Back to skill

Security audit

Pixcake Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is for real PixCake workflows, but its setup can globally install software and persistently register auto-discovered executables without enough verification or consent.

Review before installing. Use the check-only mode first, prefer explicitly supplying the known PixCake and pixcake-mcp paths, and avoid running setup with elevated privileges. Be aware that setup may install mcporter globally and modify your OpenClaw mcporter config; back up that config first if you have other MCP settings.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:332
Finding

Unpinned Global npm Installation Exposes the Setup Process to Supply-Chain Compromise

Content
View full analysis
/dev/null; then : else log "[WARN] First install attempt failed, cleaning npm cache and retrying..." npm cache clean --force 2>/dev/null || true npm install -g mcporter fi ``` `scripts/setup.ps1.txt:204-210`: ```powershell Write-Log '[INSTALL] Installing mcporter via npm...' try { & npm install -g mcporter 2>&1 | Out-Null } catch {} if (-not (Test-CommandExists 'mcporter')) { Write-Log '[WARN] First install attempt failed, cleaning npm cache and retrying...' try { & npm cache clean --force 2>&1 | Out-Null } catch {} & npm install -g mcporter } ``` ### Technical Analysis Both setup implementations install the mutable latest version of the `mcporter` npm package globally. The project does not pin an exact version, provide a lockfile, verify a package integrity hash, or authenticate an expected publisher or artifact. npm installation may execute package lifecycle scripts such as `preinstall`, `install`, and `postinstall`. Consequently, a compromised package release, maintainer account, registry response, or transitive dependency could execute code during setup. The global installation scope also modifies shared user or system tooling rather than isolating the dependency to this Skill. The fallback clears the npm cache and repeats the unpinned installation. This does not provide integrity protection and further reduces reproducibility. ### Attack Path 1. An attacker compromises the `mcporter` package, one of its dependencies, or the relevant npm publishing account. 2. The attacker publishes a malicious version or injects malicious lifecycle code into the dependency chain. 3. A user or Agent runs `setup ...[truncated 785 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/setup.ps1.txt:94
Finding

Filename-Only MCP Executable Discovery Permits Local Tool Spoofing

Content
View full analysis
/dev/null | sort | first_line } ``` ### Technical Analysis The scripts trust executable candidates based primarily on a matching filename or process path. They do not verify the PixCake vendor's code signature, an expected cry ...[truncated 2424 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.ps1.txt:131
Finding

Windows Setup Destructively Removes Unrelated Top-Level MCP Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a PixCake client-operation skill, but it also directs process discovery, executable/path probing, setup-script execution, package installation, and configuration file modification on the host. That broadens scope from application usage into host environment mutation and reconnaissance, which is dangerous because users or calling agents may invoke it without understanding the system-level side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README is entirely in Chinese and does not indicate that users may interact in another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs execution of setup scripts that may install mcporter, rename files, and write configuration, but does not require an explicit warning or consent flow before making those system changes. This is risky because setup scripts are high-trust operations and can alter the machine state in ways the user did not specifically approve or anticipate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The skill directs creation of a persistent mcporter configuration file in the user's home directory, causing state to survive the current session and influence later executions. This becomes more dangerous in context because the file controls command routing for pixcake tool invocations, so a stale or tampered config could affect subsequent agent actions without renewed user awareness.

Content

Scanner excerpt · manifest.json (reported line 67)May include surrounding context.

json
"smart_crop"
    ]
  },
  "path_resolution": "Resolve PixCake and pixcake-mcp paths with the agent's own shell or command tools before PixCake calls, then prefer ./scripts/setup.sh to write ~/.openclaw/workspace/config/mcporter.json. On Windows, do not assume mcporter can auto-discover PixCake on D:/E:; the command path must be explicit.",
  "mismatch_policy": "If mcporter --config ~/.openclaw/workspace/config/mcporter.json list pixcake or mcporter --config ~/.openclaw/workspace/config/mcporter.json call pixcake.<tool_name> signals incompatibility, stop probing, recommend upgrading PixCake to 9.0.0 or newer, and suggest support if the issue remains."
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest explicitly instructs the agent to write a configuration file under ~/.openclaw/workspace/config/mcporter.json, which modifies persistent user state in the home directory without any indication of user consent, prompting, backup, or least-privilege handling. In an agent skill context, silent writes to user-controlled config paths are risky because they can alter future tool behavior, create persistence, or overwrite trusted settings beyond the immediate task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill file is written entirely in Chinese and presents the capability and behavior requirements only in that language, without offering any language/locale choice or stating that the skill is intentionally limited to a Chinese-speaking region or audience. This can violate the language/locale policy because it effectively forces a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions specify the required first response entirely in Chinese and do not indicate that the user can choose another language. This creates a natural-language policy concern because it effectively forces a specific language without user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill instruction set is written as Chinese-only operational guidance, with no indication that the user can choose another language or that the skill is restricted to a Chinese-language context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document directs the user to run setup scripts that modify local configuration and may perform a global npm install -g mcporter, which changes the system state and introduces code from the package registry. While this appears operational rather than overtly malicious, failing to clearly warn about these side effects can lead users to execute privileged or persistent changes without informed consent, increasing supply-chain and misconfiguration risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s operational instructions are entirely in Chinese, including workflow rules and guardrails, with no indication that users may interact in other languages or that the skill is limited to a Chinese-language context. This can violate language/locale policy when a skill implicitly enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file prescribes fixed Chinese response phrases throughout, such as required success and export-status wording, with no indication that users may choose another language. This is a natural-language policy issue because it enforces a specific language/locale without opt-in or a documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill instruction content is written in Chinese and provides no indication that users may interact in another language or opt into this locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs npm install -g mcporter, which changes the user's global Node.js environment and can affect system state beyond this skill. Although there is a log message, there is no confirmation prompt or prior user-facing warning in the file before this installation step occurs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script goes beyond simple PixCake client operations by persistently modifying the user's mcporter configuration and performing environment setup logic. Persistent config changes alter future tool behavior and increase trust in an externally discovered executable path, which broadens the blast radius if the discovered path is wrong or attacker-controlled.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script installs mcporter globally via npm, which introduces remote code execution risk through package installation, lifecycle scripts, dependency compromise, or registry tampering. This is not necessary for core PixCake project/export actions and gives the skill the ability to change the host software state in a much broader way than its stated purpose suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown states that the runtime is auto-installed and that ~/.openclaw/workspace/config/mcporter.json is "automatically written," which is a user-affecting file modification. Because this README is the user-facing description, it should explicitly warn that running setup will change local configuration files so users understand the impact before proceeding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The synopsis, description, and parameter help are presented only in Chinese, creating a language constraint in the natural-language interface of the skill. There is no indication that the skill is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script enumerates running processes and recursively searches common application paths and drives to discover PixCake binaries. While this is plausibly for setup convenience, it performs broader host inspection than the skill description implies and may expose installed software layout, running process information, or pick up an unintended executable with a matching name.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.