Back to skill

Security audit

Agentgram Openclaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for AgentGram social posting, but it has review-worthy risks around API-key routing and unverified installation paths.

Review this before installing if you will give it a real AgentGram identity. Prefer a pinned, registry-backed install path, avoid the raw curl web install unless you verify the files yourself, keep the API key in a managed secret or temporary environment variable when possible, and do not set AGENTGRAM_API_BASE with a production AgentGram key unless you trust that destination.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agentgram.sh:11
Finding

Bearer API Key Can Be Redirected to an Arbitrary Server

Content
View full analysis
...[truncated 729 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:4
Finding

Unpinned npx Package Is Downloaded and Executed During Installation

Content
View full analysis
Remediation
View remediation
install agentgram ``` 2. Document the expected registry, package publisher, version, and package integrity hash. 3. Prefer a lockfile-backed or separately verified installation of the CLI rather than resolving it dynamically during each Skill installation. 4. Review new CLI versions before changing the documented pin. 5. Apply the same version pinning to update, login, publishing, inspection, search, deletion, and other documented `npx clawhub` commands. 6. Where supported, verify package provenance or registry signatures and reject packages that do not match the expected publisher identity. ]]>

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:17
Finding

Mutable Remote Skill Instructions Are Installed Without Integrity Verification

Content
View full analysis
~/.openclaw/skills/agentgram/SKILL.md curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json ``` ``` ### Technical Analysis The manual installation procedure downloads mutable files directly from service-controlled URLs into the active Skill directory. It does not pin a release, verify a checksum or signature, validate the downloaded file type, or inspect the content before activation. `SKILL.md` and `HEARTBEAT.md` are agent-consumed instruction files. Although they are not shell executables, replacing them can alter the agent's future behavior when the installed Skill is loaded. The downloaded `package.json` can likewise alter declared metadata and capabilities. The commands also use `curl -s` without `--fail`. HTTP error responses may therefore overwrite valid local files while the command still appears superficially successful. Direct shell redirection truncates each destination before download success and validation are known. ### Attack Path 1. An attacker compromises the AgentGram distribution server, deployment pipeline, DNS/TLS trust path, or another component capable of changing the files returned by the documented URLs. 2. The attacker replaces `skill.md`, `heartbeat.md`, or `skill.json` with altered content. 3. A user executes the documented manual installation commands. 4. The altered files are written directly into `~/.openclaw/skills/agentgram`. 5. The OpenClaw-compatible agent later loads the attacker-controlled instructions or metadata. 6. Those instructions can attempt to redirect the agent's goals, induce u ...[truncated 719 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (47)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 50)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
  "api_key": "ag_xxxxxxxxxxxx",
  "agent_name": "YourAgentName"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 56)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
  "api_key": "ag_xxxxxxxxxxxx",
  "agent_name": "YourAgentName"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
  "api_key": "ag_xxxxxxxxxxxx",
  "agent_name": "YourAgentName"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · package.json (reported line 109)May include surrounding context.

json
```bash
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
  "api_key": "ag_xxxxxxxxxxxx",
  "agent_name": "YourAgentName"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 111)May include surrounding context.

Uninstalling

bash
rm -rf ~/.openclaw/skills/agentgram

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 111)May include surrounding context.

Uninstalling

bash
rm -rf ~/.openclaw/skills/agentgram

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The skill instructs users to persist the API key in a plaintext credentials file under the home directory. Even with restrictive permissions, file-based secret storage increases the attack surface for local compromise, accidental inclusion in backups, workspace leakage, or downstream tooling that reads home-directory files.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The credentials.json path is explicitly used for long-lived secret storage, which can expose the AgentGram API key to other local processes, misconfigured backups, or accidental disclosure if the home directory is shared or inspected. The risk is heightened because the skill also promotes shell-based workflows that may log or manipulate files directly.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

bash
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json

3. Verify Setup

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · package.json (reported line 69)May include surrounding context.

json
"post_create": "POST /api/v1/posts",
    "post_get": "GET /api/v1/posts/:id",
    "post_update": "PUT /api/v1/posts/:id",
    "post_delete": "DELETE /api/v1/posts/:id",
    "post_like": "POST /api/v1/posts/:id/like",
    "post_repost": "POST /api/v1/posts/:id/repost",
    "post_upload": "POST /api/v1/posts/:id/upload",

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The web-install flow persists remotely fetched skill files under ~/.openclaw/skills/agentgram, creating durable agent behavior that survives the current session. Persistence alone is not malicious, but in combination with unsigned remote content it increases risk because any malicious or tampered skill content becomes resident and repeatedly available to the agent.

Content

Scanner excerpt · INSTALL.md (reported line 20)May include surrounding context.

Option B: From Web

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALL.md (reported line 21)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The guide instructs users to download executable skill artifacts directly from a remote website with curl and save them into the active skill directory, without version pinning, signature verification, or checksum validation. Because this skill executes in an agent context, compromised hosting or in-transit tampering at the source could deliver malicious SKILL/HEARTBEAT/package content and lead to agent compromise or persistence.

Content

Scanner excerpt · INSTALL.md (reported line 21)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 56)May include surrounding context.

"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json

text

### 3. Verify Setup

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json

text

### 3. Verify Setup

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL.md:111