Back to skill

Security audit

constructor-miniapps-f100k

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its mini-app builder purpose, but it gives conflicting approval rules and can publish apps to Vercel with the user's token and send results over Telegram without a clear confirmation gate.

Review this skill before installing. It is not evidence of a backdoor, but you should only use it if you are comfortable with an agent publishing to Vercel and sending deliverables through Telegram, and you should require explicit confirmation before every deploy, token use, login, or external send.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Production deployment can proceed without explicit user authorization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 3, 17, and 117–126
Vulnerability Type: Unauthorized production deployment caused by contradictory approval instructions
Risk Level: Medium

Relevant Snippets

yaml
description: "... La publica en *.vercel.app solo con la cuenta de Vercel de la usuaria conectada y su ✅. ..."
markdown
> - Fase 4 · publicar: **Las apps siempre se despliegan directo en Vercel** con la cuenta de la usuaria (`VERCEL_TOKEN` en el entorno): `vercel --prod --yes --token "$VERCEL_TOKEN"`, y le mandas la URL por Telegram. No hace falta pedir ✅ para desplegar. Nunca `vercel login` desde el servidor ni una cuenta que no sea suya.
markdown
Hay tres caminos. **Empieza siempre por el primero: publícala tú, desde esta misma conversación.**

### Camino A — la publicas tú (el que hay que intentar primero)

Es gratis y no pide tarjeta. Pide permiso antes de correr comandos y di en una línea qué hace cada uno; no la dejes mirando una terminal sin entender qué pasa.

1. **¿Está la CLI?** `vercel --version`. Si no está: `npm i -g vercel`.
2. **¿Hay sesión?** `vercel whoami`.
3. **Prepara la carpeta.**
4. **Publica:** desde la carpeta del proyecto, `vercel --prod --yes`.

Technical Analysis

The Skill expands a request to build a mini-app into a production deployment under the user's Vercel account. The OpenClaw-specific instruction at line 17 explicitly states that no approval checkmark is required and supplies a non-interactive production command using VERCEL_TOKEN.

This conflicts with both the frontmatter at line 3, which says deployment requires the user's checkmark, and the later instruction at line 121 to obtain permission before running commands. Because the more environment-specific instruction explicitly removes the approval requirement and uses --yes, the documentation does not establish a reliable confirmation gate before the external side effe ...[truncated 1857 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, current user confirmation immediately before every production deployment.
  2. Remove the instruction No hace falta pedir ✅ para desplegar and align all deployment guidance with the approval requirement in the frontmatter.
  3. Do not treat the presence of VERCEL_TOKEN as authorization for a specific deployment.
  4. Default to local file delivery or a non-production preview when the user requested only application creation.
  5. Separate build and deploy phases so successful local creation does not automatically trigger publication.
  6. Before confirmation, show the user the target Vercel account, project name, files to be published, expected visibility, and exact command.
  7. After approval, constrain deployment to the user-approved project and avoid silently creating or relinking unrelated projects.
  8. Ensure any executable helper or deployment wrapper enforces the confirmation state rather than relying solely on prose instructions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata promises deployment only with the user's connected Vercel account and explicit approval, but the body later instructs automatic production deployment via VERCEL_TOKEN without requiring confirmation. This mismatch can cause the agent to perform external side effects under user credentials that the user did not knowingly authorize, which is especially risky because deployment creates a public URL and consumes an access token from the environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document gives conflicting instructions about whether permission is required before deployment: one section says to deploy automatically with the user's token and no approval, while another says to ask permission before running commands and explains interactive login. Contradictory operational guidance around credentialed external actions is dangerous because agents may choose the less restrictive path and deploy or transmit artifacts without clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to deploy using a Vercel token from the environment and to send deliverables via Telegram, but it does not consistently require a user-facing warning or consent for credential use and external transmission. This is dangerous because it can exfiltrate project artifacts to third-party services and perform account actions using stored secrets without the user's informed approval.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to deploy automatically using the user's Vercel token without explicit confirmation authorizes a privileged external action under stored credentials. In this skill's context, that is more dangerous because the same workflow also emphasizes automatic publication and delivery, increasing the chance of unintended public exposure and misuse of the user's deployment account.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use the skill 'SIEMPRE' for a long list of broad phrases such as 'constrúyeme una app', 'crea una herramienta', and 'dame el link de mi app'. These phrases are general enough to overlap with many ordinary requests, and the trigger guidance does not provide explicit exclusion examples beyond a narrow note about sales landing pages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction 'Escribe en español neutro, trato de "tú", salvo que pidan otra cosa' imposes a default language and tone choice rather than asking the user for language preference first. This is a language-policy issue because it defaults users into a locale/language without prior opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.