Back to skill

Security audit

iccn-erp

Security checks for vulnerabilities and agentic risk

Overview

This ERP lookup skill is coherent but needs review because it can use a bearer token to query sensitive business records and includes under-scoped external API behavior.

Install only if you control the ERP endpoint and token scope. Configure a trusted HTTPS ERP base URL, use a narrowly scoped read-only token, avoid broad automatic lookups of customer or supplier data without confirmation, and do not reuse the dev.iccn.cc reference UI endpoint for production data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:19
Finding

ERP bearer token can be transmitted to an unrestricted environment-configured destination

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–38
Vulnerability Type: Unrestricted credential destination
Risk Level: High

Vulnerable Code

javascript
const ERP_TOKEN = process.env.ERP_API_TOKEN;
const ERP_BASE_URL = process.env.ERP_API_BASE_URL;

const erpQuery = async (table, params = {}) => {
  const url = `${ERP_BASE_URL}/v1/${table}/lists`;
  const body = {
    page: 1,
    pagenum: 50,
    like: {},
    where: {},
    order: {},
    ...params
  };
  const response = await fetch(url, {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',
      'authorization': `Bearer ${ERP_TOKEN}`
    },
    body: JSON.stringify(body)
  });
  return await response.json();
};

Technical Analysis

The Skill reads a sensitive bearer credential from ERP_API_TOKEN and attaches it to requests sent to a URL derived entirely from ERP_API_BASE_URL. Sending a credential over the network is necessary for the declared ERP-query functionality, but allowing an unrestricted environment value to determine the credential recipient exceeds minimum privilege.

The implementation does not validate:

  • The destination hostname against an approved allowlist.
  • Whether the URL uses HTTPS.
  • Whether the URL contains embedded credentials or an unexpected port.
  • Whether redirects can forward the request to another origin.
  • Whether the configured destination is authorized to receive the ERP token.

Environment variables are not inherently trusted security boundaries. Configuration tampering, deployment mistakes, or a compromised configuration file could redirect requests to an attacker-controlled server. The request body can also expose order numbers, customer or supplier search terms, inventory models, and other sensitive ERP filters.

Attack Path

  1. An attacker or compromised deployment process modifies ERP_API_BASE_URL in the runtime environment or referenced openclaw.json configuration.
  2. The value is changed to a ...[truncated 1307 chars]
Remediation
View remediation

Remediation Suggestions

  1. Parse ERP_API_BASE_URL with a standard URL parser before issuing any request.
  2. Require the https: scheme and reject plaintext HTTP.
  3. Allowlist the exact production ERP hostname and, if applicable, the expected port and base path.
  4. Reject URLs containing embedded usernames or passwords, fragments, unexpected ports, or non-approved origins.
  5. Disable automatic redirects or validate every redirect target before following it. Never forward authorization credentials across origins.
  6. Bind the token to the intended ERP audience and use narrowly scoped, read-only permissions for a query-only Skill.
  7. Prefer short-lived credentials and implement rotation and revocation procedures.
  8. Keep the token out of logs, exception messages, telemetry, and debugging output.
  9. Separate credentials by environment so development or test services cannot use production tokens.
  10. Consider moving authenticated ERP communication into a trusted backend proxy that enforces the destination, route allowlist, request schema, and response limits.

T09 · Insecure Skill Coding Practices

Warning
Location
references/order-detail-ui.md:20
Finding

Reference UI sends order identifiers to a fixed external development endpoint

Content
View full analysis

Vulnerability Details

File Location: references/order-detail-ui.md, lines 20–24
Vulnerability Type: Sensitive business identifier disclosure through a fixed development endpoint and URL query parameter
Risk Level: Medium

Vulnerable Code

javascript
const response = await fetch(
  `https://dev.iccn.cc/api/openclaw/order_detail?order_no=${encodeURIComponent(orderNo.trim())}`
);
const data = await response.json();

Technical Analysis

The supplied React reference implementation sends user-entered order numbers to the fixed external destination https://dev.iccn.cc. This differs from the environment-configured ERP API documented in SKILL.md and may cause applications adopting the example to disclose business identifiers to a development service.

The order number is placed in a GET query string. Although encodeURIComponent prevents basic query-string injection, it does not protect the confidentiality of the value. URLs may be retained in:

  • Development-server access logs.
  • Reverse-proxy and gateway logs.
  • Browser history.
  • Network monitoring and observability systems.
  • Error reports and analytics products.
  • Referrer data in some navigation scenarios, depending on applicable browser policy.

The reference does not establish that this endpoint is an approved recipient, describe data retention, require application-level authentication, or limit which callers may enumerate orders. HTTPS protects data in transit but does not prevent the endpoint or its infrastructure from recording the identifier.

Attack Path

  1. A developer copies the documented React example into an application.
  2. A user enters a valid or sensitive sales order number.
  3. The browser sends a GET request containing the order number to dev.iccn.cc.
  4. The development service and intermediary infrastructure receive and may log the identifier.
  5. Anyone with access to those systems or logs may learn the queried order identifiers and query activity.
  6. If ...[truncated 831 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the fixed development URL from production-facing reference code.
  2. Route browser requests through an approved application backend that authenticates users and enforces record-level authorization.
  3. Use the same validated and documented ERP origin or a trusted backend proxy rather than an unrelated hardcoded destination.
  4. Prefer a POST request body for sensitive lookup values to reduce routine exposure in URL and access logs. This does not replace encryption or authorization.
  5. Require authentication, authorization, rate limiting, and anti-enumeration controls on the order-detail endpoint.
  6. Configure gateways, proxies, telemetry, and application logs to redact order identifiers where they are not operationally necessary.
  7. Document the data recipient, purpose, retention period, and environment classification.
  8. Apply an appropriate restrictive referrer policy and avoid including sensitive identifiers in URLs.
  9. Return only the minimum order fields needed by the interface rather than rendering every property from the response.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger definition is excessively broad and explicitly says the skill must be used for any mention of ERP business data. That can cause automatic transmission of potentially sensitive order, customer, supplier, and inventory queries to an external API without sufficient user intent verification or least-privilege routing, increasing the chance of unintended data access and disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to send query parameters to an external ERP API using environment-sourced credentials, but it does not disclose this behavior to users or warn that business data will leave the current conversation context. This reduces transparency and informed consent, and in an ERP context the transmitted data may include commercially sensitive customer, supplier, order, and inventory information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example sends user-entered order numbers to an external endpoint at dev.iccn.cc, but the surrounding documentation does not warn users or integrators that business identifiers will leave the local UI and be transmitted over the network. In an ERP context, order numbers can be sensitive business metadata, and silent transmission to a development-domain API increases privacy, data-governance, and environment-misuse risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language instructions and UI text are entirely in Chinese, which can amount to a language-policy issue when no user opt-in or locale justification is provided. There is no indication that this skill is intentionally restricted to Chinese-speaking users or a region-specific compliance context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.