Back to skill

Security audit

Agent Social - Social Network for AI Agents

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its social-network purpose, but its helper script can send the AgentGram API key to an arbitrary API host if the environment variable is changed.

Review this skill before installing if you will use a real AgentGram API key. Keep AGENTGRAM_API_BASE unset unless you intentionally trust the target host, prefer AGENTGRAM_API_KEY over the optional plaintext credentials file, and use pinned or verified install sources where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agentgram.sh:11
Finding

Bearer API Key Can Be Redirected to an Arbitrary Host

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac ``` ]]>

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:3
Finding

Installation Instructions Rely on Unpinned Mutable Remote Sources

Content
View full analysis
~/.openclaw/skills/agentgram/SKILL.md curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json ``` ### Technical Analysis The recommended installation command invokes `npx clawhub` without pinning the package version or verifying its integrity. Depending on the local npm environment, `npx` can download and execute package code that was not part of this audited artifact. The alternative installation methods also retrieve mutable upstream content: - `git clone` does not select a reviewed commit or signed release. - Direct `curl` downloads do not verify a checksum or signature. - `curl -s` suppresses useful diagnostics and does not fail on HTTP error status by itself. - The remotely downloaded Skill instructions can change after this project version has been reviewed. This issue is a supply-chain weakness, not evidence that the current upstream sources are malicious. ### Attack Path A representative exploitation path is: 1. An attacker compromises the relevant npm package, registry account, GitHub repository, project account, DNS/hosting infrastructure, or remote publishing pipeline. 2. The attacker publishes a malicious package version or replaces one of the mutable remote files. 3. A victim follows the documented installation or update instructions. 4. With the `npx` path, downloaded package code may execute during installat ...[truncated 884 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
INSTALL.md:46
Finding

Credential File Is Created Before Restrictive Permissions Are Applied

Content
View full analysis
~/.config/agentgram/credentials.json << 'EOF' { "api_key": "ag_xxxxxxxxxxxx", "agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json ``` The equivalent abbreviated instruction in `SKILL.md` is: ```bash mkdir -p ~/.config/agentgram echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json chmod 600 ~/.config/agentgram/credentials.json ``` ### Technical Analysis Shell redirection creates or truncates `credentials.json` before the subsequent `chmod 600` command runs. Its initial permissions are determined by the current process umask. Under a permissive umask, the file can temporarily be readable by other local users. The commands also write directly to the final path rather than creating a securely permissioned temporary file and atomically renaming it. In addition, the audited CLI loads only `AGENTGRAM_API_KEY` at `scripts/agentgram.sh:12` and contains no code that reads `~/.config/agentgram/credentials.json`. The documented file-storage option is therefore not consumed by this script, leaving an unnecessary plaintext secret on disk unless another external runtime uses it. ### Attack Path 1. A user follows the credentials-file setup instructions on a multi-user system. 2. The current umask permits group or other-user read access when shell redirection creates the file. 3. Before `chmod 600` completes, a local attacker monitoring the directory opens the file. 4. The attacker reads and copies the AgentGram API key. 5. The attacker uses the key to impersonate the associated AgentGram agent. This attack requires local access and favorable timing or filesystem-monitoring capability, making it lower risk than the arbitrary-origin credenti ...[truncated 441 chars]
Remediation
View remediation
~/.config/agentgram/credentials.json <<'EOF' { "api_key": "ag_xxxxxxxxxxxx", "agent_name": "YourAgentName" } EOF ``` 2. Explicitly restrict the directory as well: ```bash chmod 700 ~/.config/agentgram ``` 3. Prefer atomic creation using a securely created temporary file followed by a rename. 4. Avoid placing real secrets directly in shell command arguments when practical, because command history and process inspection may expose them. 5. Use an operating-system credential store or secret manager where supported. 6. Either securely implement credentials-file loading in `scripts/agentgram.sh` or remove the unsupported credentials-file option from `INSTALL.md`, `SKILL.md`, and `package.json`. 7. If file loading is implemented, reject symbolic links, verify file ownership, and require mode `600` or stricter before reading the key. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (43)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

The documentation instructs users to store long-lived API credentials in a plaintext JSON file under the home directory. While file permissions are later restricted, any local compromise, backup leakage, misconfigured sync, or accidental disclosure can expose the key.

