Back to skill

Security audit

MiniMax MCP Tools

Security checks for vulnerabilities and agentic risk

Overview

The skill’s MiniMax search and image features are coherent, but its install path executes mutable third-party code and stores an API key in plain configuration without enough controls.

Install only if you are comfortable with MiniMax receiving your search queries and image inputs, including any local image files you ask it to analyze. Prefer a safer uv installation method, pin and verify the MCP package version, restrict the OpenClaw config file permissions, and use a limited MiniMax API key that can be rotated.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:19
Finding

Remote Installer Is Downloaded and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:45
Finding

Unpinned Third-Party MCP Package Is Automatically Resolved and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:47
Finding

API Key Is Stored in Plaintext OpenClaw Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The specific use of '| sh' creates an unsafe command chain that executes untrusted network content without validation. In a skill installation context, this is especially dangerous because users are primed to copy-paste commands, making remote code execution straightforward if the fetched content changes or is tampered with.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

  1. 安装 uvx(如果未安装):
bash
# macOS/Linux
curl -LsSf https://astral.sh/uv/install.sh | sh

# 验证安装
which uvx

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The entire skill documentation is presented only in Chinese, which effectively imposes a specific language on users without stating that the skill is Chinese-only or offering an alternative language. This can violate language/locale policy where user choice or explicit justification is required.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The image-understanding feature accepts either remote image URLs or local file paths, but the skill does not warn that image contents, file-derived data, or fetched remote resources may be transmitted to MiniMax for processing. This can lead users to expose sensitive local images or internal-only URLs without realizing the data leaves their environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation says users can simply ask the AI to search or analyze images and that the AI will automatically invoke the MCP tools. This broad invocation guidance can cause unintentional tool use on ambiguous prompts, increasing the chance that sensitive queries, URLs, or local image paths are sent to the external MiniMax service without clear user awareness at the moment of use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The web_search tool sends user queries to an external provider, but the skill description does not clearly disclose that fact. Users may unknowingly transmit sensitive terms, internal project names, credentials by mistake, or other private context to a third party.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

The installation instructions tell users to pipe a remotely fetched script directly into the shell. If the remote endpoint, network path, or hosting account is compromised, arbitrary code will execute immediately on the user's machine with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

  1. 安装 uvx(如果未安装):
bash
# macOS/Linux
curl -LsSf https://astral.sh/uv/install.sh | sh

# 验证安装
which uvx

Static analysis

No suspicious patterns detected.