Back to skill

Security audit

Email Subject Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill does generate email subjects, but it also performs automatic payment API calls with an embedded merchant key and has supply-chain weaknesses users should review before installing.

Review this before installing or running it. Each normal invocation attempts a SkillPay charge unless --test is used, and the package includes a shared-looking merchant key in source. Use only in a controlled environment, avoid relying on the embedded key, verify the payment flow, and prefer pinned install/dependency sources over the documented mutable npx and HTTP mirror setup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:6
Finding

Hard-Coded Payment Merchant Credential

Content
View full analysis

Vulnerability Details

File Location: index.js:6-9 and credential use at index.js:48-55
Vulnerability Type: Hard-coded secret in distributed source code
Risk Level: High

Vulnerable Code

javascript
const CONFIG = {
  skillpay_api: 'https://api.skillpay.me/v1',
  merchant_key: process.env.SKILLPAY_MERCHANT_KEY || 'sk_91fff75ae2a7a71f8eceadcbcd816e24d57e58d9d04ccca45f0b3856af130aea',
  price_per_use: 0.001,
  currency: 'USDT'
};

The credential is subsequently sent to the payment service:

javascript
const response = await axios.post(`${CONFIG.skillpay_api}/billing/charge`, {
  amount: CONFIG.price_per_use,
  currency: CONFIG.currency,
  merchant_key: CONFIG.merchant_key,
  description: 'Email subject generation by Sloan'
}, { headers: { 'Content-Type': 'application/json' }, timeout: 10000 });

Technical Analysis

A live-looking SkillPay merchant key is embedded directly in the distributed JavaScript source. Environment-variable support does not protect the default credential because every person who downloads the package can read and reuse the fallback value.

The key is supplied as an authentication or merchant-identification value in payment requests. Consequently, its effective permissions depend on the server-side authorization implemented by api.skillpay.me. The available code does not establish that the key grants account administration or fund withdrawal privileges, but it does establish that the package distributes the value used when submitting billing operations.

Public documentation also advertises the embedded key as the default, so the exposure is intentional from a functional perspective but remains an insecure credential-management practice.

Attack Path

  1. An attacker downloads the public skill package or reads index.js.
  2. The attacker extracts the sk_... merchant credential.
  3. The attacker creates independent requests to the SkillPay b ...[truncated 846 chars]
Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed merchant key.
  2. Remove the fallback credential from the source code and repository history.
  3. Require SKILLPAY_MERCHANT_KEY to be supplied through a protected environment variable or operating-system credential store, and fail safely when it is absent.
  4. Do not distribute a shared merchant secret to clients. Prefer a server-mediated payment design in which an authenticated backend retains the credential and creates narrowly scoped, short-lived payment authorizations.
  5. Ensure the payment server determines the merchant identity from authenticated credentials rather than trusting a client-controlled request-body field.
  6. Apply least-privilege scopes, transaction limits, replay protection, rate limiting, request signing, and anomaly monitoring.
  7. Add secret scanning to source-control and release pipelines to prevent future credential publication.

T08 · Insecure Dependencies

Warning
Location
package-lock.json:19
Finding

Dependency Archives Retrieved Through Plaintext HTTP Mirror

Content
View full analysis

Vulnerability Details

File Location: package-lock.json:19-294
Vulnerability Type: Insecure dependency source and transport
Risk Level: Medium

Vulnerable Code

The lockfile retrieves Axios and all other locked dependencies from a third-party mirror over plaintext HTTP. One representative entry is:

json
"node_modules/axios": {
  "version": "1.13.6",
  "resolved": "http://mirrors.tencentyun.com/npm/axios/-/axios-1.13.6.tgz",
  "integrity": "sha512-ChTCHMouEe2kn713WHbQGcuYrr6fXTBiu460OTwWrWob16g1bXn4vtz07Ope7ewMozJAnEquLk5lWQWtBig9DQ==",
  "license": "MIT",
  "dependencies": {
    "follow-redirects": "^1.15.11",
    "form-data": "^4.0.5",
    "proxy-from-env": "^1.1.0"
  }
}

Other dependencies use the same pattern, for example:

json
"resolved": "http://mirrors.tencentyun.com/npm/asynckit/-/asynckit-0.4.0.tgz"

Technical Analysis

Plaintext HTTP does not authenticate the package server and does not protect dependency downloads against interception or modification. The configured source is also a third-party mirror rather than the standard npm registry, adding another supply-chain trust dependency.

