Back to skill

Security audit

Zillow × Airbnb Matcher

Security checks for vulnerabilities and agentic risk

Overview

The skill’s property-matching function is mostly coherent, but it needs Review because its installer and docs handle a live RapidAPI key in unsafe plaintext and command-line patterns.

Install only if you are comfortable sending search locations to RapidAPI-backed Zillow/Airbnb services and storing a RapidAPI key locally. Prefer setting the key through a secure secret store or protected environment variable, avoid passing it on the command line, set .env permissions to owner-only, and rotate the key if you already followed the command-line setup instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:66
Finding

RapidAPI Key Exposed Through Command-Line Arguments and Insecure File Permissions

Content
View full analysis
/dev/null | cut -d'=' -f2 | tr -d '"') fi if [ -n "$RAPIDAPI_KEY" ]; then if [ -f "$ENV_FILE" ]; then if grep -q "^RAPIDAPI_KEY=" "$ENV_FILE"; then sed -i "s/^RAPIDAPI_KEY=.*/RAPIDAPI_KEY=$RAPIDAPI_KEY/" "$ENV_FILE" else echo "RAPIDAPI_KEY=$RAPIDAPI_KEY" >> "$ENV_FILE" fi else echo "RAPIDAPI_KEY=$RAPIDAPI_KEY" > "$ENV_FILE" fi echo -e "${GREEN}✅ RapidAPI key saved to .env${NC}" ``` The documentation actively recommends passing the credential as a command-line argument: ```bash echo "RAPIDAPI_KEY=your_key_here" > ~/clawd/skills/zillow-airbnb-matcher/.env ``` ```bash bash ~/clawd/skills/zillow-airbnb-matcher/scripts/install.sh --rapidapi-key YOUR_KEY_HERE ``` The runtime setup message provides similar plaintext storage guidance: ```javascript console.log(` echo "RAPIDAPI_KEY=your_key_here" >> ${path.join(__dirname, '../.env')}`); ``` ### Technical Analysis The installer accepts the RapidAPI credential through `--rapidapi-key`. Command-line arguments are not an appropriate secret transport mechanism because the complete invocation may be: - Persisted in the user's shell history. - Recorded by terminal session logging or administrative auditing. - Temporarily visible to local process-monitoring facilities. - Captured in deployment logs, support transcripts, or automation output. The installer ...[truncated 2378 chars]
Remediation
View remediation
"$ENV_FILE" ``` Values should also be safely escaped if arbitrary key formats are supported. 5. **Harden pre-existing files.** Apply `chmod 600 "$ENV_FILE"` even when the file already exists. 6. **Update `GUIDE.md` and runtime setup output.** Remove examples that place real credentials in shell commands. Instruct users to use a secure prompt, protected environment injection, or the platform's secret store. 7. **Add `.env` to `.gitignore`** and document that it must never be committed, copied into support tickets, or included in diagnostic archives. 8. **Rotate potentially exposed keys.** Users who followed the existing command-line instructions should revoke and regenerate their RapidAPI key, especially where shell history or session logs are retained. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This second mismatch report points to the same core issue: the skill claims a richer, cross-source analysis workflow than the implementation apparently provides. Such overclaiming is dangerous because downstream agents or users may make investment or privacy decisions based on false assumptions about provenance, completeness, or processing of third-party real-estate and rental data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This second mismatch report points to the same core issue: the skill claims a richer, cross-source analysis workflow than the implementation apparently provides. Such overclaiming is dangerous because downstream agents or users may make investment or privacy decisions based on false assumptions about provenance, completeness, or processing of third-party real-estate and rental data.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
script: scripts/search.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
script: scripts/search.js

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins axios to 1.13.5, and the supplied advisory set includes multiple high-severity issues including SSRF/proxy-bypass and prototype-pollution-related exploitation paths. In this skill’s context, axios is likely used to fetch Zillow/Airbnb data from remote services, so a vulnerable HTTP client is directly exposed to attacker-controlled URLs, redirects, proxy settings, or response flows.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
86% confidence
Finding

form-data 4.0.5 is reported as vulnerable to CRLF injection via unescaped multipart field names/filenames, which can enable request smuggling or header/body manipulation when attacker-controlled values are included in multipart uploads. While this skill’s primary purpose is data matching rather than file upload, the package is transitively present through axios, so the risk is lower than a direct use case but still real if multipart requests are ever constructed from external input.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The analysis indicates axios resolves to a version with multiple known advisories, including SSRF and prototype-pollution-related issues. In a skill that likely performs network requests to third-party real-estate and rental endpoints, a vulnerable HTTP client is more dangerous because attacker-influenced URLs, proxy settings, headers, or response handling may be reachable through normal operation.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 20)May include surrounding context.

