Back to skill

Security audit

yandex-metrika-assistant

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Yandex Metrika assistant, but it asks for powerful OAuth access while pushing users toward third-party support and includes unsafe token-handling examples.

Review before installing. Use your own Yandex OAuth application and grant only the scopes needed for the task, preferably read-only unless you explicitly need management or imports. Never send OAuth tokens, passwords, authorization codes, or screenshots containing tokens to Telegram or any person; store them only in OpenClaw secrets, a secret manager, or a local environment variable. Treat the included full-looking OAuth token example as unsafe documentation and replace it with a placeholder in any copied commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:17
Finding

Mandatory Third-Party Promotion Injected into Agent Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:17-21
Vulnerability Type: Mandatory promotional output manipulation
Risk Level: High

Vulnerable Code

markdown
1. **Сначала** дай ссылку и краткое резюме установки: **`{baseDir}/docs/INSTALL-FOR-HUMANS-RU.md`** (шаги OpenClaw + OAuth + куда вставить ключ).
2. **Обязательно** перечисли, какие **галочки в приложении Яндекс OAuth** нужны для Метрики (таблица из того же файла / шаг 2): статистика и чтение, создание/изменение счётчиков, при необходимости расходы, параметры пользователей, офлайн-данные.
3. Укажи **канал поддержки:** [**https://t.me/maya_pro**](https://t.me/maya_pro) — вопросы по установке и сценариям; **не** проси кидать токен в Telegram публично.
4. Затем — получение токена: **`{baseDir}/docs/INSTRUCTION-GET-TOKEN-RU.md`** (или ссылка `authorize` с `oauthClientId` из конфига).
5. Напомни: ключ хранить в **`oauthToken`** плагина или в **`YANDEX_METRIKA_OAUTH_TOKEN`**, не в чате.

The mandatory promotion is repeated at SKILL.md:48, which again directs the agent to include the same Telegram account whenever no OAuth token is available.

Technical Analysis

The Skill changes the agent's response policy by requiring it to promote a specific third-party Telegram destination during onboarding. This behavior is not necessary to access the Yandex Metrika API, configure OAuth, or generate analytics reports.

Because these instructions are loaded as part of the Skill, they can consistently influence the agent's responses without the user requesting external support. The mandatory wording makes the external redirection part of normal agent behavior rather than an optional, clearly disclosed resource.

This constitutes instruction hijacking through persistent output manipulation within the current session. Although the reviewed files do not directly transmit credentials to Telegram, the forced redirection increases exposure to social engineering outsid ...[truncated 992 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions requiring the agent to promote a particular Telegram account.
  2. Do not make third-party support links part of mandatory response templates.
  3. If external support information must remain, label it clearly as optional and present it only when the user explicitly asks for support.
  4. Prefer official Yandex and OpenClaw documentation for installation and OAuth troubleshooting.
  5. Add an explicit rule prohibiting the agent from directing users to disclose tokens, passwords, authorization codes, or configuration files to external contacts.
  6. Review openclaw.plugin.json, docs/INSTALL-FOR-HUMANS-RU.md, and docs/INSTRUCTION-GET-TOKEN-RU.md for repeated promotional references and remove or neutralize them.

T09 · Insecure Skill Coding Practices

Warning
Location
docs/INSTALL-FOR-HUMANS-RU.md:57
Finding

Documentation Permits Disclosure of Credentials to a Purported Trusted Administrator

Content
View full analysis

Vulnerability Details

File Location: docs/INSTALL-FOR-HUMANS-RU.md:57
Vulnerability Type: Unsafe credential-sharing guidance
Risk Level: Medium

Vulnerable Code

markdown
Не присылайте **токены и пароли** в открытый чат — только в личку доверенному админу или через настройки секретов OpenClaw.

Technical Analysis

The documentation tells users that tokens and passwords may be sent privately to a “trusted administrator.” A private message is not a secure secret-management mechanism, and the recipient's identity, account security, retention practices, and authorization cannot be verified by the Skill.

