Back to skill

Security audit

NEXUS Translate

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed paid translation skill that sends requested text to an external NEXUS API, with no evidence of hidden local access or persistence.

Install only if you trust NEXUS with the text you ask to translate and with the payment proof used for requests. Avoid sending secrets, regulated data, or proprietary text unless your organization allows that third-party processing, and be aware that non-sandbox use is priced per request.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 16)May include surrounding context.

Or manually copy the SKILL.md to your OpenClaw skills directory:

bash
cp SKILL.md ~/.openclaw/skills/nexus-translate/SKILL.md

Usage

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states the skill is 'automatically invoked' when a matching task is detected, but provides no concrete trigger boundaries, scoping rules, or user-consent requirements. In an agent ecosystem, ambiguous auto-invocation can cause sensitive user inputs to be routed to a paid external translation service unexpectedly, increasing the risk of unintended data disclosure and unauthorized spending.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The documented behavior sends user-provided input to an external host over the network for processing. For a translation skill this is functionally expected, but it still represents a real data-exfiltration risk if agents automatically forward sensitive prompts, credentials, proprietary text, or personal data to the third-party service without clear consent and policy controls.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

bash
# Step 1: Get the x402/MPP challenge
curl -X POST https://ai-service-hub-15.emergent.host/api/original-services/translate \
  -H "Content-Type: application/json" \
  -d '{"input": "your query here"}'
# Returns 402 + WWW-Authenticate: Payment header

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill explicitly instructs agents to transmit user-provided text and a payment proof header to an external third-party service. Even though this is the stated purpose of a translation skill, it still creates a real data exfiltration/privacy boundary because potentially sensitive input is sent off-platform to a remote API and processed by upstream LLMs. The context makes this somewhat expected, but the combination of arbitrary input forwarding, external model processing, and payment-related headers means the transmission should be treated as a genuine security-relevant behavior rather than a false positive.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

API Call

bash
curl -X POST https://ai-service-hub-15.emergent.host/api/original-services/translate \
  -H "Content-Type: application/json" \
  -H "X-Payment-Proof: $NEXUS_PAYMENT_PROOF" \
  -d '{"text": "Hello, how are you?", "target_language": "ja"}'

Static analysis

No suspicious patterns detected.