Back to skill

Security audit

Pre-Publish Fact Checker

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly coherent Prismfy claim-checking skill, but it needs Review because it can send draft claims and an API key to a configurable external endpoint and recommends persistent setup without enough warning.

Install only if you are comfortable sending claim text to Prismfy or another explicitly trusted endpoint. Avoid using it on confidential drafts unless the service and token scope are acceptable, store the API key in a safer secret store instead of ~/.bashrc, do not set PRISMFY_BASE_URL unless you fully trust the target, and enable the bootstrap hook only if you want persistent reminders in future agent sessions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
claim-verify.sh:4
Finding

Unvalidated API Base URL Can Exfiltrate Credentials and Draft Claims

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
claim-verify-batch.sh:68
Finding

Predictable Temporary Error File Enables Local Symlink Overwrite

Content
View full analysis
/tmp/claim_verify_err.$$)"; then err="$(cat /tmp/claim_verify_err.$$ 2>/dev/null || true)" status="not_found" confidence="0.20" evidence='[]' ``` ```bash }]' "$tmp_items" > "${tmp_items}.new" mv "${tmp_items}.new" "$tmp_items" done ``` ```bash rm -f "$tmp_items" /tmp/claim_verify_err.$$ ``` ### Technical Analysis The batch script redirects standard error to a path formed from the process ID: ```text /tmp/claim_verify_err. ``` Process IDs are predictable and the shared `/tmp` directory is generally writable by all local users. The script does not create the file securely, verify its ownership, reject symbolic links, or use exclusive creation. Before invoking the child process, the shell opens the redirection target with truncation semantics. If a local attacker pre-creates the predicted path as a symbolic link, the shell can follow that link and truncate or overwrite the linked target with command error output. The script also constructs `${tmp_items}.new` through ordinary redirection. Although the original `tmp_items` name comes from `mktemp` and is substantially harder to predict, deriving a second filename and creating it without exclusive safeguards unnecessarily broadens the temporary-file attack surface. Cleanup occurs only at the normal end of the script. Because `set -e` is enabled and no `EXIT` trap is registered, errors or interruption can leave temporary files behind. ### Attack Path 1. A local attacker identifies or predicts the PID of a forthcoming `claim-verify-batch.sh` process. 2. The attacker creates a symbolic link in the shared temporary director ...[truncated 1416 chars]
Remediation
View remediation
"$err_file")"; then err="$(cat -- "$err_file" 2>/dev/null || true)" fi ``` 4. Avoid deriving temporary filenames in a shared directory. Place `${tmp_items}.new` in the private temporary directory, or create each replacement file with `mktemp`. 5. Apply restrictive permissions by setting: ```bash umask 077 ``` before creating temporary files or generated reports that may contain confidential claims. 6. Use `--` before path arguments where supported to prevent filenames beginning with a dash from being interpreted as options. 7. Consider writing the final report to a temporary file in the destination directory and then atomically renaming it after successful generation. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A second behavior mismatch suggests the skill may inject bootstrap guidance or hook-triggered content instead of actually executing verification. Hidden trigger behavior is risky in agent ecosystems because it can alter execution context, surprise users, and create unauthorized workflow activation beyond the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A second behavior mismatch suggests the skill may inject bootstrap guidance or hook-triggered content instead of actually executing verification. Hidden trigger behavior is risky in agent ecosystems because it can alter execution context, surprise users, and create unauthorized workflow activation beyond the stated purpose.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

you can trust.

Best for:

  • blog posts,
  • product pages,
  • social posts,
  • outbound messages with external facts.

Need a key?

Setup

  1. Install the skill:
bash
openclaw skills install claim-verifier
  1. Add your Prismfy API key:
bash
export PRISMFY_API_KEY="ss_live_your_key_here"

To keep it after restart:

bash
echo 'export PRISMFY_API_KEY="ss_live_your_key_here"' >> ~/.bashrc
source ~/.bashrc
  1. Verify API access:
bash
cd ~/.openclaw/workspace/skills/claim-verifier
bash claim-verify.sh --quota
  1. Quick smoke test:
bash
cd ~/.openclaw/workspace/skills/claim-verifier
bash claim-verify.sh --claim "OpenAI released GPT-5 in March 2026"

Enable hook (recommended):

bash
# Run from this skill directory:
# ~/.openclaw/workspace/skills/claim-verifier

# Copy OpenClaw hook into hooks registry
cp -r hooks/claim-verifier ~/.openclaw/hooks/

# Confirm files are present
find ~/.openclaw/hook

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises shell-based setup and execution flows but does not declare a tool/permission scope, which weakens reviewability and allows broader-than-expected command execution in agent environments. In a skill that invokes external services and hooks, undeclared shell capability increases the chance of users or orchestrators granting unsafe execution implicitly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup instructions tell users to place a live API key directly into shell commands and append it to ~/.bashrc, which can expose credentials via shell history, screenshots, logs, and overly broad persistence. While common in informal docs, this is still an avoidable secret-handling weakness that can lead to API key theft and account abuse.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
Avoid using this skill when:
- NOT inputs_present(draft_text)
- request_type=creative_only_without_external_facts
- intent is limited to stylistic rewrite without verification

## Inputs
- `draft_text` (required): text to verify

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Each extracted claim is forwarded to claim-verify.sh, which the skill description indicates performs external factual lookup. In a claim-verification skill, draft text may contain unpublished, confidential, or regulated information, so sending extracted claims to an external service without a clear privacy warning or consent gate can leak sensitive content to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script makes network calls to Prismfy for both quota lookup and claim verification, transmitting the user's claim text and authenticating with an API key. Although the usage text says it runs Prismfy query calls, there is no explicit warning, confirmation, or privacy disclosure that user-provided claims and account-related data are sent to a remote service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · claim-verify.sh (reported line 57)May include surrounding context.

sh
fi

  local resp
  resp=$(curl -sS -X POST "$SEARCH_ENDPOINT" \
    -H "Authorization: Bearer $PRISMFY_API_KEY" \
    -H "Content-Type: application/json" \
    -d "$body")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The provided skill manifest context says this skill should verify external factual claims and produce a structured verification report with evidence links. In contrast, this file's own description and documentation say it merely injects a reminder during agent bootstrap and adds a virtual reminder file, which is materially narrower than actual claim verification behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The hook says it fires on agent:bootstrap, while the prose describes a much narrower intended condition: drafts containing external factual statements and being prepared for publication or sending. This mismatch makes the actual activation condition ambiguous and could cause unintended invocation outside the stated scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code creates and overwrites an output JSON report via the default or user-provided --out path, but there is no explicit warning comment or disclosure that running the script will write a report file. For code files, file writes can warrant a finding when there is no confirmation prompt, user-facing disclosure, or documented warning in the skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.