Back to skill

Security audit

Website Content Scraped into Obsidian

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it needs Review because it can persistently sync social data using a logged-in browser session while relying on an unpinned global dependency and overbroad environment access.

Install only if you are comfortable with a third-party global bb-browser tool using your logged-in OpenClaw browser session and writing social content into your Obsidian vault. Before use, pin and verify the dependency, run it with a minimal environment, use a dedicated vault/folder, validate account names, and require review of any cron entry before enabling scheduled sync.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T06 · System Persistence

Error
Location
SKILL.md:122
Finding

Persistent Scheduled Execution Through Cron

Content
View full analysis
"Sync every morning at 9am" or "Sync every Monday at 8am" The agent will create a cron job that runs in isolated mode with incremental sync — no duplicates. ``` ### Technical Analysis The Skill instructs the agent to create an operating-system cron job in response to a scheduling request. A cron entry persists beyond the current Skill execution and repeatedly launches code under the user's account. Scheduled synchronization is related to the declared functionality, but the instructions do not define: - The precise command that will be installed. - Absolute and immutable interpreter, script, and configuration paths. - A restricted execution environment. - A user-confirmation step showing the final cron entry. - Ownership tracking or an uninstall procedure. - Protections against later modification of the script or executable. Consequently, modifications to the script, configuration, Python interpreter, or `bb-browser` dependency after installation can affect every subsequent scheduled execution without renewed approval. ### Attack Path 1. A user asks the agent to synchronize content on a schedule. 2. Following `SKILL.md`, the agent creates a cron entry. 3. The cron entry survives the current session and repeatedly invokes the synchronization workflow. 4. An attacker or compromised dependency later modifies the invoked script, configuration, interpreter, or `bb-browser` executable. 5. Cron automatically executes the modified component under the user's account at the next scheduled interval. ### Impact Assessment Successful exploitation provides recurring code execution with the permissions of the user who owns the cron job. This can include access to the user's files, Obsidian vault, process ...[truncated 210 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:29
Finding

Unpinned Globally Installed Network-Capable Dependency

Content
View full analysis
Full list: [bb-sites](https://github.com/epiral/bb-sites) — this document covers the most commonly used adapters. ``` ### Technical Analysis The installation command retrieves the current registry release of `bb-browser` without an exact version pin, package-lock integrity metadata, or documented provenance verification. The package is installed globally, increasing its availability and impact across the user's environment. This dependency is particularly sensitive because the script launches it with `--openclaw`, allowing it to reuse an authenticated OpenClaw browser session. It also receives the parent process's complete environment and performs network operations against social platforms. A compromised package release, maintainer account, registry response, or future incompatible version could therefore execute arbitrary code with the user's permissions and access session capabilities. The network access itself is necessary for fetching social content, but using an unpinned, globally installed component with broad session and environment access exceeds minimum privilege. ### Attack Path 1. The user follows the documented `npm install -g bb-browser` instruction. 2. npm resolves a mutable package version from the registry. 3. A compromised or malicious release is installed globally. 4. The Skill launches the installed executable with `--openclaw`. 5. The dependency obtains access to the inherited environment and authenticated browser-session functionality. 6. Malicious package code reads accessible data, performs unauthorized browse ...[truncated 515 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_save.py:224
Finding

Complete Process Environment Exposed to a Network-Capable Subprocess

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_save.py:142
Finding

Arbitrary File Placement Through Unsanitized Account Username

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/fetch_save.py (reported line 232)May include surrounding context.

python
"site", f"{platform}/{_platform_cmd(platform)}",
        username, "--openclaw", "--json"
    ]
    env = os.environ.copy()
    env["PATH"] = str(Path(BB_BROWSER_BIN).parent) + ":" + env.get("PATH", "")

    try:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill describes capabilities that involve shell execution, network access, environment/path discovery, and file writes, but it does not declare any explicit tool scope or permission boundary. That makes the skill harder to audit and increases the risk that an agent invokes powerful operations without clear user-visible constraints, especially since it writes into a local vault and relies on external commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description emphasizes fetching social media content into Obsidian but does not prominently warn that posts, metadata, and possibly sensitive account activity will be stored locally in the user's vault. This can create privacy and data-handling risks because Obsidian vaults may be synced to cloud services, indexed locally, or exposed through backups without the user realizing the sensitivity of the imported content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says the agent will create a cron job for scheduled sync, but it does not clearly warn the user that this modifies persistent system scheduler configuration. Persistent task creation can surprise users, continue running after the session ends, and repeatedly access networked content and local files without an adequately explicit consent step.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Creating a cron job introduces session persistence: the skill causes actions to continue automatically after the interactive session ends. In this context, that means recurring network fetches and local file writes tied to a logged-in browser session, which increases the risk of unmonitored data collection, stale credentials misuse, or continued operation after the user forgets it was enabled.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
> "Sync every morning at 9am" or "Sync every Monday at 8am"

The agent will create a cron job that runs in isolated mode with incremental sync — no duplicates.

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly exposes commands to access a user's bookmarks and notifications, which are privacy-sensitive, but it provides no warning, consent expectations, or handling guidance. In the context of a skill designed to fetch and save social media content into Obsidian, this increases the risk that a user or downstream automation will collect and persist private data unintentionally.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_save.py (reported line 236)May include surrounding context.

python
env["PATH"] = str(Path(BB_BROWSER_BIN).parent) + ":" + env.get("PATH", "")

    try:
        result = subprocess.run(cmd, capture_output=True, text=True,
                                timeout=60, env=env)
        raw = result.stdout.strip()

Static analysis

No suspicious patterns detected.