated active shell sessions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SETUP.md (reported line 31)May include surrounding context.

md
mkdir -p ~/.secrets/parallel_ai

# Save your API key
echo "PARALLEL_API_KEY=your_key_here" > ~/.secrets/parallel_ai/.env
chmod 600 ~/.secrets/parallel_ai/.env

# Add to your shell profile (~/.bashrc or ~/.zshrc)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SETUP.md (reported line 32)May include surrounding context.

md
mkdir -p ~/.secrets/parallel_ai

# Save your API key
echo "PARALLEL_API_KEY=your_key_here" > ~/.secrets/parallel_ai/.env
chmod 600 ~/.secrets/parallel_ai/.env

# Add to your shell profile (~/.bashrc or ~/.zshrc)

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Appending export $(cat ~/.secrets/parallel_ai/.env | xargs) to ~/.bashrc causes secrets to be loaded automatically into every future shell session using unsafe shell expansion. This broadens secret exposure to child processes and can mis-handle specially formatted values, increasing the chance of accidental disclosure or command parsing issues.

Content

Scanner excerpt · SETUP.md (reported line 35)May include surrounding context.

chmod 600 ~/.secrets/parallel_ai/.env

Add to your shell profile (~/.bashrc or ~/.zshrc)

echo 'export $(cat ~/.secrets/parallel_ai/.env | xargs)' >> ~/.bashrc source ~/.bashrc

text

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

Although this does not look like a deliberate backdoor, appending a command that loads secrets into ~/.bashrc creates persistent behavior affecting all future shell sessions and expands the exposure surface of the API key. The YARA classification overstates the threat, but the persistence combined with unsafe secret loading is still a real security concern.

Content

Scanner excerpt · SETUP.md (reported line 35)May include surrounding context.

esearch/scripts/parallel-research /usr/local/bin/parallel-research

text

**Verify it works:**
```bash
parallel-research --help

Set your API key:

bash
# Create secrets directory
mkdir -p ~/.secrets/parallel_ai

# Save your API key
echo "PARALLEL_API_KEY=your_key_here" > ~/.secrets/parallel_ai/.env
chmod 600 ~/.secrets/parallel_ai/.env

# Add to your shell profile (~/.bashrc or ~/.zshrc)
echo 'export $(cat ~/.secrets/parallel_ai/.env | xargs)' >> ~/.bashrc
source ~/.bashrc

2. Install export-pdf CLI

Symlink alongside parallel-research:

bash
ln -sf ~/.openclaw/skills/research/scripts/export-pdf ~/.local/bin/export-pdf

Dependencies

pandoc (required):

bash
# macOS
brew install pandoc

# Linux
sudo apt-get install pandoc

uv (required — handles PyMuPDF automatically):

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

The script uses uvx --with pymupdf so you don't need to manually install PyMuPDF or manage a venv.

Verif

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | sh pattern executes remote content directly in a shell, eliminating any opportunity for inspection and turning a content-fetch operation into immediate code execution. In setup documentation, this is especially dangerous because users are primed to copy-paste commands with elevated trust.

Content

Scanner excerpt · SETUP.md (reported line 62)May include surrounding context.

uv (required — handles PyMuPDF automatically):

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

The script uses uvx --with pymupdf so you don't need to manually install PyMuPDF or manage a venv.

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

The instruction to 'capture context' encourages persistent recording of why the research was performed, which can include sensitive user motivations, internal plans, or proprietary details. In a skill that stores markdown documents on disk, this increases the chance of unintended retention of confidential conversational context beyond the ephemeral session.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
- **Atomic findings** - One insight per bullet
- **Link everything** - Sources, docs, repos
- **Capture context** - Why did we look at this?
- **Note confidence** - Use qualifiers when uncertain
- **Date important findings** - Especially for fast-moving topics

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SETUP.md (reported line 13)May include surrounding context.

bash
# Option A: Symlink to ~/.local/bin (recommended, usually in PATH)
mkdir -p ~/.local/bin
ln -sf ~/.openclaw/skills/research/scripts/parallel-research ~/.local/bin/parallel-research

# Option B: Symlink to /usr/local/bin (system-wide, needs sudo)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 17)May include surrounding context.

ln -sf ~/.openclaw/skills/research/scripts/parallel-research ~/.local/bin/parallel-research

Option B: Symlink to /usr/local/bin (system-wide, needs sudo)

sudo ln -sf ~/.openclaw/skills/research/scripts/parallel-research /usr/local/bin/parallel-research

text

**Verify it works:**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 57)May include surrounding context.

ln -sf ~/.openclaw/skills/research/scripts/parallel-research ~/.local/bin/parallel-research

Option B: Symlink to /usr/local/bin (system-wide, needs sudo)

sudo ln -sf ~/.openclaw/skills/research/scripts/parallel-research /usr/local/bin/parallel-research

text

**Verify it works:**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SETUP.md (reported line 32)May include surrounding context.

md
# Save your API key
echo "PARALLEL_API_KEY=your_key_here" > ~/.secrets/parallel_ai/.env
chmod 600 ~/.secrets/parallel_ai/.env

# Add to your shell profile (~/.bashrc or ~/.zshrc)
echo 'export $(cat ~/.secrets/parallel_ai/.env | xargs)' >> ~/.bashrc

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions tell users to download and immediately execute a remote shell script via curl ... | sh without any integrity verification or warning. This creates a direct supply-chain execution path where compromise of the remote host, network, or script contents results in arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SETUP.md (reported line 81)May include surrounding context.

~/.openclaw/workspace/research/

text

Create it if needed:
```bash
mkdir -p ~/.openclaw/workspace/research

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger section activates on generic intents like researching a topic, exploring something, investigating options, or creating an investigation, without clear boundaries or exclusion conditions. These phrases are common in everyday collaboration and could match many normal conversations that do not specifically require this skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill explicitly persists research prompts and findings to a long-lived workspace directory, converting ephemeral conversation into durable files. If users include sensitive data in research questions or exploratory discussion, that information may be stored indefinitely and later exposed through local access, backups, or follow-on tooling.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- Research a topic, idea, or question
- Explore something before committing to building it
- Investigate options, patterns, or approaches
- Create a "research doc" or "investigation"
- Run deep async research on a complex topic

## Research Directory

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Commands such as "show doc", "summarize", "graduate", and "archive" are short, common phrases that may appear in unrelated contexts. Without namespace prefixes or context constraints, they are ambiguous as activation triggers.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Fetching an external script from the internet for execution introduces a supply-chain trust dependency on the remote source. Without checksum/signature verification or a manual review step, users are exposed to arbitrary code execution if the source is compromised or the URL serves unexpected content.

Content

Scanner excerpt · SETUP.md (reported line 62)May include surrounding context.

uv (required — handles PyMuPDF automatically):

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

The script uses uvx --with pymupdf so you don't need to manually install PyMuPDF or manage a venv.

Static analysis

No suspicious patterns detected.