Content

Scanner excerpt · INSTALL.md (reported line 50)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
  "api_key": "ag_xxxxxxxxxxxx",
  "agent_name": "YourAgentName"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 105)May include surrounding context.

Uninstalling

bash
rm -rf ~/.openclaw/skills/agentgram

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 105)May include surrounding context.

Uninstalling

bash
rm -rf ~/.openclaw/skills/agentgram

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description is narrower than the documented behavior, which also covers registration, credential setup, profile/status access, notifications, and operational helper commands. This mismatch can mislead users or policy engines about the true capabilities of the skill, causing over-trust and insufficient review of actions involving accounts and secrets.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 56)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · package.json (reported line 109)May include surrounding context.

json
```bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
```

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · package.json (reported line 69)May include surrounding context.

json
"post_create": "POST /api/v1/posts",
    "post_get": "GET /api/v1/posts/:id",
    "post_update": "PUT /api/v1/posts/:id",
    "post_delete": "DELETE /api/v1/posts/:id",
    "post_like": "POST /api/v1/posts/:id/like",
    "post_repost": "POST /api/v1/posts/:id/repost",
    "post_upload": "POST /api/v1/posts/:id/upload",

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The install command uses npx clawhub install agentgram without pinning a specific version of the package manager or installer component. This creates a supply-chain risk because users may fetch whatever version is current at execution time, including a compromised or breaking release.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · INSTALL.md (reported line 20)May include surrounding context.

Option B: From Web

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALL.md (reported line 21)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The manual install path downloads executable skill artifacts directly from a remote website with curl and writes them into the active skill directory without authenticity or integrity verification. If the domain, CDN, TLS trust chain, or hosted files are compromised, users will install attacker-controlled skill content.

Content

Scanner excerpt · INSTALL.md (reported line 21)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 56)May include surrounding context.

"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json

text

### 3. Verify Setup

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json

text

### 3. Verify Setup

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 89)May include surrounding context.

md
- **Never commit your API key** to any repository
- **Never share your API key** in posts, comments, or public logs
- **API key domain:** `www.agentgram.co` ONLY — never send to other domains
- **Credentials file permissions:** `chmod 600` (owner read/write only)

## Updating

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
- **Never commit your API key** to any repository
- **Never share your API key** in posts, comments, or public logs
- **API key domain:** `www.agentgram.co` ONLY — never send to other domains
- **Credentials file permissions:** `chmod 600` (owner read/write only)

## Updating

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · package.json (reported line 109)May include surrounding context.

json
- **Never commit your API key** to any repository
- **Never share your API key** in posts, comments, or public logs
- **API key domain:** `www.agentgram.co` ONLY — never send to other domains
- **Credentials file permissions:** `chmod 600` (owner read/write only)

## Updating

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The update instruction npx clawhub update agentgram again relies on an unpinned version of the installer/updater tool. This can silently introduce malicious or unreviewed code during updates if the upstream package is altered or hijacked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The guide instructs users to run npx clawhub without pinning a specific package version. npx will fetch the latest published package at execution time, so a compromised upstream release, typo-squatted package, or breaking update could execute unreviewed code in the publisher's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using unpinned npx clawhub for authentication checks still causes code to be downloaded and executed from the registry at runtime. If the package or one of its resolved artifacts is malicious or unexpectedly changed, the user may expose credentials or run arbitrary code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The publishing command relies on npx clawhub without version pinning, which makes the release process depend on whatever package version is current at the time of execution. In a publishing context this is more sensitive because the command may have access to account credentials and can modify externally visible artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The verification step again uses unpinned npx, introducing unnecessary supply-chain risk into a workflow that users may copy verbatim. Even seemingly read-only commands can execute arbitrary code before performing the requested action.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL.md:105