Back to skill

Security audit

Veeam MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is intended to connect OpenClaw to Veeam, but it handles powerful backup-system credentials in ways that need careful review before installation.

Review this skill carefully before installing. Use a dedicated least-privilege Veeam account instead of an administrator account, do not print or share the credentials file, require trusted certificates or certificate pinning, and only run a Veeam MCP Docker image whose source and exact digest you have verified.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/list-tools.sh:31
Finding

Unconditional Acceptance of Untrusted TLS Certificates

Content
View full analysis
&1) ``` ### Technical Analysis Every execution path unconditionally sets `ACCEPT_SELF_SIGNED_CERT=true`. Supporting a privately issued or self-signed certificate can be legitimate in an internal Veeam deployment, but unconditional acceptance removes reliable authentication of the configured server. The scripts do not provide a secure default, a trusted CA bundle, certificate pinning, or an explicit per-server opt-in ...[truncated 1462 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/list-tools.sh:16
Finding

Administrator Credentials Are Delegated to an Externally Supplied Container

Content
View full analysis
Remediation
View remediation
``` 7. Verify the provenance, signature, and expected digest of the separately obtained beta package or image. 8. Apply container hardening, including: - A fixed non-root UID - `--read-only` - `--cap-drop=ALL` - `--security-opt=no-new-privileges` - A restrictive seccomp/AppArmor profile - No host filesystem or Docker socket mounts - Network restrictions limiting access to the configured Veeam endpoint 9. Validate that the credential file is owned by the current user and has mode `0600` before reading it. 10. Use separate credentials for VBR and Veeam ONE so compromise of one integration does not expose both systems. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:144
Finding

Troubleshooting Instructions Print Plaintext Credentials

Content
View full analysis
Remediation
View remediation
" else . end)' \ "$HOME/.veeam-mcp-creds.json" ``` 3. Update all three documentation files consistently. 4. Warn users not to paste unredacted credential files or terminal output into support channels. 5. Remove or correct claims that credentials cannot appear in logs, since environment injection and troubleshooting output can expose them. 6. Recommend immediate credential rotation if an unredacted file has already been shared or logged. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · README.md (reported line 126)May include surrounding context.

Query Veeam ONE

./scripts/query-veeam.sh vone "Show current infrastructure alerts"

List available MCP tools

./scripts/list-tools.sh vbr

text

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

Query Veeam ONE

./scripts/query-veeam.sh vone "Show current infrastructure alerts"

List available MCP tools

./scripts/list-tools.sh vbr

text

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · README.md (reported line 248)May include surrounding context.

│ ├── query-veeam.sh # Main query interface │ ├── test-connection.sh # Connection testing │ ├── start-mcp.sh # Interactive MCP session │ └── list-tools.sh # List MCP tools └── .clawhub/ └── metadata.json # ClawHub metadata

text

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

This script explicitly loads Veeam server credentials from a file in the user's home directory and injects them into a Docker container to enumerate MCP tools. In the context of an agent skill, access to centralized backup-management credentials and exposing them to a container materially increases risk because any compromised image, logging path, or child process can use those secrets to access backup infrastructure.

Content

Scanner excerpt · scripts/list-tools.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# List available MCP tools from Veeam server
# Usage: ./list-tools.sh <vbr|vone>

set -euo pipefail

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README claims credentials are 'never exposed' and absent from command history, but later instructs users to print the full credentials file with cat ~/.veeam-mcp-creds.json | jq .. Displaying secrets in a terminal can expose them via scrollback, session recording, screenshots, shoulder surfing, or shell tooling, directly contradicting the security claim.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users to create a plaintext JSON file containing administrative usernames and passwords for backup infrastructure, but does not prominently warn about the sensitivity of those credentials or recommend safer secret storage options. Because these are likely privileged Veeam and Windows/domain credentials, compromise could expose backup systems and broader infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs users to place Veeam usernames and passwords in a local JSON file in plaintext. Although it suggests restrictive file permissions, that does not eliminate the risk of credential exposure through local compromise, backups, shell history, accidental sharing, or misconfigured home directory access. In the context of backup infrastructure, exposed credentials can grant access to highly sensitive systems and data.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 92)May include surrounding context.

