Back to skill

Security audit

Quackgram

Security checks for vulnerabilities and agentic risk

Overview

QuackGram’s messaging purpose is clear, but the skill sends and reads agent messages through an external relay with weak identity and inbox scoping controls.

Review this skill before installing if you care about message authenticity or inbox privacy. It is meant to use an external relay, so do not send secrets or sensitive instructions through it unless you trust QuackGram’s service and retention practices. The current client does not visibly authenticate sender ownership or inbox access, and it unnecessarily handles the Quack API key in setup examples.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/send.mjs:18
Finding

Arbitrary Sender Identity Override Without Authentication

Content
View full analysis
--message [--from ]'); process.exit(1); } const creds = loadCreds(); const from = args.from || creds.agentId || 'openclaw/main'; const res = await fetch(QUACKGRAM_API, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ from, to: args.to, message: args.message }), }); const data = await res.json().catch(() => res.text()); console.log(JSON.stringify(data, null, 2)); } ``` ### Technical Analysis The script allows the caller to provide an arbitrary sender identity through `--from`. It then places that value directly into the request body. Although the credential file contains an API key, the request has no authorization header, signature, token, or other proof that the caller owns the selected identity. Consequently, the client does not enforce an association between the authenticated account and the claimed sender. If the relay accepts the submitted `from` property without an independent server-side ownership check, any local caller capable of running this script can impersonate another agent. The script reads credentials before sending, but credential presence is not equivalent to authentication because neither the API key nor any credential-derived proof is transmitted. ### Attack Path 1. The a ...[truncated 1092 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/inbox.mjs:16
Finding

Arbitrary Inbox Selection Without Authentication

Content
View full analysis
res.text()); console.log(JSON.stringify(data, null, 2)); } ``` ### Technical Analysis The inbox identifier can be overridden by the first positional command-line argument. The resulting request contains no API key or other authorization credential. URL encoding prevents path injection, but it does not establish that the caller owns or is permitted to read the requested inbox. If the external relay authorizes access solely by the agent identifier in the URL, any caller can request another agent's inbox. The local credential-file check does not mitigate this because credential possession is neither transmitted nor bound to the requested `agentId`. The actual disclosure depends on the external service's server-side controls. Nevertheless, the client implements no authentication and explicitly facilitates arbitrary inbox selection, creating an unsafe access-control model. ### Attack Path 1. The attacker learns or guesses a victim agent identifier. 2. The attacker invokes: ```bash node scripts/inbox.mjs "victim/main" ``` 3. The script sends: ```text GET https://quack-gram.replit.app/api/inbox/victim%2Fmain ``` without an authorization token. 4. If the relay does not independently authenticate and authorize the request, it returns the victim's inbox. 5. The script prints the returned messages to standard output. ### Impact Assessment If the relay relies on the URL identifier rather than server-side authorization, an attacker could read mes ...[truncated 334 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:12
Finding

Unnecessary Reading and Shell Extraction of an Unused API Key

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill performs network operations to an external relay service but does not declare any tool scope or permissions boundary. This weakens user and platform visibility into what capabilities the skill needs, increasing the chance of unintended data transmission or overbroad execution in environments that rely on manifest-declared permissions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough that the skill may auto-activate for generic messaging-related requests, causing an agent to invoke external messaging functionality unexpectedly. Because the skill transmits data off-platform, overbroad activation increases the risk of accidental disclosure of user content or agent identifiers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to send agent IDs and message bodies to an external network service without an explicit warning that this is an off-platform transmission. Users may believe the action is internal agent coordination when it actually discloses metadata and content to a third-party relay.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The curl example explicitly posts sender ID, recipient ID, and message content to an external endpoint. While external transmission is core to the skill's purpose, it is still security-relevant because it can expose sensitive instructions, identity metadata, or secrets if invoked without clear consent and data-handling warnings.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Or via curl:

bash
curl -s -X POST "https://quack-gram.replit.app/api/send" \
  -H "Content-Type: application/json" \
  -d "{\"from\":\"$AGENT_ID\",\"to\":\"recipient/main\",\"message\":\"Hello!\"}"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script automatically reads credentials from the local home directory and immediately uses them to make a network request to a third-party service, without any prompt, consent, or visible warning to the user. In an agent-skill context, this creates a data-flow from local sensitive material to an external endpoint that may be triggered implicitly, increasing the risk of unintended credential use, privacy leakage, or covert agent enumeration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script reads a local credential file to derive the sender identity and transmits user-supplied message content to an external API, but it provides no explicit disclosure, consent prompt, or trust boundary warning before doing so. In an agent skill ecosystem, this is risky because users or upstream agents may not realize that local state is being accessed and data is leaving the host to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.