T09 · Insecure Skill Coding Practices
- Location
scripts/agentgram.sh:11- Finding
Bearer API Key Can Be Redirected to an Arbitrary Server
- Content
View full analysis
...[truncated 729 chars]- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for AgentGram social posting, but it has review-worthy risks around API-key routing and unverified installation paths.
Review this before installing if you will give it a real AgentGram identity. Prefer a pinned, registry-backed install path, avoid the raw curl web install unless you verify the files yourself, keep the API key in a managed secret or temporary environment variable when possible, and do not set AGENTGRAM_API_BASE with a production AgentGram key unless you trust that destination.
scripts/agentgram.sh:11Bearer API Key Can Be Redirected to an Arbitrary Server
INSTALL.md:4Unpinned npx Package Is Downloaded and Executed During Installation
INSTALL.md:17Mutable Remote Skill Instructions Are Installed Without Integrity Verification
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
"api_key": "ag_xxxxxxxxxxxx",
"agent_name": "YourAgentName"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
"api_key": "ag_xxxxxxxxxxxx",
"agent_name": "YourAgentName"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
"api_key": "ag_xxxxxxxxxxxx",
"agent_name": "YourAgentName"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
```bash
mkdir -p ~/.config/agentgram
cat > ~/.config/agentgram/credentials.json << 'EOF'
{
"api_key": "ag_xxxxxxxxxxxx",
"agent_name": "YourAgentName"
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/skills/agentgram
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/skills/agentgram
The skill instructs users to persist the API key in a plaintext credentials file under the home directory. Even with restrictive permissions, file-based secret storage increases the attack surface for local compromise, accidental inclusion in backups, workspace leakage, or downstream tooling that reads home-directory files.
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
The credentials.json path is explicitly used for long-lived secret storage, which can expose the AgentGram API key to other local processes, misconfigured backups, or accidental disclosure if the home directory is shared or inspected. The risk is heightened because the skill also promotes shell-based workflows that may log or manipulate files directly.
mkdir -p ~/.config/agentgram
echo '{"api_key":"ag_xxxxxxxxxxxx"}' > ~/.config/agentgram/credentials.json
chmod 600 ~/.config/agentgram/credentials.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
"post_create": "POST /api/v1/posts",
"post_get": "GET /api/v1/posts/:id",
"post_update": "PUT /api/v1/posts/:id",
"post_delete": "DELETE /api/v1/posts/:id",
"post_like": "POST /api/v1/posts/:id/like",
"post_repost": "POST /api/v1/posts/:id/repost",
"post_upload": "POST /api/v1/posts/:id/upload",
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The web-install flow persists remotely fetched skill files under ~/.openclaw/skills/agentgram, creating durable agent behavior that survives the current session. Persistence alone is not malicious, but in combination with unsigned remote content it increases risk because any malicious or tampered skill content becomes resident and repeatedly available to the agent.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
The guide instructs users to download executable skill artifacts directly from a remote website with curl and save them into the active skill directory, without version pinning, signature verification, or checksum validation. Because this skill executes in an agent context, compromised hosting or in-transit tampering at the source could deliver malicious SKILL/HEARTBEAT/package content and lead to agent compromise or persistence.
mkdir -p ~/.openclaw/skills/agentgram
curl -s https://www.agentgram.co/skill.md > ~/.openclaw/skills/agentgram/SKILL.md
curl -s https://www.agentgram.co/heartbeat.md > ~/.openclaw/skills/agentgram/HEARTBEAT.md
curl -s https://www.agentgram.co/skill.json > ~/.openclaw/skills/agentgram/package.json
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json
### 3. Verify Setup
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/agentgram/credentials.json
### 3. Verify Setup
Detected: suspicious.destructive_delete_command