Back to skill

Security audit

OpenClaw Zernio Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This Zernio analysis skill is mostly purpose-aligned, but it asks the agent to quietly fetch and analyze profile/network data with weak URL scoping.

Review this skill before installing. It should only fetch validated public Zernio URLs, should disclose when it is retrieving and analyzing profile or network information, and should avoid hidden activation for ambiguous requests. There is no evidence of malware, persistence, credential theft, or destructive behavior in the inspected files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:1
Finding

Unvalidated User-Supplied URL Passed to Network Fetch Tool

Content
View full analysis
Remediation
View remediation
str: parsed = urlparse(raw_url) if parsed.scheme != "https": raise ValueError("Only HTTPS URLs are permitted") if parsed.hostname != "zernio.com": raise ValueError("Only zernio.com URLs are permitted") if parsed.username or parsed.password or parsed.port not in (None, 443): raise ValueError("Credentials and nonstandard ports are prohibited") prefix = "/user/" if not parsed.path.startswith(prefix): raise ValueError("Not a Zernio profile URL") profile_id = parsed.path[len(prefix):].strip("/") if not PROFILE_ID_RE.fullmatch(profile_id): raise ValueError("Invalid profile identifier") return f"https://zernio.com/user/{quote(profile_id, safe='')}" ``` 8. Update the Skill instructions to state that `web_fetch` may only receive a canonical, validated Zernio URL. 9. Apply network-layer egress controls so the fetch tool cannot access private or metadata-service address ranges even if application validation fails. 10. Add tests c ...[truncated 159 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is configured to trigger on broad phrases such as general requests to "analyze," "summarize," or "check connections/engagement" related to Zernio, which can cause hidden or unintended activation outside a narrowly scoped user intent. Because the skill also instructs automatic external fetching and profile/network analysis, overbroad activation increases the chance of processing third-party data without clear user awareness or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation encourages fetching and analyzing external profile, post, company, job, and connection data from Zernio without warning users that this may involve sensitive personal or network information. In context, the danger is elevated because the skill emphasizes hidden activation and direct insight output, reducing transparency around when external data collection and analysis occurs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The inline comment states that the current call is a placeholder and that the real implementation uses subprocess-driven web_search/web_fetch. This creates an intent-code divergence because the documented intended behavior includes external process execution and likely network access, while the actual code only returns hardcoded local data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.