Back to skill

Security audit

Agent Kanban

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real OpenClaw monitoring dashboard, but it exposes sensitive agent data too broadly and includes unsafe credential handling.

Review carefully before installing. Do not expose this dashboard on a network as shipped. Remove and rotate the embedded Gateway token, bind the server to localhost, add authentication and per-agent authorization, restrict CORS, avoid displaying raw histories/files by default, and replace remote scripts/avatar calls with local assets before use with sensitive agents.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
assets/agent-kanban/server.js:65
Finding

Unauthenticated Network Exposure of Sensitive Agent Data

Content
View full analysis
{ res.header('Access-Control-Allow-Origin', '*'); res.header('Access-Control-Allow-Methods', 'GET, POST, OPTIONS'); res.header('Access-Control-Allow-Headers', 'Content-Type'); if (req.method === 'OPTIONS') return res.sendStatus(200); next(); }); ``` ```javascript // assets/agent-kanban/server.js:228-259 app.get('/api/sessions', async (req, res) => { try { const result = await gatewayInvoke('sessions_list', {}); const data = parseSessionsList(result); for (const s of data.sessions) { s.jsonlSizeKB = getAgentJsonlSize(s.agentId); } res.json(data); } catch (err) { console.error('Failed to get sessions:', err); res.status(500).json({ error: err.message }); } }); app.get('/api/sessions/:key/history', async (req, res) => { try { const sessionKey = decodeURIComponent(req.params.key); const result = await gatewayInvoke('sessions_history', { sessionKey, limit: 100 }); const data = parseSessionHistory(result); res.json(data); } catch (err) { console.error('Failed to get session history:', err); res.status(500).json({ error: err.message }); } }); ``` ```javascript // assets/agent-kanban/server.js:262-289 app.get('/api/agents/:agentId/files', async (req, res) => { try { const agentId = decodeURIComponent(req.params.agentId); const workspaceDir = path.join(OPENCLAW_HOME, `workspace-${agentId}`); const files = {}; const fileNames = ['OKR.md', 'SOUL.md', 'HEARTBEAT.md']; for (const fileName of fileNames) { ...[truncated 2878 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
assets/agent-kanban/server.js:262
Finding

Path Traversal in Agent Workspace File Endpoint

Content
View full analysis
{ try { const agentId = decodeURIComponent(req.params.agentId); const workspaceDir = path.join(OPENCLAW_HOME, `workspace-${agentId}`); const files = {}; const fileNames = ['OKR.md', 'SOUL.md', 'HEARTBEAT.md']; for (const fileName of fileNames) { const filePath = path.join(workspaceDir, fileName); if (fs.existsSync(filePath)) { const content = fs.readFileSync(filePath, 'utf8'); files[fileName] = { exists: true, content: content, lines: content.split('\n').length, size: Math.round(content.length / 1024) + 'KB' }; } else { files[fileName] = { exists: false, content: '', lines: 0, size: '0KB' }; } } res.json({ agentId, files }); } catch (err) { console.error('Failed to get agent files:', err); res.status(500).json({ error: err.message }); } }); ``` ### Technical Analysis The `agentId` route parameter is decoded and interpolated directly into a filesystem path. The code does not validate the identifier, resolve it against an approved workspace list, or verify that the final canonical path remains inside the intended directory. An identifier containing path separators and `..` components can cause `path.join()` to normalize the path outside the intended `workspace-{agentId}` location. The fixed file-name allowlist limits reads to files named `OKR.md`, `SOUL.md`, or `HEARTBEAT.md`, but it does not ensure those files belong to the requested Agent. The explicit `decodeURIComponent()` may also apply decoding to a value already decoded by the routing framework, increasing ambiguity around encoded ...[truncated 1115 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/agent-kanban/config.js:32
Finding

Hard-Coded OpenClaw Gateway Bearer Token

Content
View full analysis
Remediation
View remediation

other

Warning
Location
assets/agent-kanban/public/index.html:433
Finding

Disclosure of Agent Session Identifiers to External Avatar Provider

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
assets/agent-kanban/public/index.html:411
Finding

