Back to skill

Security audit

Lead Enrichment Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed lead-enrichment helper that sends user-provided lead queries to Prismfy and optionally saves reports or installs a reminder hook.

Install only if you are comfortable sending lead-enrichment queries to Prismfy. Prefer setting PRISMFY_API_KEY only for the session or via a dedicated secret manager rather than storing it in ~/.bashrc, avoid custom endpoint variables unless you trust the exact HTTPS host, and keep exported JSON reports out of shared folders or source control.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
lead-enrich.sh:4
Finding

API Credential Disclosure Through Unrestricted Endpoint Overrides

Content
View full analysis
"$err")"; then ``` ### Technical Analysis The script permits `PRISMFY_API_URL`, `PRISMFY_API_ROOT`, and `PRISMFY_ME_URL` to control network destinations without validating their schemes, hostnames, ports, or trust boundaries. Both quota and search requests attach `PRISMFY_API_KEY` as a bearer token. Consequently, a manipulated environment can redirect the request to an attacker-controlled endpoint. The script also permits plain HTTP URLs, which can expose the bearer token and request data to network interception. The search payload can contain company names, domains, person names, roles, geographic criteria, and ICP information. Therefore, endpoint redirection can disclose both the API credential and lead-enrichment input data. This is not evidence of intentional exfiltration: the normal default destination is the documented Prismfy API. The vulnerability arises because credential-bearing endpoint overrides are accepted without security validation. ### Attack Path 1. An attacker gains the ability to influence the environment used to launch the Skill, such as through a compromised shell profile, CI configuration, wrap ...[truncated 1599 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 69)May include surrounding context.

r:

  • lead qualification,
  • pre-outreach verification,
  • company/person enrichment after a lead is already found.

Need a key?

Setup

  1. Install the skill:
bash
openclaw skills install lead-enrichment
  1. Add your Prismfy API key:
bash
export PRISMFY_API_KEY="ss_live_your_key_here"

To keep it after restart:

bash
echo 'export PRISMFY_API_KEY="ss_live_your_key_here"' >> ~/.bashrc
source ~/.bashrc

Preflight:

  • PRISMFY_API_KEY is set
  • curl and jq are installed

Advanced setup:

  • if quota lives on a different endpoint than search, set PRISMFY_API_ROOT or PRISMFY_ME_URL
  1. Verify API access:
bash
cd ~/.openclaw/workspace/skills/lead-enrichment
bash lead-enrich.sh --quota
  1. Quick smoke test:
bash
cd ~/.openclaw/workspace/skills/lead-enrichment
bash lead-enrich.sh --company "Vercel" --query-family identity
  1. Export a JSON report:
bash
cd ~/.openclaw/workspace/skills/lead-

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

r:

  • lead qualification,
  • pre-outreach verification,
  • company/person enrichment after a lead is already found.

Need a key?

Setup

  1. Install the skill:
bash
openclaw skills install lead-enrichment
  1. Add your Prismfy API key:
bash
export PRISMFY_API_KEY="ss_live_your_key_here"

To keep it after restart:

bash
echo 'export PRISMFY_API_KEY="ss_live_your_key_here"' >> ~/.bashrc
source ~/.bashrc

Preflight:

  • PRISMFY_API_KEY is set
  • curl and jq are installed

Advanced setup:

  • if quota lives on a different endpoint than search, set PRISMFY_API_ROOT or PRISMFY_ME_URL
  1. Verify API access:
bash
cd ~/.openclaw/workspace/skills/lead-enrichment
bash lead-enrich.sh --quota
  1. Quick smoke test:
bash
cd ~/.openclaw/workspace/skills/lead-enrichment
bash lead-enrich.sh --company "Vercel" --query-family identity
  1. Export a JSON report:
bash
cd ~/.openclaw/workspace/skills/lead-

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell commands extensively (bash, curl, jq) but does not declare any explicit tool scope or permissions boundary. This can cause the agent or operator to run shell-capable workflows without a clear least-privilege contract, increasing the chance of unintended command execution or misuse in automation contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup instructions tell users to append a live API key directly into ~/.bashrc, which persists the secret in plaintext on disk and increases exposure through backups, dotfile syncing, shell-history mistakes, or local compromise. While common, this is still unsafe credential-handling guidance because it normalizes long-lived secret storage without warning or safer alternatives.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file describes a bootstrap hook whose stated function is to inject a reminder, but the reminder explicitly tells the agent to use lead-enrich.sh with PRISMFY_API_KEY. Accessing or relying on credentials is a distinct capability that is not justified by the hook’s narrow documented purpose of injecting a lightweight reminder.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · lead-enrich.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
set -euo pipefail

API_URL="${PRISMFY_API_URL:-https://api.prismfy.io/v1/search}"
API_URL="${API_URL%/}"
API_ROOT="${PRISMFY_API_ROOT:-}"
API_ROOT="${API_ROOT%/}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This code performs authenticated external transmission of enrichment queries to a remote service using curl and a bearer token. Because the skill processes lead data and potentially person names and employer information, the transmission can leak commercially sensitive targeting data or personal information to an external processor; the skill context makes this more significant than a generic web lookup helper.

Content

Scanner excerpt · lead-enrich.sh (reported line 319)May include surrounding context.

sh
while (( attempt < max_attempts )); do
    attempt=$((attempt + 1))
    err="$(mktemp)"
    if response="$(curl -m 20 -fsS "$API_URL" \
      -H "Authorization: Bearer $PRISMFY_API_KEY" \
      -H "Content-Type: application/json" \
      -d "$payload" 2>"$err")"; then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends user-supplied enrichment inputs such as company, domain, person name, role, geography, and ICP-derived search terms to a third-party API, but it provides no explicit user-facing notice, consent step, or data-minimization control at the point of transmission. In a lead-enrichment skill, these queries can reveal sensitive business intent, prospecting targets, or personal data about individuals, making the external disclosure meaningful even if the transport is over HTTPS.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file includes instructions to export results with --out lead_enrichment_report.json, which causes a file write. The README explains how to perform the export but does not include any user-facing warning that the command creates a local artifact containing lead-enrichment data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.