Back to skill

Security audit

JobTread Agent

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate JobTread API helper, but it deserves Review because it enables broad live business-data changes, document access tokens, stored grant keys, and webhooks with limited safety scoping.

Install only if you intend to let OpenClaw operate JobTread through a grant key. Use the least-privilege grant available, avoid logging or sharing grant keys and PDF token URLs, test mutating queries on non-production data first, keep an inventory of created webhooks, and revoke or rotate the grant when automation is no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill is designed to send authenticated requests containing a grant key and business data to an external API endpoint. External transmission is expected for this integration, but it still creates real risk because secrets and potentially sensitive organizational data are sent off-host and the skill encourages broad operational use.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
# Skill: JobTread via Pave Query API

## Summary
This skill lets you operate JobTread entirely through openclaw using the Pave-based API at `https://api.jobtread.com/pave`. Every request is a single POST with a `query` object that mirrors GraphQL-style expressions, and you decide which fields you want back. With the right grant key, you can create and manage accounts (customers/vendors), jobs, documents, tasks, locations, custom fields, documents, and even subscribe to webhooks for live updates.

## Setup & Credentials
1. **Create a grant:** Login to https://app.jobtread.com/grants and create a new grant for automation. Copy the one-time `grantKey` (it begins with `grant_` and will only show once).

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill supports persistent capabilities through grant keys and webhook subscriptions, enabling ongoing access and continuous event delivery beyond a single session. In context, this persistence is functional rather than overtly malicious, but it meaningfully expands blast radius if credentials are stolen or webhook endpoints are abused.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
# Skill: JobTread via Pave Query API

## Summary
This skill lets you operate JobTread entirely through openclaw using the Pave-based API at `https://api.jobtread.com/pave`. Every request is a single POST with a `query` object that mirrors GraphQL-style expressions, and you decide which fields you want back. With the right grant key, you can create and manage accounts (customers/vendors), jobs, documents, tasks, locations, custom fields, documents, and even subscribe to webhooks for live updates.

## Setup & Credentials
1. **Create a grant:** Login to https://app.jobtread.com/grants and create a new grant for automation. Copy the one-time `grantKey` (it begins with `grant_` and will only show once).

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

bash
   mkdir -p ~/.config/jobtread
   echo "grant_xxx" > ~/.config/jobtread/grant_key
   chmod 600 ~/.config/jobtread/grant_key
  1. Keep it fresh: JobTread expires keys after 3 months of inactivity, so schedule a reminder (cron/heartbeat) to rotate or re-use the grant before expiration.
  2. Optional webhook secret: If you plan to receive webhooks, note your endpoint URL and save the webhook ID in the same folder so you can disable or inspect it later.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill describes generating signed PDF access tokens and appending them to a public URL path, enabling external access to document content. While this is a normal feature, exposing tokenized document URLs can leak sensitive files if tokens are logged, shared, or mishandled.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

}

text
- You can also set `notify`, `timeZone`, or `viaUserId` inside `$` when you need to suppress notifications or scope results.
- For signed queries (PDF tokens, pre-signed data), call `pdfToken: { _: signQuery, $: { query: {...} } }` and append the token to `https://api.jobtread.com/t/`.

## API Basics & Request Flow
- All requests go to `POST https://api.jobtread.com/pave` with `Content-Type: application/json`.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill instructs users to POST all requests, including grant-key-authenticated queries, to an external API. This is inherent to the integration, but the absence of stronger safety guidance around secret exposure, request logging, and data minimization makes the transmission more dangerous in operational use.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

  • For signed queries (PDF tokens, pre-signed data), call pdfToken: { _: signQuery, $: { query: {...} } } and append the token to https://api.jobtread.com/t/.

API Basics & Request Flow

  • All requests go to POST https://api.jobtread.com/pave with Content-Type: application/json.
  • Structure:
    json
    {
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The documented PDF token flow creates externally consumable links to JobTread documents, which can expose invoices or other records outside the local environment. If those links are pasted into chats, logs, browser history, or monitoring systems, unauthorized parties may gain access to sensitive business documents.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

sum: priceWithTax withValues: {}

text
- Get document PDF token (append to `https://api.jobtread.com/t/{{token}}`):
```yaml
pdfToken:
  _: signQuery

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly documents data-modifying operations such as creating accounts, updating records, and deleting webhooks, but it does not prominently warn the operator that these actions can alter production data or be difficult to reverse. In an agent-driven context, this increases the chance of accidental destructive actions, especially when reusable automations or copy/paste snippets are encouraged.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.