Unpinned Third-Party JavaScript Executed Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis The dashboard executes JavaScript supplied at runtime by an external package mirror. The URLs use a broad React 18 path rather than an exact immutable release, and the tags do not include Subresource Integrity hashes. If the mirror, its DNS path, its hosting account, or the referenced content is compromised or modified, attacker-controlled JavaScript will execute under the dashboard's origin. Same-origin execution is particularly sensitive here because the frontend can call APIs that return Agent sessions, conversation history, and workspace files. The package dependency also uses the range `"express": "^4.18.2"` and no lockfile was present in the supplied directory structure. This reduces reproducibility, although no malicious Express package was identified during this static review. ### Attack Path 1. An attacker compromises the external script source or causes the referenced resource to serve modified JavaScript. 2. An operator loads or refreshes the dashboard. 3. The browser downloads and executes the modified script because no integrity hash is enforced. 4. The malicious script calls the same-origin `/api/sessions`, history, and Agent file endpoints. 5. It transmits the returned sensitive data to an attacker-controlled destination or alters the dashboard interface. 6. The compromise persists for as long as the remote source continues serving the malicious content. ### Impact Assessment Compromised third-party JavaScript would gain the privileges of dashboard-origin code. It could read all data exposed by the backen ...[truncated 295 chars]
Remediation
View remediation
``` 4. Add a strict Content Security Policy that limits `script-src`, prohibits unapproved remote scripts, and avoids `unsafe-eval`. 5. Use automated dependency scanning and controlled update review. 6. Verify package provenance and avoid unnecessary third-party mirrors for executable assets. 7. Serve the application over trusted HTTPS whenever it is accessed beyond loopback. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The dashboard is described as monitoring status and session sizes, but it also reads and returns contents of workspace files and session history, which may contain sensitive prompts, secrets, or operational data. Undisclosed file-content access materially increases risk because it moves the skill from metadata monitoring into direct sensitive-data exposure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The dashboard is described as monitoring status and session sizes, but it also reads and returns contents of workspace files and session history, which may contain sensitive prompts, secrets, or operational data. Undisclosed file-content access materially increases risk because it moves the skill from metadata monitoring into direct sensitive-data exposure.

Content

No source excerpt is available for this finding.

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
- **Session History** - Click cards to view recent conversation history
- **File Viewer** - View Agent's OKR.md, SOUL.md, HEARTBEAT.md
- **Session Size Monitor** - Display .jsonl file size with threshold warnings
- **Send Message** - Send messages to agents directly from the UI
- **Font Size Control** - 10px-24px with reset button (R)
- **Bloomberg Style** - Bloomberg Terminal style interface
- **Auto Config Reload** - Hot reload when openclaw.json changes

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
| `R` button | Reset font size to 13px |
| `CLOSE` button | Close agent + hide right panel |
| `HIDE` button | Hide right panel |
| Input box + SEND | Send message to selected agent |

## Send Message to Agent

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
| `R` button | Reset font size to 13px |
| `CLOSE` button | Close agent + hide right panel |
| `HIDE` button | Hide right panel |
| Input box + SEND | Send message to selected agent |

## Send Message to Agent

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
| `HIDE` button | Hide right panel |
| Input box + SEND | Send message to selected agent |

## Send Message to Agent

Click on an agent card, then use the input box at the bottom of the right panel to send messages directly to the agent.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hardcoded gateway token is a direct credential exposure. Anyone who obtains this file can use the token to access the gateway API, and because the server is also configured to bind to 0.0.0.0, the dashboard context makes the secret more dangerous by potentially enabling remote access paths to authenticated backend functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The server enables cross-origin access for any origin and defines no authentication or authorization for its HTTP API, allowing broad unauthenticated read access to sensitive session and agent data. In practice, any local or reachable web page can query the dashboard API and retrieve internal histories and workspace documents if the service is accessible.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill documentation describes capabilities that require filesystem, environment, and network access, but it declares no explicit tool scope or permissions. This creates a transparency and governance gap: operators may enable a skill without understanding that it can read local configuration, contact a gateway API, and interact with agents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation advertises sending direct messages to agents but does not warn that this mutates agent state and appends to session history. In an agent-control context, message injection can trigger actions, alter behavior, or create misleading audit trails if users do not understand the side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly instructs users to print the gateway token from a local config file without warning that the token is a sensitive credential. This encourages insecure handling, increases the chance of token exposure in shells, logs, screenshots, or copied documentation, and can lead to unauthorized gateway