T09 · Insecure Skill Coding Practices
- Location
claim-verify.sh:4- Finding
Unvalidated API Base URL Can Exfiltrate Credentials and Draft Claims
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a mostly coherent Prismfy claim-checking skill, but it needs Review because it can send draft claims and an API key to a configurable external endpoint and recommends persistent setup without enough warning.
Install only if you are comfortable sending claim text to Prismfy or another explicitly trusted endpoint. Avoid using it on confidential drafts unless the service and token scope are acceptable, store the API key in a safer secret store instead of ~/.bashrc, do not set PRISMFY_BASE_URL unless you fully trust the target, and enable the bootstrap hook only if you want persistent reminders in future agent sessions.
claim-verify.sh:4Unvalidated API Base URL Can Exfiltrate Credentials and Draft Claims
claim-verify-batch.sh:68Predictable Temporary Error File Enables Local Symlink Overwrite
A second behavior mismatch suggests the skill may inject bootstrap guidance or hook-triggered content instead of actually executing verification. Hidden trigger behavior is risky in agent ecosystems because it can alter execution context, surprise users, and create unauthorized workflow activation beyond the stated purpose.
A second behavior mismatch suggests the skill may inject bootstrap guidance or hook-triggered content instead of actually executing verification. Hidden trigger behavior is risky in agent ecosystems because it can alter execution context, surprise users, and create unauthorized workflow activation beyond the stated purpose.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
you can trust.
Best for:
Need a key?
openclaw skills install claim-verifier
export PRISMFY_API_KEY="ss_live_your_key_here"
To keep it after restart:
echo 'export PRISMFY_API_KEY="ss_live_your_key_here"' >> ~/.bashrc
source ~/.bashrc
cd ~/.openclaw/workspace/skills/claim-verifier
bash claim-verify.sh --quota
cd ~/.openclaw/workspace/skills/claim-verifier
bash claim-verify.sh --claim "OpenAI released GPT-5 in March 2026"
Enable hook (recommended):
# Run from this skill directory:
# ~/.openclaw/workspace/skills/claim-verifier
# Copy OpenClaw hook into hooks registry
cp -r hooks/claim-verifier ~/.openclaw/hooks/
# Confirm files are present
find ~/.openclaw/hook
The skill advertises shell-based setup and execution flows but does not declare a tool/permission scope, which weakens reviewability and allows broader-than-expected command execution in agent environments. In a skill that invokes external services and hooks, undeclared shell capability increases the chance of users or orchestrators granting unsafe execution implicitly.
The setup instructions tell users to place a live API key directly into shell commands and append it to ~/.bashrc, which can expose credentials via shell history, screenshots, logs, and overly broad persistence. While common in informal docs, this is still an avoidable secret-handling weakness that can lead to API key theft and account abuse.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Avoid using this skill when:
- NOT inputs_present(draft_text)
- request_type=creative_only_without_external_facts
- intent is limited to stylistic rewrite without verification
## Inputs
- `draft_text` (required): text to verify
Each extracted claim is forwarded to claim-verify.sh, which the skill description indicates performs external factual lookup. In a claim-verification skill, draft text may contain unpublished, confidential, or regulated information, so sending extracted claims to an external service without a clear privacy warning or consent gate can leak sensitive content to third parties.
This shell script makes network calls to Prismfy for both quota lookup and claim verification, transmitting the user's claim text and authenticating with an API key. Although the usage text says it runs Prismfy query calls, there is no explicit warning, confirmation, or privacy disclosure that user-provided claims and account-related data are sent to a remote service.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
fi
local resp
resp=$(curl -sS -X POST "$SEARCH_ENDPOINT" \
-H "Authorization: Bearer $PRISMFY_API_KEY" \
-H "Content-Type: application/json" \
-d "$body")
The provided skill manifest context says this skill should verify external factual claims and produce a structured verification report with evidence links. In contrast, this file's own description and documentation say it merely injects a reminder during agent bootstrap and adds a virtual reminder file, which is materially narrower than actual claim verification behavior.
The hook says it fires on agent:bootstrap, while the prose describes a much narrower intended condition: drafts containing external factual statements and being prepared for publication or sending. This mismatch makes the actual activation condition ambiguous and could cause unintended invocation outside the stated scope.
This code creates and overwrites an output JSON report via the default or user-provided --out path, but there is no explicit warning comment or disclosure that running the script will write a report file. For code files, file writes can warrant a finding when there is no confirmation prompt, user-facing disclosure, or documented warning in the skill description.
No suspicious patterns detected.