Back to skill

Security audit

FactoriaGo

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate FactoriaGo integration, but it handles passwords, session cookies, API keys, reviewer comments, and manuscript edits in ways users should review carefully before installing.

Install only if you are comfortable giving this skill access to your FactoriaGo account, manuscripts, reviewer comments, and project files. Do not paste passwords or provider API keys into chat or shell commands; prefer the FactoriaGo web settings page for API-key setup, rotate any keys or sessions already exposed this way, and require previews or backups before allowing manuscript file updates.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/factoriago-client.js:98
Finding

Sensitive credentials exposed through command-line arguments

Content
View full analysis
'); const res = await req('POST', '/auth/login', { email, password }); ``` ```javascript case 'set-llm-config': { const [provider, model, apiKey] = args; if (!provider || !model || !apiKey) { return console.error( 'Usage: set-llm-config \n' + 'Providers: anthropic | openai | google | moonshot | zhipu | minimax\n' + 'Examples:\n' + ' set-llm-config anthropic claude-3-5-sonnet-20241022 sk-ant-xxx\n' + ' set-llm-config openai gpt-4o sk-xxx\n' + ' set-llm-config google gemini-2.0-flash AIza...' ); } if (!cookie) return console.error('❌ Not authenticated.'); const res = await req('POST', '/settings/llm', { primary_provider: provider, primary_model: model, primary_api_key: apiKey, }, cookie); ``` The associated documentation explicitly instructs users to supply secrets this way: ```bash node scripts/factoriago-client.js set-llm-config ``` ```markdown Via AI assistant: Tell your OpenClaw assistant your key and ask it to configure it for you ``` ### Technical Analysis The client obtains the FactoriaGo password and third-party LLM API key from `process.argv`. Command-line arguments may be: - Saved in interactive shell history. - Visible to process-monitoring or diagnostic tools while the command is running. - Captured by terminal session recording, automation logs, or debugging systems. - Retained in Agent prompts, tool-call transcripts, or conversation hi ...[truncated 1979 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/factoriago-client.js:103
Finding

Authenticated session cookie disclosed through standard output

Content
View full analysis
| grep "Cookie:" | cut -d' ' -f2-) ``` ### Technical Analysis After successful authentication, the client extracts the complete session cookie returned by the service and prints an executable shell command containing that cookie to standard output. A session cookie is a bearer credential: any party possessing a valid cookie may be able to act as the authenticated user without knowing the password. Terminal output can be copied, recorded, captured by Agent tool transcripts, retained by CI systems, or collected by centralized logging. Printing the full cookie therefore exposes an authenticated session through channels that do not need access to it. Using a session credential is necessary for subsequent authenticated API requests. Printing it in plaintext is not the least-privilege method of transferring or retaining that credential. ### Attack Path 1. The user runs the login command. 2. The client prints the complete FactoriaGo session cookie to stdout. 3. The outp ...[truncated 1141 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (28)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to 'tell your OpenClaw assistant your key' encourages users to disclose a live secret in conversational text without any warning about retention, logging, access scope, or safer alternatives. Chat channels are typically not appropriate secret-entry mechanisms, so this materially raises the risk of credential compromise.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Directing users to provide API keys to the assistant is a classic insecure secret-handling pattern. Even if the product later stores keys encrypted, the initial transmission through the assistant can expose the secret to intermediate systems, logs, analytics, or prompt history, making the context especially dangerous because the key belongs to another external service and may carry billing and data-access authority.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The FAQ reinforces the same unsafe behavior by normalizing secret sharing with the assistant as a supported setup path. Repetition in onboarding material increases the likelihood that users will comply, making accidental credential disclosure more probable and systemic rather than incidental.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
nAI). No data is sent to any third-party or unknown endpoints. The CLI script (`scripts/factoriago-client.js`) handles:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api.md (reported line 44)May include surrounding context.

GET /paper/tasks/by-paper/:paperId → tasks for a project POST /paper/tasks { paperId, title, description, priority } PUT /tasks/:taskId/rename { title } DELETE /tasks/:taskId

text

## Project Files (LaTeX)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Accepting an API key as a positional CLI argument exposes the secret to shell history, process listings, debugging tools, and potentially multi-user system inspection. In the context of a paper-revision assistant that handles third-party LLM credentials, this creates a direct pathway for credential theft and downstream abuse of the user’s model account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide says AI features require a BYOK configuration but does not clearly disclose that reviewer comments, manuscript text, and other uploaded content may be sent to external model providers for processing. In this academic context, that can expose unpublished research, peer review content, and potentially confidential or embargoed material without informed user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly instructs users to give a third-party AI provider API key to the assistant so it can configure the service on the user's behalf. This expands the skill into handling highly sensitive credentials, creating unnecessary secret exposure risk and increasing the chance of logging, prompt leakage, misuse, or replay of the key outside the intended destination.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill describes operational use of environment variables for authentication (FACTORIAGO_COOKIE) and instructs users to pass sensitive credentials and API keys to a local script, but it declares no explicit tool scope or permission boundary. In an agent environment, missing scope declarations can let the skill access or encourage handling of secrets without clear runtime restrictions, increasing the risk of credential exposure or overbroad execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation phrases include very generic academic tasks such as 'revise paper', 'reviewer comments', 'LaTeX editing', and 'paper submission', which can cause the skill to trigger in unrelated conversations. Because this skill also includes credential collection and external API workflows, accidental activation increases the chance that users are steered into sharing sensitive manuscript content, login details, or API keys when they did not intend to use this integration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 91)May include surrounding context.

js
// Login and save cookie
const res = await fetch('https://factoriago.com/api/auth/login', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ email, password }),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow tells users to paste raw reviewer comments into an analysis endpoint without any notice about transmitting potentially sensitive manuscript, reviewer, or unpublished research content to a backend service. In the academic context, reviewer feedback may contain confidential material, and undisclosed processing or retention can create privacy, confidentiality, and trust risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow explicitly instructs the agent to read and then overwrite paper files via API, but it does not require explicit user confirmation, preview, or backup before modifying user-authored content. In a document-revision skill, silent overwrites can cause unintended data loss, destructive edits, or submission-impacting changes, especially if the agent misinterprets a request or edits the wrong file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The login flow prints a reusable authenticated session cookie directly to stdout, which can be captured by terminal logs, shell recording, CI logs, shared terminals, or copy/paste leakage. Anyone obtaining that cookie may be able to impersonate the user for API calls until the session expires or is revoked.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes onboarding, FactoriaGo project/task/file management, and revision-analysis features, but this code also accepts and transmits a user's raw API key for external LLM providers. Managing users' third-party credentials is a materially broader capability than assisting with manuscript revision and is not explicitly declared in the skill purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document states the API base URL is https://editor.factoriago.com/api and explicitly says the app and API are hosted at editor.factoriago.com. However, the example script under 'Auth Flow' performs login against https://factoriago.com/api/auth/login, which conflicts with the earlier documentation and could mislead implementers about where authentication actually occurs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.