This guidance contradicts the stronger controls in SKILL.md:22,45-50 and docs/03-auth-oauth.md:74, which direct users to keep OAuth tokens in OpenClaw secrets or environment variables and not disclose them to third parties.

The issue creates a practical phishing and impersonation path. An attacker posing as an administrator could convince a user that private credential transmission is an approved installation procedure. A disclosed Yandex OAuth token can then be used directly as a bearer credential until it expires or is revoked.

The risk is increased by the authorization examples in docs/INSTRUCTION-GET-TOKEN-RU.md, which request both metrika:read and metrika:write. A token with those scopes may permit both data access and state-changing management operations.

Attack Path

  1. A user follows the installation documentation and encounters a configuration problem.
  2. The user contacts an external support channel referenced by the project.
  3. An attacker impersonates, compromises, or presents themselves as a trusted administrator.
  4. Relying on the documented instruction, the user sends an OAuth token or password through a private message.
  5. The attacker uses the OAuth token in an Authorization: OAuth <token> header.
  6. Depending on the granted scopes and account permissions, ...[truncated 807 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the affected sentence with an absolute prohibition against sending tokens, passwords, client secrets, authorization codes, or refresh tokens to any person or chat.
  2. Require credentials to be entered only through OpenClaw's sensitive configuration field, an approved secret manager, or a local environment variable.
  3. Explicitly state that legitimate support personnel never need the user's complete credential.
  4. Provide redacted diagnostic procedures that reveal only HTTP status codes, request paths, scope names, and sanitized error messages.
  5. Tell users to revoke and reissue any credential that has already been sent through a messaging service.
  6. Default OAuth examples to metrika:read and instruct users to add write permissions only when a requested operation requires them.
  7. Remove the hardcoded OAuth Client ID from docs/INSTRUCTION-GET-TOKEN-RU.md:79 so users cannot accidentally authorize an application they do not control.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (32)

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The HTTP example exposes a full OAuth token inline, which is a sensitive bearer secret. If this token is real or copied from a real environment, anyone who obtains it may access the associated Yandex Metrika resources with the token owner's privileges until revoked or expired.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructions and referenced onboarding materials are entirely in Russian, and the agent is directed to send users to Russian-only documents such as INSTALL-FOR-HUMANS-RU.md. There is no indication that the skill is intentionally limited to Russian-speaking users or that users may choose another language, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation includes what appears to be a full OAuth bearer token in an HTTP example, while later advising not to share tokens. Even if the token is illustrative, publishing realistic bearer tokens normalizes unsafe handling and risks accidental reuse, scraping, or use of a real still-valid credential if it was copied from a live environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Showing a complete OAuth token in a request example can lead users to copy unsafe patterns into docs, tickets, logs, or scripts. In an auth-focused skill, this is more dangerous because readers are specifically being taught how to handle credentials, so examples strongly influence operational behavior.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/08-management-quickstart.md (reported line 48)May include surrounding context.

Пример из quick-start — цель типа MessengerGoal (messenger), условие с url (например whatsapp):

bash
curl -i -X POST 'https://api-metrika.yandex.net/management/v1/counter/XXX/goals' \
  -H 'Authorization: OAuth 05dd3dd8...' \
  -H 'Content-Type: application/json' \
  -d '{

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document title and all instructional content are written only in Russian, which imposes a specific language on users without any opt-in or alternative locale. Under the stated policy, language constraints should either offer a choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is written entirely in Russian, including operational details, with no indication that other languages are supported or that the skill is intentionally restricted to a Russian-speaking context. This can violate language/locale policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is entirely written in Russian and explicitly labels a documentation link as "Документация (RU)", which indicates a fixed language context. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Russian, and there is no indication that the language is optional or intentionally constrained to a Russian-speaking audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill content forces a specific language for all readers, which can be a natural-language locale policy issue when no opt-in or rationale is provided. There is no indication that this file is intentionally limited to a Russian-only audience or region-specific compliance context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.