Back to skill

Security audit

Offlyn Clipper

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real local Offlyn Clipper integration, but it needs review because it can expose sensitive meeting and note content, stores reusable credentials, and trusts a local socket too broadly.

Install only if you trust Offlyn Clipper and are comfortable letting OpenClaw access local notes and live meeting context. Review the credential file location, keep the socket path under your control, avoid custom CLIPPER_SOCKET_PATH values unless you know why they are needed, and be cautious with broad prompts like 'catch me up' because they may retrieve live meeting data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
mcp-bridge/index.mjs:250
Finding

Untrusted Clipper Content Is Presented as Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: mcp-bridge/index.mjs:250-257
Vulnerability Type: Prompt injection across an external-content trust boundary
Risk Level: High

Vulnerable Code

js
function formatCatchMeUpResult(result) {
  const prompt = result.suggested_agent_prompt ?? result.suggestedAgentPrompt;
  const recap = result.recap_context ?? result.recapContext ?? result.answer ?? "";
  const title = result.title ?? "Current meeting";
  const recording = result.is_recording ?? result.isRecording;
  const header = recording
    ? `Live meeting: ${title} (recording)`
    : `Meeting session: ${title} (paused — transcript so far)`;
  return `${header}\n\n${recap}\n\n---\nSummarize the above for the user (catch me up): decisions, open questions, action items, and current topic.${prompt ? `\nSuggested prompt: ${prompt}` : ""}`;
}

Technical Analysis

The bridge receives recap_context, answer, and suggested_agent_prompt from the external Clipper socket and places them directly into text returned to the AI agent. In particular, the externally supplied suggested_agent_prompt is labeled as a suggested prompt and combined with an imperative instruction telling the agent to summarize the preceding content.

No boundary marker or policy tells the agent that the transcript, recap, and suggested prompt are untrusted data that must not be interpreted as instructions. No filtering or structured separation is applied. Consequently, instruction-like content originating in a meeting transcript, note, compromised Clipper process, or spoofed socket response can compete with the legitimate task instructions.

This is an instruction-hijacking risk rather than conventional code execution. Exploitation depends on the consuming agent interpreting malicious content as authoritative instructions.

Attack Path

  1. An attacker causes malicious instruction-like text to appear in a recorded meeting, note, rec ...[truncated 1132 chars]
Remediation
View remediation

Remediation Suggestions

  1. Return structured JSON fields instead of combining external content with imperative prose. Keep recap_context, title, recording state, and other data in separate fields.
  2. Do not forward suggested_agent_prompt as an instruction. Remove it, or render it as explicitly quoted and untrusted source data.
  3. Add a high-priority tool description stating that meeting transcripts, notes, presets, summaries, socket responses, and suggested prompts are untrusted content and must never authorize tool calls or override system, developer, user, or skill instructions.
  4. Ask the agent to summarize only factual meeting content and to ignore any commands embedded in that content.
  5. Where practical, normalize or reject fields that are not required for the requested operation.
  6. Add adversarial tests using transcript content such as requests to ignore prior instructions, reveal secrets, or invoke unrelated tools. Verify that such text is quoted or summarized as meeting content rather than executed as an instruction.

T07 · Tool Hijacking and Spoofing

Error
Location
mcp-bridge/clipper-socket.mjs:43
Finding

Unix Socket Endpoint Is Trusted Without Peer Verification

Content
View full analysis

Vulnerability Details

File Location: mcp-bridge/clipper-socket.mjs:6-9, 43-69
Vulnerability Type: Unauthenticated local endpoint selection and tool-response spoofing
Risk Level: High

Vulnerable Code

js
export function defaultSocketPath() {
  if (process.env.CLIPPER_SOCKET_PATH) {
    return process.env.CLIPPER_SOCKET_PATH;
  }
  const home = os.homedir();
  const candidates = [
    path.join(home, "Library/Application Support/ai.offlyn.clipper/clipper.sock"),
    path.join(
      home,
      "Library/Containers/ai.offlyn.clipper/Data/Library/Application Support/ai.offlyn.clipper/clipper.sock"
    ),
  ];
  for (const p of candidates) {
    if (fs.existsSync(p)) return p;
  }
  return candidates[0];
}
js
export async function callClipper(method, params) {
  const socketPath = defaultSocketPath();
  const payload = JSON.stringify({
    jsonrpc: "2.0",
    id: crypto.randomUUID(),
    method,
    params,
  });

