Back to skill

Security audit

Automate Nbm

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its agent-automation purpose, but it persists SSH keys and task contents in predictable local files and uses broad automation triggers, so it needs review before installation.

Review this skill before installing in any persistent or shared runner. Do not provide AUTOMATE_SSH_KEY unless you are comfortable with it being written to ~/.ssh/automate_key and left there; prefer a short-lived deploy key or ssh-agent-style handling. Avoid sending sensitive task descriptions through webhook notifications, and restrict issue-label or keyword-triggered automation to trusted repository users.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run-task.sh:135
Finding

Persistent Plaintext Storage of an SSH Private Key

Content
View full analysis
~/.ssh/automate_key chmod 600 ~/.ssh/automate_key log "🔑 SSH key loaded" fi ``` ### Technical Analysis When `AUTOMATE_SSH_KEY` is present, the script writes its complete value to the stable path `~/.ssh/automate_key`. Although the file is assigned mode `600`, the script does not: - Use the key for any SSH operation. - Store it in an ephemeral task-specific location. - Register an exit handler to remove it. - Check whether the destination is an existing regular file or symbolic link. - Restrict the permissions of the containing `.ssh` directory. - Prevent subsequent jobs running under the same account from reading it. File mode `600` protects the key from other operating-system users, but not from later processes, jobs, or compromised tools operating as the same user. The stable filename also causes every invocation to overwrite the previous key. The behavior exceeds the current implementation's operational needs. Task execution only generates Markdown and JSON result files; no active code consumes the SSH key. ### Attack Path 1. A workflow or operator invokes `scripts/run-task.sh` with `AUTOMATE_SSH_KEY` containing a valid private key. 2. The script writes the private key to `~/.ssh/automate_key`. 3. Task processing finishes, but the script performs no credential cleanup. 4. A later process, compromised dependency, malicious task, or separate job running under the same account reads the retained file. 5. The attacker uses the key aga ...[truncated 956 chars]
Remediation
View remediation
"$SSH_TEMP_DIR/automate_key" chmod 600 "$SSH_TEMP_DIR/automate_key" fi ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run-task.sh:32
Finding

Predictable Temporary Result Files Permit Symlink-Based File Overwrite

Content
View full analysis
"$RESULT_FILE" < "$RESULT_JSON" </dev/null || echo "\"$TASK_TITLE\""), "result_file": "${RESULT_FILE}" } EOF ``` The dispatch script similarly uses a predictable shared path: ```bash RESULT_FILE="${RESULT_FILE:-/tmp/agent-result.md}" ``` ### Technical Analysis The scripts create output in the globally shared `/tmp` directory using predictable filenames. Shell output redirection follows symbolic links and truncates the destination before writing. The implementation does not use exclusive file creation, validate ownership, reject symbolic links, or create a task-specific private directory. Consequently, another local user or process can create one of the expected paths as a symbolic link before the task starts. If the task runner has permission to write the link target, the redirection will overwrite that target. The configurable `RESULT_FILE` further expands the risk where an untrusted workflow input can influence the environment v ...[truncated 1888 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared repository inspection of workflows, issue templates, and package scripts can expose sensitive project metadata and produce unexpected automation against a user's codebase. While not inherently malicious, hidden analysis of CI/CD and project files expands the attack surface and violates the principle of least astonishment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Undeclared repository inspection of workflows, issue templates, and package scripts can expose sensitive project metadata and produce unexpected automation against a user's codebase. While not inherently malicious, hidden analysis of CI/CD and project files expands the attack surface and violates the principle of least astonishment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared repository inspection of workflows, issue templates, and package scripts can expose sensitive project metadata and produce unexpected automation against a user's codebase. While not inherently malicious, hidden analysis of CI/CD and project files expands the attack surface and violates the principle of least astonishment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Undeclared repository inspection of workflows, issue templates, and package scripts can expose sensitive project metadata and produce unexpected automation against a user's codebase. While not inherently malicious, hidden analysis of CI/CD and project files expands the attack surface and violates the principle of least astonishment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared repository inspection of workflows, issue templates, and package scripts can expose sensitive project metadata and produce unexpected automation against a user's codebase. While not inherently malicious, hidden analysis of CI/CD and project files expands the attack surface and violates the principle of least astonishment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented auto-dispatch behavior routes tasks based on broad natural-language keywords and falls back to a default agent when no exact match is found. In a multi-agent system, this can cause unintended agent selection, leading to mis-execution of tasks, inappropriate tool access, or triggering higher-impact workflows such as orchestration from ambiguous user input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents the project summary entirely in Chinese, including headings, status, plans, and pricing, but does not indicate that the skill is Chinese-only or offer users an alternative language. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises shell-based usage examples and operational behavior, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent framework, missing scope boundaries can let the runtime grant broader-than-expected execution capability, increasing the risk of unintended command execution or abuse if downstream prompts or wrappers invoke shell actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Nearly all user-facing documentation and examples are presented in Chinese, and the skill does not state that other languages are supported or that the user may choose their preferred language. Per the policy, forcing a specific language without opt-in is a natural-language policy concern unless clearly documented as region-specific or optional.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · agents/engineering/frontend-developer.md (reported line 15)May include surrounding context.

md
a modern web application specialist. You build fast, accessible, beautiful interfaces. You think in components, design systems, and user interactions. Performance isn't an afterthought — it's built into every decision from the first line of code.

**Personality:** Detail-oriented, pixel-precise, user-centric. You care deeply about the 200ms that separates "snappy" from "sluggish." You advocate fiercely for accessibility because the web is for everyone. You write TypeScript because types catch bugs before users do.