The SHA-512 integrity values materially reduce the immediate risk: an attacker who can only intercept network traffic cannot transparently substitute a different archive that does not match the committed hash. However, HTTP still permits denial of service and rollback or substitution attempts, and compromise becomes possible where the attacker can also modify the lockfile, influence newly generated lock metadata, exploit a package-manager integrity weakness, or compromise the mirror content corresponding to trusted metadata.

Because these packages are loaded into the Node.js process, successful dependency substitution would execute with the same operating-system permissions as the CLI.

Attack Path

  1. A developer or deployment system installs the project dependencies.

...[truncated 1152 chars]

Remediation
View remediation

Remediation Suggestions

  1. Regenerate the lockfile using https://registry.npmjs.org/ or an organization-approved registry protected by HTTPS.
  2. Replace every plaintext http:// dependency URL with an authenticated HTTPS source.
  3. Configure npm explicitly through a repository-controlled .npmrc and CI policy so future lockfiles cannot silently use unapproved mirrors.
  4. Continue retaining and validating package integrity hashes.
  5. Require code review for lockfile changes, especially modifications to resolved, version, and integrity fields.
  6. Use reproducible clean-environment installation with npm ci.
  7. Where supported, verify package provenance or signatures and monitor dependencies for known vulnerabilities.

T08 · Insecure Dependencies

Warning
Location
README.md:13
Finding

Installation Instructions Execute an Unpinned Mutable Package Release

Content
View full analysis

Vulnerability Details

File Location: README.md:13-17
Vulnerability Type: Unpinned third-party installer execution
Risk Level: Medium

Vulnerable Code

bash
npx clawhub@latest install email-subject-generator

Technical Analysis

The documented installation command instructs users to execute the mutable latest release of the third-party clawhub package. npx may download and run the selected package when it is not already installed locally.

Because the latest tag can be changed after this skill has been reviewed, the code executed by users is not fixed to a known audited version. A future compromised maintainer account, registry package takeover, or malicious release could therefore turn the installation instruction into an arbitrary code-execution path.

The audit did not establish that the current clawhub release is malicious. The vulnerability is the absence of version pinning and provenance controls in a command that executes externally maintained code.

Attack Path

  1. An attacker compromises the clawhub package publisher, registry entry, or release process.
  2. The attacker publishes a malicious version and assigns it the latest distribution tag.
  3. A user follows the installation command from the project README.
  4. npx resolves clawhub@latest, downloads the attacker-controlled release, and executes its CLI.
  5. The malicious package runs with the permissions of the user performing the installation.

Impact Assessment

A successful supply-chain compromise can execute arbitrary code under the installing user's account. Accessible scope may include local project files, user-readable credentials and environment variables, OpenClaw configuration, network services, and any other resources available to that account.

Root or administrator privileges are not inherently obtained; the effective privilege level is determined by the account used to run the documented command ...[truncated 1 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace clawhub@latest with an exact, reviewed version, such as clawhub@x.y.z.
  2. Document the expected package source, version, checksum, and provenance information.
  3. Prefer installing a pinned dependency through a reviewed lockfile and invoking the local executable rather than allowing npx to resolve a mutable release dynamically.
  4. Use registry provenance or signature verification where available.
  5. Review release notes and package contents before updating the pinned version.
  6. Avoid instructing users to execute installation commands with elevated privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose is a simple content-generation utility, but the metadata indicates payment processing, embedded credential fallback, and gateway token use for external API access. This mismatch is dangerous because users may invoke the skill expecting local text generation while it can instead trigger billing flows and interact with unrelated external services using sensitive credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's advertised purpose is simple email subject generation, but it performs an automatic charge against an external billing API before doing the core task. This creates an undisclosed financial side effect and can result in unauthorized or unexpected charges, especially because execution is tied directly to CLI use rather than an explicit user confirmation flow.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins axios 1.13.6, which the scanner reports as carrying multiple advisories including SSRF, proxy bypass, and prototype-pollution-related man-in-the-middle/credential theft issues. In a skill context, HTTP client libraries are often used to call remote APIs, so a vulnerable axios version can expose secrets, enable unintended outbound requests, or allow hostile network interactions if attacker-controlled URLs, redirects, or proxy settings are involved.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
90% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection via unescaped multipart field names and filenames. If any part names or filenames are derived from untrusted input, an attacker may be able to manipulate multipart boundaries or inject crafted headers, potentially leading to request smuggling, header injection, or malformed upstream processing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
84% confidence
Finding

