Back to skill

Security audit

admapix

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent AdMapix analytics skill whose main risks are expected third-party API sharing, API-key handling, and one unpinned install example, not hidden malicious behavior.

Before installing, make sure you trust AdMapix and the ClawHub/OpenClaw install path. Avoid sending confidential campaign plans, private app identifiers, or personal user IDs unless you intend to share them with AdMapix, keep `SKILLBOSS_API_KEY` out of logs and chat output, and prefer a pinned or already trusted installer instead of the unpinned `npx` command shown in the Chinese README.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README_CN.md:20
Finding

Unpinned Third-Party Package Execution via npx

Content
View full analysis

Vulnerability Details

File Location: README_CN.md, line 20
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

bash
npx clawhub install admapix

Technical Analysis

The installation command asks npx to resolve and execute the clawhub package without specifying a reviewed version or verifying its integrity. Depending on the local npm configuration and cache state, npx may download the package from the configured registry and immediately run its CLI code.

The project provides no version pin, lockfile, integrity hash, or registry restriction for this command. Consequently, the code executed during installation can change after this Skill has been reviewed. This creates a supply-chain trust boundary outside the audited project.

The finding does not prove that the current clawhub package is malicious. The vulnerability is that the documented installation process does not ensure that users execute the same reviewed package release.

Attack Path

  1. An attacker compromises the package publisher, registry account, package distribution channel, or a future release of the package.
  2. The attacker publishes a malicious version under the package name resolved as clawhub.
  3. A user follows the installation command in README_CN.md.
  4. npx resolves and downloads the attacker-controlled version.
  5. The malicious package's CLI or lifecycle code executes with the privileges of the user running the command.
  6. That code can perform actions allowed by the user's operating-system account before or while pretending to install the Skill.

Impact Assessment

Successful exploitation could result in arbitrary local code execution with the installing user's privileges. Depending on those privileges and the host environment, the malicious package could access user-readable files and environment variables, modify user-owned configuration, install additi ...[truncated 301 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to a specific version that has been reviewed:

    bash
    npx --yes clawhub@<reviewed-version> install admapix
    
  2. Document the authoritative npm registry and package publisher so users can verify the package source.

  3. Provide a published integrity hash, signed release, or equivalent provenance mechanism for the approved package artifact.

  4. Review each version before updating the documented pin.

  5. Prefer an already installed and trusted CLI where appropriate, and provide instructions for verifying its version before use.

  6. Keep installation commands consistent across localized README files so all users receive the same hardened procedure.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
**Reuse data:** If the user asks follow-up questions about already-fetched data, analyze existing results first. Only make new API calls when needed.

## Output Guidelines

1. **Language consistency** — ALL output (headers, labels, insights, hints, errors, disclaimers) must match the user's detected language. See "Language Handling" section above.
2. **Route-appropriate output** — Don't force H5 links on analytical questions; don't dump tables for browsing

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to install and execute the skill via npx clawhub install admapix without pinning a specific version. This creates a supply-chain risk because a later compromised or maliciously replaced package version could be fetched and run implicitly at install time. The skill context does not mitigate this risk, since installation is the point where untrusted code may first execute.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list is extremely broad and includes common phrases such as 'market analysis', 'revenue', 'search ads', and 'competitor analysis', which can cause the skill to activate for ordinary user requests that may not clearly imply consent to use this third-party integration. Over-broad invocation increases the chance of unintended external API calls and data disclosure to api.admapix.com when the user did not specifically intend to use this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires the assistant to detect the user's language from their first message and maintain it, which enforces a locale/language choice without explicitly offering the user an option. This matches the policy concern around forcing a specific language behavior absent opt-in or a documented justified constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint indicates all requests are directed to a third-party domain outside the local trust boundary. Even without direct credential leakage in output, this creates dependency and privacy risk because user requests are processed externally and may be retained or correlated by that provider.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

bash
# GET
curl -s "https://api.admapix.com/api/data/{endpoint}?{params}" \
  -H "X-API-Key: $SKILLBOSS_API_KEY"

