Back to skill

Security audit

Property Management Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent property-management purpose, but its autonomous emergency triage and repair-approval rules are under-specified in ways that could affect tenant safety and spending decisions.

Review this carefully before installing in a real property-management workflow. Require human review for emergencies, ambiguous maintenance reports, and repair quotes; replace the 00 spending cap with an explicit currency amount; document exactly what tenant data is sent to each integration; and use a pinned, verified ThumbGate install path instead of the mutable npx command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
setup-guide.md:3
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
Remediation
View remediation
thumbgate init --agent openclaw`. - Document the expected package publisher, official source repository, and trusted npm registry. - Provide a lockfile or another reproducible installation mechanism that verifies dependency versions and integrity hashes. - Review package entry points, lifecycle scripts, and transitive dependencies before recommending execution. - Run installation under a dedicated, least-privileged account and avoid invoking the command with `sudo` or an administrator shell. - Prefer downloading a signed release artifact and verifying its signature or checksum before execution. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:20
Finding

Emergency Classification Depends on an Incomplete Keyword Gate

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:21
Finding

Malformed Repair Spending Threshold Produces Ambiguous Authorization Behavior

Content
View full analysis
00 without a human landlord's explicit signature in ThumbGate. ``` ```markdown 2. **Spending Limit** — Block authorized repair work where the estimated cost exceeds 00. ``` ### Technical Analysis Both policy files specify the spending threshold as `00`, with no currency symbol, currency code, or meaningful configured amount. The sales copy similarly refers to a “Strict 00 Spending Cap.” This appears to be a corrupted or incomplete monetary value. The ambiguity can produce fail-open or fail-closed behavior depending on how the text is interpreted: - A parser may treat `00` as zero and block every nonzero repair. - A natural-language agent may infer an unintended value from surrounding context. - An implementation may reject the rule and apply no spending cap. - Different integrations may interpret the malformed value differently. Because this policy controls authorization of repair expenditure, the threshold must not depend on model inference or undocumented parsing behavior. ### Attack Path 1. A repair quote is submitted for authorization. 2. The agent or integration evaluates the malformed `00` threshold. 3. If the rule is ignored or interpreted as a larger inferred amount, work exceeding the intended cap may be authorized without required human approval. 4. If interpreted as zero, legitimate repairs are blocked and delayed. 5. Inconsistent interpretations across CRM, agent, and approval components can also bypass the intended human-signature control. No implementation is included in the reviewed project, so the exact runtime interpretation cannot be determined from the available files. ### Impact Assessment This issue does not directly gra ...[truncated 336 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill can autonomously create maintenance tickets in operational systems, but the description does not clearly warn that these actions may alter official property records and trigger downstream workflows. In this context, silent autonomous record creation is risky because mis-triaged or spoofed requests could create false emergencies, duplicate work orders, or inaccurate maintenance history.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly states it syncs tenant maintenance requests into Buildium, AppFolio, or Google Sheets, but it does not warn users that personally identifiable tenant data and maintenance details may be transmitted to third-party systems. This creates a transparency and privacy risk because operators may enable the skill without understanding where tenant data is stored, processed, or shared.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This plain-text sales copy describes the skill as handling 'tenant calls 24/7' and triaging 'routine stuff' versus 'real emergencies' without defining clear trigger phrases, scope boundaries, or exclusion conditions. The lack of specific activation criteria or negative examples makes the trigger conditions ambiguous for when the skill should activate or escalate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The copy promotes autonomous maintenance triage and emergency escalation without warning users about failure modes, review requirements, or the consequences of misclassification. In a property-management context, incorrect emergency/routine decisions can delay urgent repairs or trigger unnecessary dispatches, affecting safety, cost, and tenant welfare.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The setup guide instructs users to run npx thumbgate init --agent openclaw without pinning an exact package version. This causes the installer to fetch whatever package version is current at execution time, which creates a supply-chain risk: a compromised upstream package, malicious update, or typo/package takeover could execute arbitrary code on the operator's system during setup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.