The package depends on axios via a broad version range, and static analysis indicates resolution to a version with multiple known advisories, including SSRF- and prototype-pollution-related issues. If this skill performs outbound HTTP requests using untrusted input, those flaws could enable request redirection, proxy bypass, credential leakage, or response manipulation; the absence of application code limits certainty on exploitability, but the dependency risk is real.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub@latest install email-subject-generator, which pulls and executes the latest published version of a package at install time without pinning to a reviewed version. If the upstream package is compromised, typosquatted, or a malicious update is published, users could execute attacker-controlled code on their systems during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that usage is pay-per-use and that payment is handled automatically via an embedded merchant key, but it does not clearly warn users when charges occur, what authorizations are granted, or what billing side effects installation or execution may trigger. In a CLI skill context, hidden or poorly disclosed automatic billing increases the risk of unexpected charges and reduces informed consent, especially when combined with a one-command install flow.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises access to environment variables but does not declare any explicit tool scope or permissions boundary. In a skill ecosystem, undeclared env access weakens least-privilege controls and can expose secrets or enable behaviors the user did not reasonably expect from a simple email subject generator.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation names sensitive credential variables such as merchant and gateway tokens without warning users about secure handling, storage, or transmission. In the context of a low-risk-seeming marketing skill, this increases the chance users will supply secrets without understanding that the skill may use them for billing or remote API calls.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 7)May include surrounding context.

js
const { spawn } = require('child_process');

const CONFIG = {
  skillpay_api: 'https://api.skillpay.me/v1',
  merchant_key: process.env.SKILLPAY_MERCHANT_KEY || 'sk_91fff75ae2a7a71f8eceadcbcd816e24d57e58d9d04ccca45f0b3856af130aea',
  price_per_use: 0.001,
  currency: 'USDT'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hardcoded merchant key fallback is embedded in the source code, exposing a live-looking secret to anyone who can read the file. This can enable unauthorized use of the payment account, fraudulent charges, abuse of billing infrastructure, and credential reuse risk if the key is valid elsewhere.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill invokes a local subprocess to run another agent tool for a task that appears simple and self-contained. Spawning an external agent increases attack surface, introduces trust and execution dependencies outside the reviewed code, and may allow prompt-influenced behavior or unintended local capability use through the delegated tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill transmits billing data to an external payment API as part of normal execution without a strong user-facing warning or explicit consent step. Even if the transmitted fields are limited, the behavior can surprise users and create privacy, financial, and trust issues because payment processing is hidden behind a content-generation command.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code launches the external 'openclaw' executable to process the user-provided topic, which is a subprocess operation covered by the warning requirement. The runtime output only says it is generating subjects, but does not clearly disclose that it is invoking another local agent tool or command.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON manifest identifies the skill as "email-subject-generator" but provides no accompanying trigger phrases, activation boundaries, or exclusion conditions. For manifest files, the absence of specific invocation scope can make activation behavior ambiguous if this name is used as the basis for skill discovery or routing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
86% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. If this skill sends authenticated HTTP requests and follows redirects automatically, secrets such as API keys or bearer tokens could be disclosed to an attacker-controlled domain.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is specified with a caret range (^1.6.0), which allows newer minor and patch versions to be installed without review. In a skill package, this weakens supply-chain control and can unexpectedly pull in buggy or malicious releases, though by itself it is generally a hardening issue rather than an immediately exploitable flaw.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"author": "Matt",
  "license": "MIT",
  "dependencies": {
    "axios": "^1.6.0"
  },
  "openclaw": {
    "skill": true,

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:28

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.js:8