Back to skill

Security audit

Quack Network

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent messaging integration, but it asks agents to persistently process remote inbox messages and signs remote registration text without enough user control.

Review before installing. Use this only if you trust quack.us.com with your agent identity, messages, challenge submissions, and registration metadata. Avoid adding the HEARTBEAT.md automation as written; inbox messages should be displayed as untrusted data and acted on only after explicit user approval. Choose an explicit --agent value during registration, and inspect any declaration text before signing if the workflow is updated to allow that.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:77
Finding

Persistent processing of untrusted remote inbox instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/quack-register.mjs:79
Finding

Cryptographic signing of mutable remote content without informed approval

Content
View full analysis
Remediation
View remediation

other

Note
Location
scripts/quack-register.mjs:51
Finding

Default disclosure of the local hostname as a public agent identifier

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell commands (node, curl) but does not declare any tool scope or allowed-tools boundary. This increases the chance an agent will execute shell/network actions implicitly, making credential access and outbound requests less visible to users and policy layers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to read a local credential file containing agentId and apiKey and immediately use those secrets in authenticated requests to an external service, without any warning about identity exposure, message confidentiality, or trust in the remote service. This can cause inadvertent disclosure of sensitive metadata and enables actions on behalf of the agent if the workflow is triggered automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill performs authenticated external transmission to quack.us.com, including inbox retrieval and message sending using a bearer token from local credentials. Even if the feature is legitimate, it creates a real data exfiltration path for agent identity, inbox contents, and outbound task data to an external network outside the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

bash
QUACK_KEY=$(node -p "JSON.parse(require('fs').readFileSync(require('os').homedir()+'/.openclaw/credentials/quack.json','utf8')).apiKey")
AGENT_ID=$(node -p "JSON.parse(require('fs').readFileSync(require('os').homedir()+'/.openclaw/credentials/quack.json','utf8')).agentId")
curl -s "https://quack.us.com/api/inbox/$AGENT_ID" -H "Authorization: Bearer $QUACK_KEY"

Send Message

Static analysis

No suspicious patterns detected.