# POST

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint indicates all requests are directed to a third-party domain outside the local trust boundary. Even without direct credential leakage in output, this creates dependency and privacy risk because user requests are processed externally and may be retained or correlated by that provider.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

bash
# GET
curl -s "https://api.admapix.com/api/data/{endpoint}?{params}" \
  -H "X-API-Key: $SKILLBOSS_API_KEY"

# POST

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The POST example shows arbitrary JSON payloads being sent to the same external API, which broadens the egress surface beyond simple URL queries. In the context of this skill's autonomous multi-step workflows, that means user requests can trigger richer data submission to an outside service without a separate confirmation boundary.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
-H "X-API-Key: $SKILLBOSS_API_KEY"

# POST
curl -s -X POST "https://api.admapix.com/api/data/{endpoint}" \
  -H "X-API-Key: $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{...}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly supports sending a delivery object containing externalUserId for H5 page generation, but provides no privacy notice, minimization guidance, or restrictions on what identifier may be sent. This can lead integrators to transmit persistent user identifiers to a third-party API without consent, lawful basis, or data handling safeguards, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 122)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 139)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 177)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 191)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 192)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 193)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api-creative.md (reported line 194)May include surrounding context.

md
"playHtmlFp": [],
      "playHtmlUrl": [],
      "demoadCnt": 1,
      "appList": [
        {
          "id": "6498883328",
          "cnt": null,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file instructs use of an external API endpoint and an API key for authenticated requests, which implies transmitting app query data to a third-party service. The document provides operational details but does not include any warning about privacy, external data sharing, or handling of authentication credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

该 README 说明用户“直接对 AI 助手说”这些自然语言请求即可使用技能,但未定义明确的激活条件、专用触发词或不触发的场景。示例中如“分析一下 Temu”“对比 Temu 和 SHEIN”属于常见自然表达,若宿主环境依赖语义匹配,可能与日常对话重叠并产生误调用。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file documents use of X-API-Key: $SKILLBOSS_API_KEY, which indicates access to a sensitive credential. The document does not include any warning or handling guidance about protecting the API key, despite SQP-2 applying to markdown files that describe behaviors affecting privacy or system integrity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The file explicitly states that query.country_info.country_name is a country name in Chinese, which imposes a locale-specific output expectation in the documentation. Because no user choice, opt-in, or justification for the locale constraint is provided, this may violate the language/locale policy under SQP-3.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs use of a third-party API endpoint with an API key and user-supplied search terms/identifiers, but does not warn that those queries and identifiers will be transmitted to an external service. In an agent skill context, this can cause unintentional disclosure of user interests, app identifiers, or company lookups to a vendor, reducing transparency and potentially violating privacy expectations or organizational data-handling rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file explicitly instructs use of an API key from the SKILLBOSS_API_KEY environment variable, which involves sensitive credentials. The document describes the authentication mechanism but does not include any warning or handling guidance about protecting the key, avoiding exposure in logs, or ensuring users understand that authenticated requests will be made.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The intent mapping section provides only Chinese user utterance examples and does not clarify whether the skill is Chinese-only or whether other languages are supported. This can amount to an undocumented language/locale constraint unless the skill explicitly offers language choice or justifies the locale limitation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file maps generic phrases such as "default," "show more," "maximum," and "today" to behavior-changing parameters, but it does not clarify the scope in which these phrases should be interpreted or provide exclusion examples. In a skill-retrieval or natural-language mapping context, these everyday phrases are broad enough to cause unintended matches if reused outside the intended parameter-setting flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
52% confidence
Finding

The file requires a specific date format, "YYYY-MM-DD," which may be interpreted as a locale-format constraint. However, this appears more like a technical normalization requirement than a clear language or locale policy violation, so confidence is limited.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.