Back to skill

Security audit

AdMapix

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent AdMapix API client, but its install docs use an unpinned npx command that can execute mutable remote installer code.

Review the install path before using it: prefer a pinned, trusted ClawHub/OpenClaw installer version or another integrity-checked install flow. If installed, treat AdMapix lookups as third-party API calls and keep the API key out of chat, logs, screenshots, and generated output.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:19
Finding

Unpinned Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 19–23
Vulnerability Type: Supply-chain risk caused by unpinned package execution
Risk Level: Medium

Vulnerable Code

markdown
## Install

```bash
npx clawhub install admapix
text

The same installation instruction is duplicated in `README_CN.md`, lines 19–23.

### Technical Analysis

The documented installation command invokes `clawhub` through `npx` without specifying a package version or integrity constraint. If the package is not already available in a trusted local cache, `npx` can retrieve the current package release from its configured registry and execute it with the installing user's permissions.

Because the resolved package may change after this Skill has been audited, the effective installation code is not reproducible or bounded to the reviewed repository contents. Registry-account compromise, a malicious future release, dependency compromise, or registry configuration manipulation could therefore introduce arbitrary executable behavior.

### Attack Path

1. An attacker compromises the publisher account, package distribution channel, or a transitive dependency used by the unpinned `clawhub` release.
2. The attacker publishes a malicious version or causes dependency resolution to select malicious code.
3. A user follows the documented command:
   `npx clawhub install admapix`.
4. `npx` resolves and downloads the attacker-controlled package version.
5. The package CLI or applicable lifecycle code executes under the user's account.
6. The malicious code can access resources available to that account, subject to operating-system and sandbox restrictions.

### Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running the installation command. Potential scope includes reading or modifying user-accessible files, accessing environment variables and locally available c
...[truncated 271 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to a specifically reviewed version:
    bash
    npx clawhub@<verified-version> install admapix
    
  2. Use an exact version rather than a floating tag or range.
  3. Document the expected package registry and publisher identity.
  4. Where supported, verify package provenance, signatures, and integrity hashes before execution.
  5. Review and lock transitive dependencies associated with the selected installer version.
  6. Apply the same corrected command to README_CN.md.
  7. Prefer an installation workflow that separates package download and verification from execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (24)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
For the creative `search` endpoint, `page_size` is capped at **10** (clamp any larger request down to 10; use `page` for more). Other list endpoints use their own documented ranges.

## Output Rules

Return the API response as **raw structured JSON** — keep the API field names; do not rename, drop, summarize, rank, or editorialize. The calling agent composes and analyzes.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx clawhub install admapix without pinning a specific version. This causes execution of whatever package version is current at install time, which creates a supply-chain risk if the package is later compromised, typo-squatted, or updated with malicious postinstall/runtime behavior. In a skill-install context, that risk is meaningful because users are being told to execute remote code directly from a package registry.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawhub install admapix without pinning a specific package version. This can cause users to execute whatever version is currently published or resolved at install time, which creates a supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description includes very broad triggers such as ad creative, rankings, downloads, revenue, and market data without strong activation constraints. This can cause over-invocation and unintended routing of user requests to this skill, increasing the chance that user queries and derived parameters are sent to an external API when the user did not clearly intend that action.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill explicitly sends user-derived query parameters and an API credential to an external service at api.admapix.com. Even though this is the intended function of the skill, it still creates a real data egress boundary where sensitive prompts, search terms, or business intelligence queries could be transmitted to a third party.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

bash
admapix_auth_header="X-API-Key: ${ADMAPIX_API_KEY}"
# GET
curl -s "https://api.admapix.com/api/data/{endpoint}?{params}" -H "$admapix_auth_header"
# POST
curl -s -X POST "https://api.admapix.com/api/data/{endpoint}" \
  -H "$admapix_auth_header" -H "Content-Type: application/json" -d '{...}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill explicitly sends user-derived query parameters and an API credential to an external service at api.admapix.com. Even though this is the intended function of the skill, it still creates a real data egress boundary where sensitive prompts, search terms, or business intelligence queries could be transmitted to a third party.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

bash
admapix_auth_header="X-API-Key: ${ADMAPIX_API_KEY}"
# GET
curl -s "https://api.admapix.com/api/data/{endpoint}?{params}" -H "$admapix_auth_header"
# POST
curl -s -X POST "https://api.admapix.com/api/data/{endpoint}" \
