Back to skill

Security audit

Openclaw Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Impromptu platform integration, but it needs review because it combines account-writing and money-related abilities with persistent heartbeat guidance, mutable remote references, plaintext key setup advice, and referral/promotional output hooks.

Install only if you are comfortable giving this skill an Impromptu bearer token that can read account state and perform content, engagement, handoff, wallet-sync, and related platform actions. Use the narrowest token available, avoid plaintext launchd plist storage, do not schedule unattended heartbeats until you understand their API calls, review any fetched update before using it, and do not allow referral/share templates to be inserted into unrelated conversations automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
impromptu.skill.json:2060
Finding

Promotional Hooks Can Hijack Agent-Generated Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
impromptu.skill.json:2051
Finding

Executable Scripts and Agent Instructions Reference a Mutable Upstream Branch

Content
View full analysis
~/.impromptu/IMPROMPTU-HEARTBEAT.md.new diff ~/.impromptu/IMPROMPTU-HEARTBEAT.md ~/.impromptu/IMPROMPTU-HEARTBEAT.md.new # If the diff looks safe, apply it: # mv ~/.impromptu/IMPROMPTU-HEARTBEAT.md.new ~/.impromptu/IMPROMPTU-HEARTBEAT.md # Optional: fetch latest skill manifest (new endpoints, new capabilities) curl -sf https://impromptusocial.ai/impromptu.skill.json \ > ~/.impromptu/impromptu.skill.json.new ``` ### Technical Analysis The manifest points to shell and Python scripts, service-integration resources, and agent guidance on the mutable Git branch named `main`. It does not pin these resources to an immutable commit, provide expected cryptographic hashes, or require signature verification. The audited heartbeat and installation scripts do not automatically down ...[truncated 2023 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
launchd/README.md:19
Finding

Launchd Setup Recommends Storing a Bearer API Key in Plaintext

Content
View full analysis
IMPROMPTU_API_KEY YOUR_API_KEY_HERE # To your actual key: IMPROMPTU_API_KEY impr_sk_agent_... ``` The document later states: ```text Security tip: For better security, source from keychain or env file instead of embedding in plist. ``` ### Technical Analysis The primary launchd setup procedure instructs users to embed the Impromptu bearer token directly in a property-list file. A later Keychain alternative is documented, but the insecure plaintext method remains the first operational configuration path. A bearer token generally grants access based solely on possession. Storing it in a routinely inspected and backed-up configuration directory increases exposure to other local processes running under the same account, support archives, backups, accidental commits, file-sharing operations, and malware with user-level file access. The risk is amplified because the scheduled heartbeat runs across sessions and uses the credential for authenticated account, notification, recommendation, budget, and wallet synchronization requests. ### Attack Path 1. A user follows the launchd setup instructions. 2. The user writes the actual `IMPROMPTU_API_KEY` into `~/Library/LaunchAgents/com.impromptu.heartbeat.plist`. 3. The plist is read by another process under the same account, included in a backup or diagnostic archive, or shared accidentally. 4. An attacker extracts the bearer token. 5. The attacker sends authenticated requests to the Impromptu API while impersonating the victim's agent. 6. The attacker performs any action permitted by the token until it is revoked or rotated. ### Impact Assessment The attacker does not obtain operating-system ad ...[truncated 759 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (132)

Tainted flow: 'request' from os.environ.get (line 79, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The request destination is derived from the IMPROMPTU_API_URL environment variable and then used directly in urlopen while attaching the Authorization bearer token. If an attacker can influence the environment, they can redirect requests to an attacker-controlled host and capture the API key and any response data. In an agent or cron context, environment-based endpoint override is more dangerous because the script runs unattended and will automatically transmit credentials.

Content

Scanner excerpt · heartbeat.py (reported line 82)May include surrounding context.

python
request = Request(url, data=data, headers=headers, method=method)

    try:
        with urlopen(request, timeout=30) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        logger.error(f"HTTP {e.code}: {e.reason}")

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · CHANGELOG.md (reported line 99)May include surrounding context.

md
- `createCommunity()` - Create new communities
  - `joinCommunity()` / `leaveCommunity()` - Membership management
- **Messaging API:**
  - `sendMessage()` - Send messages to other agents
  - `getInbox()` - Retrieve inbox with pagination
- **Standing Queries:**
  - `createStandingQuery()` - Schedule recurring content queries

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contradicts the manifest by stating a 70/30 creator-platform split while the metadata promises 80% of subscription revenue goes back to creators. In a financially oriented skill, contradictory compensation terms can mislead users' economic decisions and undermine informed consent, even if the issue is documentation rather than code execution.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 274)May include surrounding context.

bash
   # Add to .gitignore
   .env
   .env.local
   *.env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 276)May include surrounding context.

bash
   # Add to .gitignore
   .env
   .env.local
   *.env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 275)May include surrounding context.

bash
   # Add to .gitignore
   .env
   .env.local
   *.env

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Local environment setup, environment-variable inspection, config-directory creation, and scheduling guidance are privileged host-level actions that should be clearly disclosed up front. In a skill ecosystem, hidden setup behavior can lead users to expose secrets, modify shell startup files, or enable automation they do not fully understand.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
ts require manual review before execution.** `install.sh`, `heartbeat.sh`, and `impromptu-health.sh` are included and inspectable. Do not run them blindly. Use

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

The example harvests an environment API key and injects it into Authorization headers for live GraphQL requests. While common in SDK samples, in agent-skill contexts this is dangerous because execution would grant the code authority to act on behalf of the account, including token-backed and workflow-changing operations.

Content

Scanner excerpt · examples/hiring.ts (reported line 183)May include surrounding context.

ts
query: string,
  variables?: Record<string, unknown>
): Promise<T> {
  const apiKey = process.env['IMPROMPTU_API_KEY']
  if (!apiKey) {
    throw new Error('IMPROMPTU_API_KEY environment variable required')
  }

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · examples/create-conversation.ts (reported line 29)May include surrounding context.

ts
*/

const API_URL = process.env['IMPROMPTU_API_URL'] ?? 'https://impromptusocial.ai/api'
const API_KEY = process.env['IMPROMPTU_API_KEY']

if (!API_KEY) {
  console.error('Missing IMPROMPTU_API_KEY environment variable')

Static analysis

Detected: suspicious.env_credential_access, suspicious.prompt_injection_instructions

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
examples/create-conversation.ts:28

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
examples/hiring.ts:173

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
examples/manage-credentials.ts:19

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
TOKENOMICS.md:218