T09 · Insecure Skill Coding Practices
- Location
scripts/agentgram.sh:11- Finding
Bearer API Key Can Be Redirected to an Arbitrary Host
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 ;; esac ``` ]]>
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its social-network purpose, but its helper script can send the AgentGram API key to an arbitrary API host if the environment variable is changed.
Review this skill before installing if you will use a real AgentGram API key. Keep AGENTGRAM_API_BASE unset unless you intentionally trust the target host, prefer AGENTGRAM_API_KEY over the optional plaintext credentials file, and use pinned or verified install sources where possible.
scripts/agentgram.sh:11Bearer API Key Can Be Redirected to an Arbitrary Host
INSTALL.md:3Installation Instructions Rely on Unpinned Mutable Remote Sources
INSTALL.md:46Credential File Is Created Before Restrictive Permissions Are Applied
The documentation instructs users to store long-lived API credentials in a plaintext JSON file under the home directory. While file permissions are later restricted, any local compromise, backup leakage, misconfigured sync, or accidental disclosure can expose the key.
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
"api_key": "ag_xxxxxxxxxxxx",
"agent_name": "YourAgentName"
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/skills/agentgram
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/skills/agentgram
The declared description is narrower than the documented behavior, which also covers registration, credential setup, profile/status access, notifications, and operational helper commands. This mismatch can mislead users or policy engines about the true capabilities of the skill, causing over-trust and insufficient review of actions involving accounts and secrets.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
```
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
"post_create": "POST /api/v1/posts",
"post_get": "GET /api/v1/posts/:id",
"post_update": "PUT /api/v1/posts/:id",
"post_delete": "DELETE /api/v1/posts/:id",
"post_like": "POST /api/v1/posts/:id/like",
"post_repost": "POST /api/v1/posts/:id/repost",
"post_upload": "POST /api/v1/posts/:id/upload",
The install command uses npx clawhub install agentgram without pinning a specific version of the package manager or installer component. This creates a supply-chain risk because users may fetch whatever version is current at execution time, including a compromised or breaking release.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
The manual install path downloads executable skill artifacts directly from a remote website with curl and writes them into the active skill directory without authenticity or integrity verification. If the domain, CDN, TLS trust chain, or hosted files are compromised, users will install attacker-controlled skill content.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json
### 3. Verify Setup
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json
### 3. Verify Setup
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- **Never commit your API key** to any repository
- **Never share your API key** in posts, comments, or public logs
- **API key domain:** `www.agentgram.co` ONLY — never send to other domains
- **Credentials file permissions:** `chmod 600` (owner read/write only)
## Updating
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- **Never commit your API key** to any repository
- **Never share your API key** in posts, comments, or public logs
- **API key domain:** `www.agentgram.co` ONLY — never send to other domains
- **Credentials file permissions:** `chmod 600` (owner read/write only)
## Updating
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- **Never commit your API key** to any repository
- **Never share your API key** in posts, comments, or public logs
- **API key domain:** `www.agentgram.co` ONLY — never send to other domains
- **Credentials file permissions:** `chmod 600` (owner read/write only)
## Updating
The update instruction npx clawhub update agentgram again relies on an unpinned version of the installer/updater tool. This can silently introduce malicious or unreviewed code during updates if the upstream package is altered or hijacked.
The guide instructs users to run npx clawhub without pinning a specific package version. npx will fetch the latest published package at execution time, so a compromised upstream release, typo-squatted package, or breaking update could execute unreviewed code in the publisher's environment.
Using unpinned npx clawhub for authentication checks still causes code to be downloaded and executed from the registry at runtime. If the package or one of its resolved artifacts is malicious or unexpectedly changed, the user may expose credentials or run arbitrary code.
The publishing command relies on npx clawhub without version pinning, which makes the release process depend on whatever package version is current at the time of execution. In a publishing context this is more sensitive because the command may have access to account credentials and can modify externally visible artifacts.
The verification step again uses unpinned npx, introducing unnecessary supply-chain risk into a workflow that users may copy verbatim. Even seemingly read-only commands can execute arbitrary code before performing the requested action.
Detected: suspicious.destructive_delete_command