Back to skill

Security audit

Shodan Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Shodan wrapper, but it should be reviewed carefully because it enables agent-driven reconnaissance, active scans, streaming, and exploit searches without clear authorization guardrails.

Install only if you intend to give an agent Shodan-powered reconnaissance authority. Use it only on assets you own or are explicitly authorized to assess, use a dedicated low-privilege Shodan API key, avoid shared machines, prefer a pinned dependency install in a virtual environment, and require explicit user confirmation before active scans, alert creation, exploit searches, or realtime streaming.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Shodan Dependency

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:17-20
  • README.md:55-61
  • README.md:117-123

Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium
Classification: T08: Insecure Dependencies

Vulnerable Code

SKILL.md:17-20:

markdown
1.  **Install dependencies**:
    ```bash
    pip install shodan
    ```

README.md:55-61:

markdown
#### 2. Install Dependencies

Install the required Python library:

```bash
pip3 install shodan
text

`README.md:117-123`:

```markdown
#### 2. 安装依赖

安装必要的 Python 库:

```bash
pip3 install shodan
text

### Technical Analysis

The installation instructions retrieve the latest available `shodan` package and its transitive dependencies without specifying reviewed versions or validating package hashes. The project does not provide a version-pinned requirements file or lockfile.

Consequently, the code installed by users can differ from the code available when this skill was audited. If the upstream package, one of its dependencies, a maintainer account, or package-index resolution is compromised, installation may introduce arbitrary code into the skill's runtime environment.

This is a supply-chain weakness rather than evidence that the current `shodan` package is malicious. The audited skill itself contains no remote payload loader, persistence mechanism, obfuscated payload, or unrelated credential-exfiltration logic.

### Attack Path

1. An attacker compromises a future release of `shodan`, one of its transitive dependencies, or an associated package-publishing account.
2. A user follows the documented `pip install shodan` or `pip3 install shodan` instruction.
3. The package manager resolves and installs the attacker-controlled release because no exact versions or integrity hashes are enforced.
4. Malicious installation hooks or imported runtime code execute with the privileges 
...[truncated 941 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin shodan and every transitive dependency to reviewed versions in a dedicated requirements file.

  2. Generate and verify cryptographic hashes for all distributions. For example:

    text
    shodan==REVIEWED_VERSION --hash=sha256:VERIFIED_HASH
    
  3. Install dependencies with hash enforcement:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Generate the fully resolved, hash-locked file using a dependency-locking tool such as pip-compile --generate-hashes, then commit it to the project.

  5. Install the dependencies in an isolated virtual environment rather than the user's global Python environment.

  6. Use a trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.

  7. Add automated dependency scanning and a controlled review process before updating locked versions.

  8. Update both SKILL.md and README.md so every installation example uses the same locked dependency workflow.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/shodan_skill.py (reported line 8)May include surrounding context.

python
import os
import argparse

# Try to get API key from environment or config file
API_KEY = os.environ.get('SHODAN_API_KEY')
CONFIG_FILE = os.path.expanduser('~/.config/shodan/api_key')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly promotes network reconnaissance, vulnerability scanning, real-time monitoring, and exploit search, but provides no warning about authorization, legality, privacy, or safe-use boundaries. In an agent skill context, this omission increases the chance that an autonomous or semi-autonomous system will perform intrusive or abusive actions against third-party targets without operator awareness.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

Clone this repository into your OpenClaw skills directory (usually ~/.openclaw/skills/):

bash
mkdir -p ~/.openclaw/skills
git clone https://github.com/liuweitao/shodan-skill.git ~/.openclaw/skills/shodan-skill

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example prompts directly encourage scanning IPs, monitoring subnets, searching for vulnerable systems, and streaming real-time data without any accompanying authorization or ethics warning. Because these are copyable instructions for AI agents, they lower the barrier to misuse and may normalize unauthorized reconnaissance or surveillance.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill invokes local Python scripts and explicitly requires python3/pip, but the manifest does not declare any tool scope or permissions boundaries despite capabilities indicating environment and file access. In an agent system, this weakens least-privilege controls and can let the skill execute with broader access than users or reviewers expect, increasing the blast radius if the script is modified or abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The scan command directly invokes Shodan's on-demand scan API on user-supplied IPs/CIDRs without any warning, confirmation, or policy gate. Because this triggers an external active operation rather than a passive lookup, it can cause unauthorized scanning requests, compliance issues, or accidental targeting of third-party networks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description says it covers search, scan, alerts, and DNS, but the code also exposes exploit-search functionality. This expands the capability surface beyond what a user or reviewer would reasonably expect, undermining informed consent and enabling higher-risk reconnaissance workflows without explicit disclosure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest omits realtime streaming, but the code provides access to Shodan streaming APIs, including banners and alert-based streams. Undisclosed streaming can continuously ingest external data and materially changes the operational and privacy risk profile of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The setup instructions tell the user to run 'shodan init <YOUR_API_KEY>', which stores the Shodan API key locally, but the skill does not warn about local credential persistence. This can lead to accidental exposure through shared machines, backups, shell history, or other local tooling, especially in agent-driven environments where users may assume secrets are handled ephemerally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The manifest frames the skill as Shodan API interactions, but does not mention credential discovery from local environment or filesystem sources. While common for CLI tooling, this is still an additional local-access capability beyond the manifest's functional description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.