sh
set -e

SKILL_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
RED='\033[0;31m'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · GUIDE.md (reported line 40)May include surrounding context.

md
process.exit(1);
}

// Load .env ONLY from skill directory
const envPath = path.join(__dirname, '../.env');
if (fs.existsSync(envPath)) {
  require('dotenv').config({ path: envPath });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.js (reported line 26)May include surrounding context.

js
process.exit(1);
}

// Load .env ONLY from skill directory
const envPath = path.join(__dirname, '../.env');
if (fs.existsSync(envPath)) {
  require('dotenv').config({ path: envPath });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.js (reported line 329)May include surrounding context.

js
process.exit(1);
}

// Load .env ONLY from skill directory
const envPath = path.join(__dirname, '../.env');
if (fs.existsSync(envPath)) {
  require('dotenv').config({ path: envPath });

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.js (reported line 27)May include surrounding context.

js
}

// Load .env ONLY from skill directory
const envPath = path.join(__dirname, '../.env');
if (fs.existsSync(envPath)) {
  require('dotenv').config({ path: envPath });
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.js (reported line 330)May include surrounding context.

js
}

// Load .env ONLY from skill directory
const envPath = path.join(__dirname, '../.env');
if (fs.existsSync(envPath)) {
  require('dotenv').config({ path: envPath });
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/search.js (reported line 355)May include surrounding context.

js
}

// Load .env ONLY from skill directory
const envPath = path.join(__dirname, '../.env');
if (fs.existsSync(envPath)) {
  require('dotenv').config({ path: envPath });
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/airbnb.js (reported line 74)May include surrounding context.

js
}

// Load .env ONLY from skill directory
const envPath = path.join(__dirname, '../.env');
if (fs.existsSync(envPath)) {
  require('dotenv').config({ path: envPath });
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide instructs users to place a live RapidAPI credential into a plaintext .env file in the skill directory, but gives no warning about protecting that file, avoiding shell history leakage, or ensuring it is excluded from version control and logs. While storing secrets in environment files is common, documenting it without basic secret-handling safeguards increases the chance of accidental disclosure through backups, support bundles, screenshots, repository commits, or local multi-user access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares installation steps, requires an environment secret, and clearly relies on external APIs, but it does not declare an explicit tool/permission scope for environment and network access. This weakens transparency and policy enforcement because users and the runtime cannot easily verify that the skill is expected to read secrets and send queries to third-party services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "check properties" is generic enough to match unrelated user requests, which can cause accidental invocation of this skill in contexts where the user did not intend to send location or real-estate queries to external APIs. In an agent ecosystem, broad triggers increase the risk of unintended data disclosure and confusing or unsafe tool activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation does not clearly warn that live searches transmit user-supplied location or query data to third-party APIs. This is a meaningful privacy and transparency issue because users may treat ZIP codes, city searches, and investment lookups as local processing when they are actually disclosed to RapidAPI-backed services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill focused on cross-referencing Zillow listings with active Airbnb rentals and calculating investment metrics. In demo mode, the code can additionally print a separate 'Commercial Properties (Crexi / LoopNet)' report, which is a broader real-estate capability not covered by the stated Zillow/Airbnb matching purpose.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
88% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. Because this skill cross-references third-party property/rental sources and likely performs authenticated or API-key-backed HTTP requests, a malicious redirect target could capture sensitive headers or tokens if redirect handling is not constrained.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"test": "node scripts/search.js --demo && node scripts/search.js --demo --commercial"
  },
  "dependencies": {
    "axios": "^1.6.0",
    "dotenv": "^16.3.1",
    "fuse.js": "^7.0.0",
    "yargs": "^17.7.2"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
},
  "dependencies": {
    "axios": "^1.6.0",
    "dotenv": "^16.3.1",
    "fuse.js": "^7.0.0",
    "yargs": "^17.7.2"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"dependencies": {
    "axios": "^1.6.0",
    "dotenv": "^16.3.1",
    "fuse.js": "^7.0.0",
    "yargs": "^17.7.2"
  },
  "engines": {

Static analysis

No suspicious patterns detected.