Back to skill

Security audit

Nano Diary Hook

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it sends private diary text and a reusable webhook token to an external service, with the token placed in the URL and existing diary entries potentially updated or AI-merged.

Review this before installing if your diary contains sensitive personal information. Only use it with a Nano account and endpoint you trust, understand that same-date submissions may alter existing entries, and consider rotating the webhook token if it has been used in shell commands or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

Webhook Authentication Token Exposed in URL Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29 and 51
Vulnerability Type: Credential exposure through URL and command-line arguments
Risk Level: Medium

The skill instructs users to embed the personal NANO_DIARY_HOOK_TOKEN directly in the webhook URL:

text
POST https://image.yezishop.vip/api/diary-hook/${NANO_DIARY_HOOK_TOKEN}

The same insecure pattern appears in the executable example:

bash
curl -X POST "https://image.yezishop.vip/api/diary-hook/${NANO_DIARY_HOOK_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{"date": "2026-03-06", "content": "Today I learned how to publish OpenClaw skills to ClawHub."}'

Technical Analysis

Placing an authentication token in a URL path increases its exposure even when HTTPS is used. TLS protects the request while it is in transit, but does not prevent the complete URL from being recorded at either endpoint or on the originating system.

Potential exposure locations include:

  • Shell history containing the expanded command.
  • Process inspection and command-line telemetry while curl is running.
  • Web-server and reverse-proxy access logs.
  • API gateway, load balancer, monitoring, tracing, and error-reporting systems.
  • Diagnostic output or support records that capture request URLs.

A URL-path token may therefore become accessible to users or services that are permitted to inspect operational logs but are not authorized to modify the diary. Authentication credentials should instead be transmitted in a dedicated authorization header and redacted by default from telemetry.

Attack Path

  1. A user or agent runs the documented curl command with NANO_DIARY_HOOK_TOKEN expanded in the URL.
  2. The complete command or request URL is retained in shell history, process telemetry, access logs, proxy logs, or observability data.
  3. An attacker or insufficiently privileged operator obtains read access to one of those records. ...[truncated 1189 chars]
Remediation
View remediation

Remediation Suggestions

  1. Redesign the API to accept the token in an authorization header, for example:

    bash
    curl -X POST "https://image.yezishop.vip/api/diary-hook" \
      -H "Authorization: Bearer ${NANO_DIARY_HOOK_TOKEN}" \
      -H "Content-Type: application/json" \
      --data '{"date":"2026-03-06","content":"Today I learned how to publish OpenClaw skills to ClawHub."}'
    
  2. Configure servers, reverse proxies, API gateways, and observability systems to redact authorization data and any legacy token-bearing URL paths.

  3. Disable the URL-token form after a documented migration period rather than supporting both forms indefinitely.

  4. Rotate tokens that may already have appeared in shell history or infrastructure logs, and provide users with clear revocation and regeneration procedures.

  5. Apply least privilege to webhook tokens and rate-limit requests. Where practical, restrict each token to diary-submission operations only.

  6. Avoid logging complete request URLs and command lines. Review retention and access controls for existing logs, traces, and shell histories.

  7. Update SKILL.md so that all endpoint descriptions and examples use the safer header-based authentication mechanism.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This skill is designed to transmit user-provided diary content and a secret webhook token to an external network endpoint using curl. While external transmission is core to the skill's function, it still represents a real security and privacy exposure because highly sensitive personal data and an authentication secret leave the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
env:
        - NANO_DIARY_HOOK_TOKEN
      bins:
        - curl
      primaryEnv: NANO_DIARY_HOOK_TOKEN
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends both sensitive diary content and the user's personal webhook token to an external third-party domain, but the description does not clearly warn the user about that data transfer. This creates a privacy and credential-exposure risk because users may unknowingly disclose intimate personal content and a reusable authentication token to a remote service outside the local agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that submitting content for the same date will update an existing entry and may trigger AI-powered merging, but it does not warn users that repeated use can overwrite or materially alter prior diary content. This is dangerous because users may expect append-only behavior and unintentionally lose or distort original handwritten entries through automated modification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.