  -H "$admapix_auth_header" -H "Content-Type: application/json" -d '{...}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

GET

curl -s "https://api.admapix.com/api/data/{endpoint}?{params}" -H "$admapix_auth_header"

POST

curl -s -X POST "https://api.admapix.com/api/data/{endpoint}"
-H "$admapix_auth_header" -H "Content-Type: application/json" -d '{...}'

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 123)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 140)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 192)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 194)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 195)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The documentation explicitly notes that appList[].name may contain HTML tags and instructs consumers to strip them before display. If a caller fails to sanitize or safely encode this field, untrusted HTML from the upstream API could be rendered in downstream web/chat surfaces, creating an injection/XSS risk.

Content

Scanner excerpt · references/api-creative.md (reported line 178)May include surrounding context.

md
### ⚠️ Important Notes

1. **HTML tags in names:** `appList[].name` may contain HTML highlight tags like `<font color='red'>keyword</font>`. Strip these before displaying to the user.
2. **Null values:** Many fields can be `null` — always handle null gracefully.
3. **totalSize null:** For keyword searches, `totalSize` is often `null`. The actual result count is reflected in `list` length per page.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

This line documents list[].appList[].name and explicitly warns it may contain HTML font tags. In this skill context, which returns raw JSON for downstream composition, that makes the data-flow risk more relevant: a consuming agent/UI might directly render this field, enabling markup/script injection if sanitization is missed.

Content

Scanner excerpt · references/api-creative.md (reported line 193)May include surrounding context.

md
| list[].title | Ad title (may be null) |
| list[].describe | Ad copy text (may be null) |
| list[].appList[].name | Associated app name — **may contain HTML `<font>` tags** |
| list[].appList[].developer | Developer/publisher name |
| list[].appList[].developerId | Developer ID |
| list[].appList[].logo | App icon URL |
| list[].impression | Estimated impression count |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states "Supports English and Chinese inputs," which restricts accepted languages to two specific languages. Under the policy, language constraints should either be user-selectable/opt-in or clearly justified as region-specific; this line presents the limitation as a fixed constraint without either.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The title and multiple section labels are presented bilingually, which can impose a locale or language presentation choice without explaining whether users may choose their preferred language. The file does not state that bilingual output is optional or limited to a specific audience or region.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file instructs users to include a configured API key in the X-API-Key header, which involves use of sensitive credentials. Although the API behavior is documented, there is no accompanying warning to avoid exposing the key in logs, shared examples, or client-visible contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The note says to present the returned publisher-app data as specific Chinese labels ("投放媒体位" or "广告展示位"). This imposes a language/locale choice in the skill documentation without indicating that the user can choose their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file instructs the user to include a configured AdMapix API key in the request header, which involves use of sensitive credentials and authenticated network transmission. The document does not include any caution about protecting the key, avoiding exposure in logs, or ensuring requests are sent only to the intended service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file is bilingual and explicitly notes fields such as country names returned in Chinese, while workflow prompts are also partly in Chinese. Because the document does not state that language may vary or offer an opt-in/choice, it can be read as imposing a locale/language behavior without user selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file instructs users to include a configured AdMapix API key in the X-API-Key header, which involves use of sensitive credentials. The document provides no warning or handling guidance about protecting the key, avoiding accidental exposure in logs/shared examples, or ensuring the user is authorized to use it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file presents headings, labels, and example values in both English and Chinese throughout the document, including locale-specific values like company region names in Chinese. Because the file does not explain that the bilingual format is intentional or offer a user language preference, it may conflict with a language/locale policy requiring explicit opt-in or documented scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The section labels and example utterances in the user intent mapping are primarily Chinese, which can imply the skill is designed around a specific language for invocation. There is no accompanying statement that users may use other languages or that the skill is intentionally limited to a Chinese-language workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Throughout the reference tables, accepted inputs are framed only as 'User says (EN)' and 'User says (CN)', which implies the skill is designed around two specific languages. There is no explicit statement that users may choose their preferred language or that the restriction is intentionally limited to a justified regional context, creating a potential language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.