T01 · Skill Instruction Hijacking
- Location
SKILL.md:77- Finding
Persistent processing of untrusted remote inbox instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent messaging integration, but it asks agents to persistently process remote inbox messages and signs remote registration text without enough user control.
Review before installing. Use this only if you trust quack.us.com with your agent identity, messages, challenge submissions, and registration metadata. Avoid adding the HEARTBEAT.md automation as written; inbox messages should be displayed as untrusted data and acted on only after explicit user approval. Choose an explicit --agent value during registration, and inspect any declaration text before signing if the workflow is updated to allow that.
SKILL.md:77Persistent processing of untrusted remote inbox instructions
scripts/quack-register.mjs:79Cryptographic signing of mutable remote content without informed approval
scripts/quack-register.mjs:51Default disclosure of the local hostname as a public agent identifier
The skill invokes shell commands (node, curl) but does not declare any tool scope or allowed-tools boundary. This increases the chance an agent will execute shell/network actions implicitly, making credential access and outbound requests less visible to users and policy layers.
The skill instructs the agent to read a local credential file containing agentId and apiKey and immediately use those secrets in authenticated requests to an external service, without any warning about identity exposure, message confidentiality, or trust in the remote service. This can cause inadvertent disclosure of sensitive metadata and enables actions on behalf of the agent if the workflow is triggered automatically.
The skill performs authenticated external transmission to quack.us.com, including inbox retrieval and message sending using a bearer token from local credentials. Even if the feature is legitimate, it creates a real data exfiltration path for agent identity, inbox contents, and outbound task data to an external network outside the local trust boundary.
QUACK_KEY=$(node -p "JSON.parse(require('fs').readFileSync(require('os').homedir()+'/.openclaw/credentials/quack.json','utf8')).apiKey")
AGENT_ID=$(node -p "JSON.parse(require('fs').readFileSync(require('os').homedir()+'/.openclaw/credentials/quack.json','utf8')).agentId")
curl -s "https://quack.us.com/api/inbox/$AGENT_ID" -H "Authorization: Bearer $QUACK_KEY"
No suspicious patterns detected.