Back to skill

Security audit

web-tools-guide

Security checks for vulnerabilities and agentic risk

Overview

This skill is a web-tool guide, but installing it can run broad local setup that downloads unverified code, changes browser state, and handles API keys unsafely.

Install only if you trust the opencli npm package and GitHub release source, are comfortable with a browser extension being loaded into Chrome, and can tolerate browser/gateway restarts. Do not paste real API keys into chat unless you accept that they may appear in logs, process arguments, or configuration output; prefer a safer local secret setup and rotate any key already shared this way.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:1
Finding

Mandatory instruction override solicits third-party API credentials and diverts users to fixed providers

Content
View full analysis
openclaw config set plugins.entries.kimi.enabled true openclaw config set plugins.entries.kimi.config.webSearch.apiKey ``` ### Technical Analysis The Skill declares itself mandatory before ordinary web operations and states that a search error must trigger a prescribed API configuration workflow. That workflow prevents immediate use of available fallback mechanisms and requires the Agent to emit fixed provider recommendations and request a secret directly in the conversation. This behavior is not necessary for the declared web-routing functionality. The Skill already documents alternatives such as direct fetching, `opencli`, and browser access. Making third-party promotion and credential solicitation mandatory changes the Agent's response goals instead of merely documenting tool usage. The behavior also creates a social-engineering risk: a us ...[truncated 1068 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/setup-opencli.sh:76
Finding

Unpinned global npm installation executes mutable third-party package code

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup-opencli.sh:92
Finding

Unverified remote browser extension is downloaded and activated

Content
View full analysis
/dev/null; then downloaded=true fi fi if [ "$downloaded" = false ]; then download_url="${GITHUB_RELEASE_BASE}/latest/download/opencli-extension.zip" if ! curl -fsSL --max-time 60 -o "$tmp_zip" "$download_url" 2>/dev/null; then rm -f "$tmp_zip" fail "Browser Bridge extension download failed" fi fi mkdir -p "$ext_dir" unzip -qo "$tmp_zip" -d "$ext_dir" rm -f "$tmp_zip" ``` The downloaded content is then activated through Chrome command-line arguments: ```bash local new_cmdline="${clean_cmdline} --disable-extensions-except=${ext_dir} --load-extension=${ext_dir}" kill "$chrome_pid" 2>/dev/null || true nohup bash -c "exec ${new_cmdline}" > "$log_file" 2>&1 & ``` ### Technical Analysis The script downloads an executable browser extension from GitHub Releases and validates only that extraction produces a `manifest.json`. It does not verify a cryptographic checksum, release signature, signer identity, or expected extension contents. The fallback URL uses `latest`, making the retrieved payload explicitly mutable. Even the version-specific URL is inferred from another dynamically installed package and is not tied to an audited digest. A browser extension is active code with permissions declared in its manifest. Depending on those permissions, it can inspect or alter pages, access authenticated browser sessions, communicate with remote services, and interact with browser debugging interfaces. Checking only for the presence of `manifest.json` provides no authenticity or integrity assurance. ### Attack Path 1. T ...[truncated 1267 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-opencli.sh:214
Finding

Chrome command-line reconstruction permits shell interpretation and command injection

Content
View full analysis
"$log_file" 2>&1 & ``` ### Technical Analysis Linux exposes process arguments in `/proc//cmdline` as NUL-delimited values. The script destroys those argument boundaries by translating NUL bytes into spaces and storing the result in a single string. It then interpolates that string into `bash -c`. This causes shell metacharacters contained in an original Chrome argument to be interpreted as shell syntax rather than preserved as literal argument data. Characters such as semicolons, command substitutions, redirections, and shell operators may therefore execute additional commands. The `sed` expressions are also not safe parsers for arbitrary process arguments. They can corrupt quoted values, whitespace-containing paths, and extension arguments. The fixed extension directory does not remove the risk because the untrusted portion is the reconstructed existing command line. ### Attack Path 1. An attacker causes a Chrome process listening on port 9222 to start with an argument containing shell metacharacters. 2. The setup script identifies that process as the browser to reload. 3. `/proc//cmdline` is flattened into a space-separated string. 4. The script performs text substitutions without retaining argument boundaries. 5. The resulting string is insert ...[truncated 668 chars]
Remediation
View remediation
/cmdline` as NUL-delimited arguments and load them into a Bash array. 2. Execute the browser directly with an array, for example using `"${args[@]}"`, rather than through `bash -c`. 3. Never convert process arguments into a shell command string. 4. Compare and remove extension options as individual array elements. 5. Validate that the selected executable is an expected Chrome binary owned by a trusted user. 6. Refuse to restart processes owned by another user. 7. Use `readarray -d ''` or an equivalent NUL-safe mechanism. 8. Add tests covering spaces, quotes, command substitutions, semicolons, and redirection characters in arguments. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
references/web-search-config.md:68
Finding