  return new Promise((resolve, reject) => {
    const client = net.createConnection(socketPath);
    let buffer = Buffer.alloc(0);

    client.on("error", reject);
    client.on("data", (chunk) => {
      buffer = Buffer.concat([buffer, chunk]);
      const idx = buffer.indexOf(0x0a);
      if (idx >= 0) {
        const line = buffer.subarray(0, idx).toString("utf8");
        client.end();
        try {
          resolve(JSON.parse(line));
        } catch (e) {
          reject(e);
        }
      }
    });

    client.on("connect", () => {
      client.write(payload + "\n");
    });
  });
}

Technical Analysis

The bridge accepts CLIPPER_SOCKET_PATH without validating that the path points to the genuine Offlyn Clipper socket. For both configured and automatically selected paths, it does not verify the canonical path, file type, owner, permissions, symlink status, or server identity before transmitting ...[truncated 2208 chars]

Remediation
View remediation

Remediation Suggestions

  1. Canonicalize the socket path and restrict it to explicitly approved Offlyn Clipper application directories.
  2. Use lstat and reject symbolic links, non-socket objects, unexpected owners, and paths or parent directories with unsafe permissions.
  3. Require the socket and relevant directories to be owned by the current user and inaccessible to other users where the platform permits.
  4. Treat CLIPPER_SOCKET_PATH as privileged configuration. Reject arbitrary paths unless an explicit development mode is enabled.
  5. Add mutual authentication at the application layer. The bridge should verify that each server session possesses a trusted Clipper identity key before sending a reusable credential or sensitive request.
  6. Prefer short-lived, audience-bound tokens and rotate or revoke a token after endpoint-authentication failures.
  7. Bind request and response authentication to the method, request identifier, nonce, and session to prevent forged or replayed results.
  8. Document the local attacker model and provide a command that verifies socket ownership, permissions, canonical location, and server identity before setup or use.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (26)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · PUBLISH.md (reported line 39)May include surrounding context.

The skill bundles mcp-bridge/ for self-contained installs. After changing OpenClawPlugin/mcp-bridge/, refresh the copy:

bash
rm -rf OpenClawPlugin/skills/offlyn-clipper/mcp-bridge
cp -R OpenClawPlugin/mcp-bridge OpenClawPlugin/skills/offlyn-clipper/mcp-bridge

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description focuses on meeting and note retrieval, but the file also instructs local skill installation/refresh, directory replacement, npm dependency installation, and CLI inspection commands. That broader behavior increases supply-chain and local-environment risk while remaining under-disclosed in the skill's stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description focuses on meeting and note retrieval, but the file also instructs local skill installation/refresh, directory replacement, npm dependency installation, and CLI inspection commands. That broader behavior increases supply-chain and local-environment risk while remaining under-disclosed in the skill's stated purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
export function credentialsPath() {
  return (
    process.env.CLIPPER_CREDENTIALS_PATH ||
    path.join(os.homedir(), ".config/offlyn-clipper/openclaw-credentials.json")
  );
}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mcp-bridge/clipper-socket.mjs (reported line 27)May include surrounding context.

js
export function credentialsPath() {
  return (
    process.env.CLIPPER_CREDENTIALS_PATH ||
    path.join(os.homedir(), ".config/offlyn-clipper/openclaw-credentials.json")
  );
}

Known Vulnerable Dependency: fast-uri==3.1.2 — 6 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +3 more

High
Category
Supply Chain
Confidence
89% confidence
Finding

fast-uri 3.1.2 is flagged for multiple host parsing and normalization issues including SSRF-relevant confusion bugs. URI parsing libraries are security-sensitive; if this bridge or its dependencies validate URLs, callback hosts, or network destinations with this version, an attacker may bypass allowlists or reach unintended internal resources.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: hono==4.12.23 — 15 advisory(ies): CVE-2026-71848 (Hono: Algorithmic Complexity DoS in Language Middleware); CVE-2026-71849 (Hono: Proxy Helper does not remove response headers listed in the `Connection` h); CVE-2026-54290 (hono: CORS Middleware reflects any Origin with credentials when `origin` default) +12 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

hono 4.12.23 is listed with numerous advisories affecting middleware and proxy/CORS behavior. Because this package is an MCP bridge and likely exposes HTTP endpoints through the SDK stack, framework-level flaws are more relevant here than in a purely local library and could enable request smuggling, header mishandling, origin policy weaknesses, or DoS depending on features used.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.2.0 — 3 advisory(ies): CVE-2026-54272 (ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSR); CVE-2026-69198 (ip-address: a CIDR suffix on the parsed address suppresses special-use classific); CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco)

