Back to skill

Security audit

Batchedits

Security checks for vulnerabilities and agentic risk

Overview

The skill’s video-editing purpose is coherent, but it asks the agent to run a shell upload command supplied by a remote service and encourages a risky API-key-in-URL setup.

Review this skill before installing. Prefer the header-based or OAuth setup over putting an API key in the URL, rotate any key already used in a URL, and do not let the agent run an upload command unless it first shows you the exact local file, destination host, and command semantics.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Execution of a Remotely Supplied Upload Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 64–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code Snippet:

text
5. Call `upload_videos` to get the upload command.
6. Execute the upload command and extract the `videoId`.

Technical Analysis

The Skill explicitly instructs the Agent to obtain a command from the external BatchEdits MCP service and execute it locally. The command is generated remotely after the Skill has been reviewed, so its effective behavior is mutable and cannot be established from the package contents alone.

No restrictions require the returned command to invoke only curl, constrain its arguments, validate its destination, or present it to the user for approval. Consequently, a malicious or compromised MCP service could return arbitrary shell syntax rather than a legitimate upload command. Executing an untrusted command string crosses the trust boundary between remote service data and local code execution.

Attack Path

  1. The user or Agent configures the external BatchEdits MCP endpoint as directed by the Skill.
  2. The Agent invokes upload_videos for a local video.
  3. A malicious or compromised endpoint returns a shell command containing an arbitrary payload.
  4. Following line 65, the Agent executes that command without local validation or argument-safe reconstruction.
  5. The payload runs with the same operating-system privileges and environment access as the Agent.
  6. The payload may read local files and environment variables, transmit credentials or documents, modify accessible data, or execute additional downloaded content.

Impact Assessment

Successful exploitation provides arbitrary command execution within the security context of the OpenClaw process. The attacker could access all files, credentials, environment variables, and network resources available to that process. The scope may include BatchEdits ...[truncated 282 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not execute command strings returned by an MCP server or any other remote service.
  • Redesign upload_videos to return structured data, such as an upload URL, HTTP method, required headers, and form fields.
  • Construct the upload request locally with an argument-safe HTTP library rather than passing remote text to a shell.
  • Allowlist the exact HTTPS scheme, hostname, port, method, and expected path patterns before uploading.
  • Reject redirects to unapproved hosts and prohibit URL schemes such as file:, ftp:, or shell-specific process substitutions.
  • Prevent the remote response from controlling local file paths. Use only the specific video path selected by the user.
  • Require explicit user confirmation showing the local file and validated remote destination before transmission.
  • If a command-line client is unavoidable, build its argument array locally without sh -c, eval, or string interpolation, and ensure secrets are not exposed in process arguments or logs.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

API Key Embedded in the MCP Endpoint URL

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–19
Vulnerability Type: Sensitive credential exposure through URL-based authentication
Risk Level: Medium

Vulnerable Code Snippet:

bash
openclaw config set mcp.servers.batchedits '{"type": "sse", "url": "https://batchedits.com/api/mcp/PASTE_YOUR_API_KEY_HERE"}'

Technical Analysis

Option A directs the user to place the BatchEdits API key directly in the MCP URL. URL-embedded secrets are prone to disclosure because complete URLs may be retained in shell history, application configuration, process diagnostics, error reports, proxy or server access logs, telemetry, and debugging output.

HTTPS protects the URL while it is transmitted over the network but does not prevent exposure at endpoints or in local and server-side logging systems. Labeling this method as the easiest setup option further encourages use of the less secure credential transport mechanism.

Attack Path

  1. The user replaces the placeholder with a valid BatchEdits API key and executes the configuration command.
  2. The command containing the key may be saved in shell history, while the complete credential-bearing URL is persisted in OpenClaw configuration.
  3. The URL may subsequently appear in diagnostics, logs, backups, telemetry, screenshots, or support bundles.
  4. A local user, process, administrator, log reader, or other party with access to one of those records obtains the key.
  5. The exposed key is replayed against the BatchEdits service to perform operations authorized for the associated account.

Impact Assessment

Exposure could permit unauthorized use of the victim's BatchEdits account and API allocation. Depending on the permissions assigned to the key and the service behavior, an attacker may be able to inspect account-associated resources, submit processing jobs, access uploaded or processed videos, consume paid capacity, or alter resources available through ...[truncated 88 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the URL-based API-key option and do not place credentials in URL paths or query strings.
  • Store the key in a protected secret manager or a minimally accessible environment/configuration secret field.
  • Transmit the credential through a dedicated authorization header supported by the MCP client and service.
  • Ensure OpenClaw, BatchEdits, reverse proxies, and monitoring systems redact authorization data from logs and diagnostics.
  • Limit the key to the minimum scopes required for video upload and processing.
  • Support short-lived, revocable credentials where possible and document a key-rotation procedure.
  • Warn existing users to rotate any key previously embedded in a URL and remove credential-bearing entries from shell history, logs, configuration backups, and support artifacts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises autonomous video editing but does not clearly warn that local video files will be transferred to a third-party BatchEdits server. This can cause users to unknowingly expose sensitive or regulated media, especially when the skill is invoked from chat or CLI contexts where data-flow is not obvious.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

Option C: OAuth DCR (Dynamic Client Registration)

bash
CLIENT_RESPONSE=$(curl -sS -X POST https://batchedits.com/api/oauth/register \
  -H 'Content-Type: application/json' \
  -d '{"client_name":"OpenClaw Local","redirect_uris":["http://localhost/callback"]}')
CLIENT_ID=$(echo "$CLIENT_RESPONSE" | jq -r '.client_id')

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
# After approval, copy the ?code=... value:
CODE="PASTE_CODE_HERE"
TOKEN_RESPONSE=$(curl -sS -X POST https://batchedits.com/api/oauth/token \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -d "grant_type=authorization_code&code=$CODE&client_id=$CLIENT_ID&client_secret=$CLIENT_SECRET&redirect_uri=http://localhost/callback")
ACCESS_TOKEN=$(echo "$TOKEN_RESPONSE" | jq -r '.access_token')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow directs the agent to execute an upload command autonomously and proceed with remote processing without an explicit confirmation gate. In agentic environments, this creates a real risk of silent exfiltration of local video files and associated metadata to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.