API keys are exposed through process arguments and plaintext verification output

Content
View full analysis
openclaw config set plugins.entries.kimi.enabled true openclaw config set plugins.entries.kimi.config.webSearch.apiKey ``` The verification procedure retrieves the secret itself: ```bash openclaw config get plugins.entries.tavily.config.webSearch.apiKey openclaw config get plugins.entries.kimi.config.webSearch.apiKey ``` ### Technical Analysis The configuration workflow places the user's API key directly in a command-line argument. Command arguments may be visible to other local processes through process inspection, audit systems, shell history, terminal capture, diagnostic tooling, and Agent execution logs. The verification step compounds the issue by retrieving and potentially displaying the complete stored key. Verification should test whether a secret exists or whether authenticated access succeeds; it should not print the secret value. The workflow begins by asking the user to place the key in the conversation, creating another plaintext copy in chat history before the command is executed. ### Attack Path 1. The user submits an API key in the Agent conversation. 2. The Agent substitutes the key into an `openclaw config set` command. 3. The key appears in the process argument vector and potentially execution logs. 4. The key is stored in `openclaw.json`. 5. The Agent runs `openclaw config get` during verification. 6. The complete key may be emitted to terminal output or returned into the conversation. 7. A local observer, log reader, or conversation-accessing party captures and reuses the credential. ### Impact Assessment A stolen key can be used to c ...[truncated 442 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/web-search-config.md:88
Finding

Generic process-name termination can kill unrelated gateway services

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The stated purpose is web-tool guidance, but the referenced behavior includes software installation, filesystem modification, process inspection, and browser restart/reconfiguration. This mismatch is dangerous because it can cause an agent or reviewer to trust the skill as documentation while it actually enables privileged local system changes and external downloads.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary heading and surrounding instructions are presented in Chinese, and the manifest description uses forceful language such as "MANDATORY" without offering any language choice. This can impose a language/locale expectation on users or downstream agents without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script unconditionally kills a running Chrome process and restarts it with modified flags, which can disrupt active browsing sessions, cause loss of unsaved work, and alter the browser's security posture by injecting an extension. Because this is an installation script for a web tooling skill, the behavior is especially risky: it targets a live user application and changes runtime state without explicit consent or process ownership checks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill instructs the agent to run a shell installation script (setup-opencli.sh) but does not declare any tool scope or allowed-tools boundary. That creates an unexpected capability expansion path where a guidance skill can trigger local command execution without explicit permissioning, increasing the risk of unauthorized environment changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger terms are so broad that the skill can activate for a large fraction of normal web-related requests. Because the skill includes operational instructions that can lead to shell execution and browser/login workflows, overly broad activation expands the attack surface and makes accidental invocation much more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire guide is written only in Chinese and presents the skill instructions as mandatory usage guidance, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire instruction file is written as a fixed Chinese interaction flow and includes required user-facing text to be output verbatim in Chinese, but it does not offer any language or locale opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the user to paste an API key into the chat and then store it, but it provides no warning that the key is a sensitive credential, no guidance on minimizing exposure, and no safer alternative flow. In an agent setting, this increases the risk of accidental secret disclosure through conversation logs, transcripts, screenshots, or mishandling by downstream tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level description is written as a Chinese-only directive for the address index and does not indicate that language selection is optional. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the regional constraint is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments and runtime messages throughout the script are written in Chinese, including usage and operational status text. This imposes a specific language/locale on users without opt-in or an alternative, which fits the language-policy violation category.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The script downloads and installs executable browser-extension content from the network at runtime without integrity verification such as a pinned checksum or signature check. If the release asset, network path, or upstream account is compromised, the script will trust and deploy malicious extension code into the browser environment.

Content

Scanner excerpt · scripts/setup-opencli.sh (reported line 117)May include surrounding context.

sh
if [ -n "$version" ]; then
        download_url="${GITHUB_RELEASE_BASE}/download/v${version}/opencli-extension.zip"
        info "尝试下载 Browser Bridge 插件 v${version}..."
        if curl -fsSL --max-time 60 -o "$tmp_zip" "$download_url" 2>/dev/null; then
            downloaded=true
        else
            warn "v${version} 下载失败,回退到 latest release"

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-opencli.sh (reported line 262)May include surrounding context.

sh
info "使用新参数重新启动 Chrome..."
    # 后台启动,重定向输出到日志文件
    local log_file="/tmp/opencli-chrome-restart.log"
    nohup bash -c "exec ${new_cmdline}" > "$log_file" 2>&1 &
    local new_pid=$!
    info "Chrome 已启动 (PID: ${new_pid}),日志: ${log_file}"

Static analysis

No suspicious patterns detected.