High
Category
Supply Chain
Confidence
84% confidence
Finding

ip-address 10.2.0 is reported with address classification bugs that can undermine SSRF and network-policy checks. In an MCP bridge context, where network endpoints, callback addresses, or client IP logic may matter, misclassifying special-use or mapped addresses can let attackers bypass filters intended to block private or sensitive destinations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill declares no explicit tool scope or permission boundaries, yet the content shows capabilities involving environment-dependent configuration, local socket access, and connectivity to a desktop app. Without a clear allowlist, users and hosting systems may not understand the skill's effective reach, increasing the risk of overbroad access or accidental invocation of sensitive integrations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are very broad, including common language like 'meetings,' 'voice notes,' 'catch me up,' and 'what did I miss.' This can cause the skill to activate in contexts where the user did not intend access to Clipper data, increasing the chance of unnecessary exposure of sensitive meeting or notes content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill handles highly sensitive content—live meeting transcripts/recaps and saved notes—but does not present a clear upfront warning about that access in the description. Users may invoke it without understanding that current meeting content and stored note data can be surfaced through the assistant.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction to immediately call the live-meeting tool for generic phrases like 'catch me up' or 'recap the call' is ambiguous and may over-trigger on ordinary conversation. In the context of a tool that can access active meeting content, this creates a real privacy risk through unintended data retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This function loads credentials from a local file containing sensitive authentication data. The code provides no user-facing notice, logging, or explanatory comment that the skill accesses stored credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function writes credential data to a persistent file on disk, which is a safety-relevant operation involving sensitive data. In this file there is no confirmation prompt, logging, comment, or docstring disclosing that credentials will be stored locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill saves a token and exported private key to storage via saveCredentials, which is a sensitive credential-handling operation. While the file has a technical header comment, it does not provide any user-facing warning, confirmation, or visible disclosure around storing credentials locally.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language instruction for clipper_catch_me_up explicitly frames live transcript, user notes, and decisions as content to retrieve whenever the user asks to 'catch up' or recap. This is a semantic data-exposure pattern rather than an explicit technical exfiltration command: it normalizes collecting and surfacing potentially sensitive meeting content in plain language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill retrieves recap context from an active meeting and note content from Clipper, which can expose sensitive user data. Although tool descriptions mention what is returned, this code path lacks a direct warning or disclosure to the user when accessing live transcripts or note bodies.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The formatted response tells the agent to 'Summarize the above for the user' after inserting recap context from a live or paused meeting session. This is a plain-language instruction to process and reveal potentially sensitive user-provided content, and the appended suggested prompt can further steer the model's disclosure behavior semantically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists both a long-lived session token and the Ed25519 private key to disk, enabling future authentication without re-approval. If those saved credentials are readable by other local users, malware, backups, or logs, an attacker could impersonate the paired client and access Clipper note data without additional user consent. In a notes/live-meeting integration, that can expose sensitive meeting content and historical notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script forcefully removes the destination directory with rm -rf and then replaces it, which can delete existing user data in that path. Although the script prints source and destination paths, it does not explicitly warn that the target directory will be deleted or ask for confirmation before doing so.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @hono/node-server==1.19.14 — 1 advisory(ies): GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode)

Low
Category
Supply Chain
Confidence
81% confidence
Finding

The lockfile pins @hono/node-server 1.19.14, which is reported as affected by a Windows-specific path traversal in static file serving. A lockfile entry alone does not prove the vulnerable serve-static path is actually used, but shipping a known-vulnerable version in a bridge package is still a real supply-chain risk because the vulnerable code is present and may become reachable depending on runtime usage.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==2.2.2 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
66% confidence
Finding

body-parser 2.2.2 is flagged for a denial-of-service condition involving invalid limit handling. In this file we only know the package is present transitively through Express, so exploitability depends on whether attacker-controlled request bodies hit affected parsing paths, but the dependency version itself is vulnerable.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.15.2 — 2 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
72% confidence
Finding

qs 6.15.2 is affected by low-severity parsing and DoS issues. Since this is a transitive parser commonly used for query strings and form bodies, the risk depends on whether untrusted complex query structures are accepted, but the vulnerable package version is present in the shipped dependency set.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.