Back to skill

Security audit

Lead Contact Finder

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but needs review because it handles a Prismfy API key in ways that can expose the key if users follow the setup or override endpoints unsafely.

Review this before installing if the Prismfy key has meaningful quota, billing, or access. Use a secret manager or per-command environment injection instead of putting the key in ~/.bashrc, avoid endpoint override variables unless you control the endpoint, and assume contact lookup queries are sent to Prismfy. Enable the optional hook only if you want a persistent bootstrap reminder for this workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
contact-find.sh:4
Finding

Bearer API Credential Can Be Transmitted to an Untrusted Configurable Endpoint

Content
View full analysis
"$err")"; then ``` ### Technical Analysis The script takes request destinations from the `PRISMFY_API_URL`, `PRISMFY_API_ROOT`, and `PRISMFY_ME_URL` environment variables. It does not validate their URL schemes, hostnames, ports, or trust relationships before attaching the `PRISMFY_API_KEY` as a bearer credential. Consequently, any party able to influence the process environment or the wrapper used to invoke this script can redirect authenticated requests to an arbitrary destination. The risk is especially significant because the authorization header is added unconditionally after only checking that the API key is present. The search request also includes person, company, domain, role, and geographic query data in its JSON payload. The default endpoint is the expected Prismfy HTTPS service, so exploitation requires influence over configuration or the invocation environment. This is nevertheless ...[truncated 1495 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:48
Finding

Documentation Recommends Persistent Plaintext Storage of the API Key

Content
View full analysis
> ~/.bashrc source ~/.bashrc ``` `README.md`: ```bash echo 'export PRISMFY_API_KEY="ss_live_your_key_here"' >> ~/.bashrc source ~/.bashrc ``` ### Technical Analysis The setup instructions recommend writing a long-lived API credential directly into `~/.bashrc`. This stores the key as plaintext in a commonly read and frequently backed-up shell configuration file. Shell startup files may be collected in support bundles, copied between systems, synchronized as dotfiles, committed accidentally to source control, or exposed to other local accounts if permissions are too broad. Sourcing the file also exports the secret to subsequently launched child processes, increasing the number of processes that can access it. The issue is not a hardcoded credential in the package—the displayed value is an example—but the prescribed storage method encourages users to persist their real credential in an insufficiently protected location. ### Attack Path 1. A user follows the documented persistent-setup instructions and substitutes a valid Prismfy API key. 2. The key is stored in plaintext in `~/.bashrc`. 3. A local process or user with read access, a backup consumer, a support-bundle recipient, a dotfile synchronization service, or an accidental repository publication obtains the file. 4. The observer extracts the API key from the exported environment assignment. 5. The disclosed key can be reused against Prismfy until it expires or is revoked. ### Impact Assessment Exposure grants the attacker the API permissions and quota associated with the compromised Prismfy key. Potential consequences include unauthorized searches, quota depletion, charges where applicable, and activity being attributed to ...[truncated 265 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 70)May include surrounding context.

ecking whether a person has a public email trail,

  • finding company email-format clues for later human review.

Need a key?

Setup

  1. Install the skill:
bash
openclaw skills install contact-discovery
  1. Add your Prismfy API key:
bash
export PRISMFY_API_KEY="ss_live_your_key_here"

To keep it after restart:

bash
echo 'export PRISMFY_API_KEY="ss_live_your_key_here"' >> ~/.bashrc
source ~/.bashrc

Preflight:

  • PRISMFY_API_KEY is set
  • curl and jq are installed

Advanced setup:

  • if quota lives on a different endpoint than search, set PRISMFY_API_ROOT or PRISMFY_ME_URL
  1. Verify API access:
bash
cd ~/.openclaw/workspace/skills/contact-discovery
bash contact-find.sh --quota
  1. Quick smoke test:
bash
cd ~/.openclaw/workspace/skills/contact-discovery
bash contact-find.sh --company "Vercel" --query-family company
  1. Export a JSON report:
bash
cd ~/.openclaw/workspace/skills/

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

ecking whether a person has a public email trail,

  • finding company email-format clues for later human review.

Need a key?

Setup

  1. Install the skill:
bash
openclaw skills install contact-discovery
  1. Add your Prismfy API key:
bash
export PRISMFY_API_KEY="ss_live_your_key_here"

To keep it after restart:

bash
echo 'export PRISMFY_API_KEY="ss_live_your_key_here"' >> ~/.bashrc
source ~/.bashrc

Preflight:

  • PRISMFY_API_KEY is set
  • curl and jq are installed

Advanced setup:

  • if quota lives on a different endpoint than search, set PRISMFY_API_ROOT or PRISMFY_ME_URL
  1. Verify API access:
bash
cd ~/.openclaw/workspace/skills/contact-discovery
bash contact-find.sh --quota
  1. Quick smoke test:
bash
cd ~/.openclaw/workspace/skills/contact-discovery
bash contact-find.sh --company "Vercel" --query-family company
  1. Export a JSON report:
bash
cd ~/.openclaw/workspace/skills/

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · contact-find.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
set -euo pipefail

API_URL="${PRISMFY_API_URL:-https://api.prismfy.io/v1/search}"
API_URL="${API_URL%/}"
API_ROOT="${PRISMFY_API_ROOT:-}"
API_ROOT="${API_ROOT%/}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The code performs an authenticated POST request to an external service containing assembled search queries derived from person/company/domain inputs. Because this skill is specifically designed to discover contact details, the transmitted payload may include personal names and employer associations, making third-party exfiltration of user-supplied reconnaissance data a meaningful privacy risk.

Content

Scanner excerpt · contact-find.sh (reported line 223)May include surrounding context.

sh
while (( attempt < max_attempts )); do
    attempt=$((attempt + 1))
    err="$(mktemp)"
    if response="$(curl -m 20 -fsS "$API_URL" \
      -H "Authorization: Bearer $PRISMFY_API_KEY" \
      -H "Content-Type: application/json" \
      -d "$payload" 2>"$err")"; then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends user-supplied person, company, domain, and role data to a third-party Prismfy API without any user-facing disclosure or consent mechanism. In a contact-discovery skill, these queries can contain personal data or sensitive business targeting information, so undisclosed external transmission creates a real privacy and data-handling risk even if it is central to the feature.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code reads PRISMFY_API_KEY from the environment and uses it for authenticated requests, but it provides no warning in comments, help text, or runtime output that a sensitive credential is required and will be used. This falls under the code-file criterion for access to sensitive environment variables lacking disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.