access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration explicitly instructs operators how to retrieve a live gateway authentication token and place it into a web dashboard config. That extends the skill from passive monitoring into credential handling and authenticated control-plane access, increasing the chance of token exposure through source control, local file leaks, logs, screenshots, or accidental redistribution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Core UI functionality depends on remotely hosted React/ReactDOM from npmmirror and avatar generation from DiceBear, creating a supply-chain and data-exposure path outside the monitored system boundary. A compromised dependency host, unexpected content changes, or network interception could alter the dashboard behavior or exfiltrate sensitive dashboard data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The avatar URL embeds an agent/session-derived seed and sends it to an external service without any user disclosure. Even if the value is only an identifier, it leaks internal naming/session patterns to a third party and creates an unnecessary metadata exposure channel.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The code transmits a session-derived seed to api.dicebear.com, which is an external network destination unrelated to core monitoring. This creates unnecessary outbound data flow from sensitive operational context and can expose internal identifiers or usage patterns to a third party.

Content

Scanner excerpt · assets/agent-kanban/public/index.html (reported line 434)May include surrounding context.

html
// 像素风头像 URL
    function getAvatarUrl(seed) {
      return `https://api.dicebear.com/7.x/pixel-art/svg?seed=${encodeURIComponent(seed)}`;
    }
    
    // 时间格式化

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The page retrieves conversation history and agent file contents and presents them directly, but gives users no notice that potentially sensitive prompts, messages, and file data are being exposed. In a monitoring dashboard for multiple agents, lack of disclosure and consent increases privacy risk and makes accidental overexposure more likely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dashboard goes beyond the stated monitoring purpose and fetches/displays full contents of agent files such as OKR.md, SOUL.md, and HEARTBEAT.md. In an agent environment, these files can contain sensitive prompts, operational state, goals, or secrets, so broad UI exposure materially increases confidentiality risk and insider misuse potential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The server posts tool names and arguments to an external Gateway HTTP API, including session identifiers and later history-related requests, but this file provides no user-facing notice, confirmation, or comment warning that user/session data is sent over the network. Under the code-file criteria, network transmission of user or system data should have some visible disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The API exposes full session histories and the contents of internal agent workspace files such as SOUL.md, HEARTBEAT.md, and OKR.md. For a dashboard described as monitoring agent status, this is overbroad data access that can reveal sensitive prompts, plans, credentials, internal reasoning, or operational metadata to any caller of the server.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to extract a live gateway authentication token from a local config file and copy it into another file, but provides no warning that this credential is sensitive. This increases the chance of accidental disclosure through source control, screenshots, shared configs, or local file exposure, especially because the dashboard is designed to access agent/session data through the gateway.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README shows authenticated bearer-token API usage but omits warnings about protecting the token from shell history, terminal logs, shared snippets, or screen recording. Because this token grants access to gateway API operations, an exposed example can enable unauthorized access to agent status, session history, and related files.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/README.md (reported line 139)May include surrounding context.

API Usage

bash
curl -X POST http://127.0.0.1:18789/tools/invoke \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"tool": "sessions_list", "args": {}}'

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency uses a semver range (^4.18.2) rather than a fully pinned version, which allows different installs to resolve to different Express patch/minor releases over time. In a dashboard service that may be deployed in multiple environments, this weakens build reproducibility and can unintentionally introduce vulnerable or behavior-changing versions from the 4.x line.

Content

Scanner excerpt · assets/agent-kanban/package.json (reported line 11)May include surrounding context.

json
"dev": "node server.js"
  },
  "dependencies": {
    "express": "^4.18.2"
  }
}

Unverifiable Dependency: express has 5 known advisory(ies) (CVE-2024-10491 (Express ressource injection); CVE-2014-6393 (No Charset in Content-Type Header in express); CVE-2024-9266 (Express Open Redirect vulnerability) +2 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
83% confidence
Finding

Because Express is not pinned, it is not possible to verify from this manifest alone which exact release will be installed, and some Express releases have known security advisories. For a web dashboard exposed to users, uncertainty around the actual installed web framework version increases supply-chain and patch-management risk, even though this file alone does not prove a specific CVE is present.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document declares the page language as Chinese, and the script also formats time using the fixed zh-CN locale. This enforces a specific language/locale without offering the user a choice or documenting that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
assets/agent-kanban/server.js:28