## Core Capabilities

### Modern Web Applications
- **Frameworks:** React (Next.js, Remix), Vue (Nuxt), Angular, Svelte (SvelteKit)
- **Language:** TypeScript-first, always. JavaScript when forced.
- **Styling:** Tailwind CSS, CSS Modules, Styled Components, vanilla CSS with custom properties
- **State:** Zustand, Jotai, Redux Toolkit, TanStack Query, SWR
- **Build tools:** Vite, Turbopack, webpack (legacy)

### Component Architecture
- Design system creation with tokens,

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The keyword set for the marketing agent includes very broad, common terms such as 'growth' and especially 'marketing', which can match many unrelated task descriptions. In an automated dispatch system, this can cause unintended agent selection, misrouting work, and execution of the wrong automation path without strong user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The support agent uses highly generic trigger terms like 'customer' and 'help-desk', which overlap with ordinary issue text and common operational discussion. In a GitHub-native automation environment with auto-acknowledgment and labeling enabled, this increases the chance of accidental invocation and unintended workflow actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The statement that the orchestrator 'runs autonomously from a single command' promotes unattended execution without warning users that it may trigger agent actions, scripts, workflows, or other system-impacting operations. In this context, the skill is specifically an orchestration engine tied to CLI and GitHub workflow invocation, so lack of safety guardrails increases the chance of accidental execution of broad project tasks with insufficient human review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill allows orchestration to be triggered automatically by creating a GitHub issue with the orchestrate label, but it does not describe any authorization, repository-scope, branch, actor, or content validation controls. In a multi-agent system that can autonomously decompose work and invoke downstream agents, a broad trigger can let untrusted or low-trust users initiate costly or unsafe automation, including generation of code, workflow activity, or task fan-out.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest describes skills as '61 specialized AI agents across 8 departments' and 'Multi-agent orchestration engine' without stating when they should be invoked, what trigger phrases apply, or what contexts are excluded. In a manifest file, such broad descriptions can contribute to unintended invocation because the trigger scope is not clearly bounded.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/notify.sh (reported line 112)May include surrounding context.

sh
json_body=$(echo "$body" | python3 -c 'import json,sys; print(json.dumps(sys.stdin.read()))' 2>/dev/null || echo "\"$body\"")

  local response
  response=$(curl -sS -w "\n%{http_code}" -X POST \
    -H "Authorization: token ${token}" \
    -H "Accept: application/vnd.github+json" \
    -H "X-GitHub-Api-Version: 2022-11-28" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/notify.sh (reported line 116)May include surrounding context.

sh
-H "Authorization: token ${token}" \
    -H "Accept: application/vnd.github+json" \
    -H "X-GitHub-Api-Version: 2022-11-28" \
    "https://api.github.com/repos/${repo}/issues/${issue}/comments" \
    -d "{\"body\": ${json_body}}" 2>&1)

  local http_code

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The webhook sender transmits arbitrary notification content to a fully attacker-controlled URL from WEBHOOK_URL with no allowlist, scheme restriction, or trust validation. In an agent environment, this can be abused for data exfiltration or SSRF-like behavior if untrusted workflows can influence the message or webhook destination.

Content

Scanner excerpt · scripts/notify.sh (reported line 157)May include surrounding context.

sh
)

  local response
  response=$(curl -sS -w "\n%{http_code}" -X POST "$url" \
    -H "Content-Type: application/json" \
    -d "$payload" 2>&1)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script accepts SSH private key material via an environment variable and writes it to disk under ~/.ssh/automate_key. In an AI task-runner/orchestration context, this expands the skill's capability into sensitive credential handling, which increases the blast radius if the script, host, logs, or downstream agents are compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The private key is written to a file with only a generic "SSH key loaded" message, so users may not realize sensitive credentials are being persisted on disk. This can lead to accidental exposure through backups, later filesystem access, container/image capture, or reuse by unintended processes.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/run-task.sh (reported line 140)May include surrounding context.

sh
if [ -n "${AUTOMATE_SSH_KEY:-}" ]; then
  mkdir -p ~/.ssh
  echo "$AUTOMATE_SSH_KEY" > ~/.ssh/automate_key
  chmod 600 ~/.ssh/automate_key
  log "🔑 SSH key loaded"
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script persists TASK_TITLE and TASK_BODY directly into a result file, potentially storing sensitive prompts, internal data, credentials, or issue-linked content without any warning or minimization. In agent orchestration workflows, tasks often contain confidential operational context, so silent persistence increases data retention and leakage risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/run-task.sh (reported line 193)May include surrounding context.

sh
# Integration point: Call OpenClaw API or local CLI here.
  # Example (pseudo):
  #   SYSTEM_PROMPT=$(cat "$PERSONA_FILE")
  #   RESPONSE=$(curl -s -X POST "$OPENCLAW_API/v1/chat" \
  #     -H "Authorization: Bearer $OPENCLAW_TOKEN" \
  #     -d "{\"system\": \"$SYSTEM_PROMPT\", \"message\": \"$TASK_BODY\"}")
  #   echo "$RESPONSE" >> "$RESULT_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically changes file permissions with chmod +x when a listed script is not executable. Although there is a console message, it does not warn beforehand that this test performs a state-changing operation rather than a read-only validation, which can surprise users running a test script.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The markdown describes recommended orchestrator use and activation of an entire department, which implies broad automated task delegation across multiple agents. However, there is no accompanying warning that outputs may be generated by multiple specialized agents and should be reviewed before use, despite possible effects on user data, system integrity, or downstream actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.