Lock it down:

bash
chmod 600 ~/.veeam-mcp-creds.json

5. Test Connection

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README_QUICK.md (reported line 62)May include surrounding context.

Lock it down:

bash
chmod 600 ~/.veeam-mcp-creds.json

5. Test Connection

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Lock it down:

bash
chmod 600 ~/.veeam-mcp-creds.json

5. Test Connection

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 203)May include surrounding context.

Docker permission denied:

bash
sudo usermod -aG docker $USER
newgrp docker

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README_QUICK.md (reported line 128)May include surrounding context.

Docker permission denied:

bash
sudo usermod -aG docker $USER
newgrp docker

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents network-capable behavior but does not declare an explicit tool scope such as permissions or allowed-tools. That increases the risk of overbroad execution in host environments because users and reviewers cannot easily verify what outbound access the skill is expected to use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation does not clearly warn users that their natural-language queries and potentially sensitive backup or infrastructure metadata are sent to a beta MCP server and downstream Veeam services. This can lead to unintentional disclosure of operational details, hostnames, backup states, and other sensitive environment data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill instructs users to store persistent administrative credentials in a local JSON file in the home directory. Even with restrictive permissions, long-lived plaintext secrets on disk increase exposure from local compromise, backups, accidental disclosure, or malware, especially because these are Veeam admin credentials.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
## Configuration

### Create Credentials File

Create `~/.veeam-mcp-creds.json`:

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims credentials are not exposed in logs or command history, yet the troubleshooting example passes the admin password directly on the command line. Command-line secrets are commonly exposed through shell history, process listings, audit logs, and terminal capture, making this a direct credential-handling flaw.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

The documentation references a Docker image by name without a version tag or digest, which can cause users to run different or unexpectedly changed images over time. In a beta server handling administrative Veeam credentials, this creates avoidable supply-chain risk if the image is rebuilt, replaced, or tampered with.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents accepting self-signed HTTPS certificates without a clear warning about the resulting loss of strong server authenticity guarantees. In an admin-credentialed backup environment, this can enable man-in-the-middle interception or credential theft if users normalize insecure TLS practices.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
## Security Notes

- Credentials stored locally in `~/.veeam-mcp-creds.json` (chmod 600)
- Docker container runs with non-root user
- HTTPS connections with self-signed cert acceptance
- No credentials exposed in logs or command history

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The script runs a Docker image by name only (veeam-intelligence-mcp-server) without pinning a tag or immutable digest. This allows unexpected image drift or a malicious/poisoned image from a local cache or registry to be executed, and because the script passes Veeam credentials as environment variables into the container, a substituted image could immediately exfiltrate secrets and query infrastructure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The script runs a Docker image by name only (veeam-intelligence-mcp-server) without a pinned tag or digest, so the actual code executed can change over time or be replaced by a malicious image from a registry or local cache. This is especially dangerous here because the container receives Veeam admin credentials via environment variables and is trusted to process backup-management queries, so a compromised image could exfiltrate secrets or issue unauthorized actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The script runs a Docker image by name only, without pinning a specific tag or immutable digest. This allows the image contents to change over time or be replaced in the registry, which is especially dangerous here because the container is launched with backup system credentials and server URLs as environment variables, so a malicious or compromised image could exfiltrate secrets or tamper with monitoring results.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The script runs a Docker image by name only (veeam-intelligence-mcp-server) without pinning a specific tag or immutable digest. This allows the executed code to change over time or be replaced unexpectedly, which is especially risky here because sensitive Veeam credentials are passed into the container as environment variables; a malicious or compromised image could exfiltrate those secrets or perform unauthorized network actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.