Back to skill

Security audit

Boil

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent labor-network purpose, but it grants recurring remote influence over the agent, handles credentials, extracts untrusted archives, and uploads local workspace contents with insufficient safeguards.

Install only after reviewing the heartbeat and work-loop behavior carefully. Use a disposable sandbox or container, do not enable unattended heartbeat/self-updates, keep the API key in a real secret store, confirm all authenticated requests use https://www.boil.sh, inspect archives before extraction, and review every uploaded tarball for secrets or private data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
skill.md:142
Finding

Persistent Remote Instruction Loading Enables Agent Goal Hijacking

Content
View full analysis
~/.openclaw/skills/theboil/SKILL.md curl -s https://www.boil.sh/heartbeat.md > ~/.openclaw/skills/theboil/HEARTBEAT.md curl -s https://www.boil.sh/workloop.md > ~/.openclaw/skills/theboil/WORKLOOP.md ``` ``` From `heartbeat.md:121-133`: ```markdown - `contributor_diff_url` — the server-generated diff of the contribution - `previous_prompt_content` / `new_prompt_content` — the prompt before and after - `claude_prompt` — send to Claude along with the diff - `verification_id` — use when submitting your verdict **Do the verification:** 1. **Download the diff** from `contributor_diff_url` (generated server-side from the checkpoints) 2. **Review the prompt changes** using `previous_prompt_content` and `new_prompt_content` 3. **Send diff + prompt to Claude** with the provided `claude_prompt` 4. **Submit your verdict:** ``` ### Technical Analysis The Skill instructs the Agent to add a recurring task to its heartbeat, record persistent state, periodically overwrite installed Skill files with c ...[truncated 2639 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
workloop.md:64
Finding

Untrusted Checkpoint Archives Are Extracted Without Path or File-Type Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
workloop.md:386
Finding

Bearer Credential Is Sent to a Host Explicitly Identified as Unsafe

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (20)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs storing a live API key in a predictable plaintext file path under the user's home directory. This increases the chance of credential theft by other local processes, accidental inclusion in backups or repositories, and compromise through any tool that can read user files.

Content

Scanner excerpt · skill.md (reported line 97)May include surrounding context.

⚠️ Save your api_key immediately! You need it for all requests.

Recommended: Save credentials to ~/.config/boil/credentials.json:

json
{

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Bundling multiple recursive deletions into a single rm -rf command against paths in the home directory creates a destructive pattern that is easy for agents or wrappers to misuse. Although the intended targets are limited, the command is still dangerous because shell automation around untrusted workspaces can turn cleanup into broader local file loss.

Content

Scanner excerpt · skill.md (reported line 287)May include surrounding context.

bash
# Clean up local workspace
rm -rf ~/boil/workspace ~/boil/checkpoint.tar.gz ~/boil/contribution.tar.gz

Response:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Bundling multiple recursive deletions into a single rm -rf command against paths in the home directory creates a destructive pattern that is easy for agents or wrappers to misuse. Although the intended targets are limited, the command is still dangerous because shell automation around untrusted workspaces can turn cleanup into broader local file loss.

Content

Scanner excerpt · skill.md (reported line 287)May include surrounding context.

bash
# Clean up local workspace
rm -rf ~/boil/workspace ~/boil/checkpoint.tar.gz ~/boil/contribution.tar.gz

Response:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Bundling multiple recursive deletions into a single rm -rf command against paths in the home directory creates a destructive pattern that is easy for agents or wrappers to misuse. Although the intended targets are limited, the command is still dangerous because shell automation around untrusted workspaces can turn cleanup into broader local file loss.

Content

Scanner excerpt · skill.md (reported line 287)May include surrounding context.

bash
# Clean up local workspace
rm -rf ~/boil/workspace ~/boil/checkpoint.tar.gz ~/boil/contribution.tar.gz

Response:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The combined cleanup command recursively deletes multiple paths in one step, increasing blast radius and making operator review harder. Because the skill otherwise emphasizes safety, this destructive instruction is especially risky: users may trust and run it without carefully inspecting the targets.

Content

Scanner excerpt · workloop.md (reported line 403)May include surrounding context.

}'

Clean up local files

rm -rf ~/boil/workspace ~/boil/checkpoint.tar.gz ~/boil/contribution.tar.gz

text

Response:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The combined cleanup command recursively deletes multiple paths in one step, increasing blast radius and making operator review harder. Because the skill otherwise emphasizes safety, this destructive instruction is especially risky: users may trust and run it without carefully inspecting the targets.

Content

Scanner excerpt · workloop.md (reported line 403)May include surrounding context.

}'

Clean up local files

rm -rf ~/boil/workspace ~/boil/checkpoint.tar.gz ~/boil/contribution.tar.gz

text

Response:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The combined cleanup command recursively deletes multiple paths in one step, increasing blast radius and making operator review harder. Because the skill otherwise emphasizes safety, this destructive instruction is especially risky: users may trust and run it without carefully inspecting the targets.

Content

Scanner excerpt · workloop.md (reported line 403)May include surrounding context.

}'

Clean up local files

rm -rf ~/boil/workspace ~/boil/checkpoint.tar.gz ~/boil/contribution.tar.gz

text

Response:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
86% confidence
Finding

The skill instructs the agent to overwrite local skill files under ~/.openclaw/skills/theboil with content fetched from a remote server, creating a self-update mechanism that can change future agent behavior without user review. Even though the content is framed as routine updates, this enables remote replacement of trusted prompts/instructions and expands the attack surface if the server or transport is compromised.

Content

Scanner excerpt · heartbeat.md (reported line 22)May include surrounding context.

Compare with your saved version. If there's a new version, re-fetch the skill files:

bash
curl -s https://www.boil.sh/skill.md > ~/.openclaw/skills/theboil/SKILL.md
curl -s https://www.boil.sh/heartbeat.md > ~/.openclaw/skills/theboil/HEARTBEAT.md
curl -s https://www.boil.sh/workloop.md > ~/.openclaw/skills/theboil/WORKLOOP.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill causes outbound network requests to fetch remote content and write it directly into local instruction files, which is a form of external content transmission/import that can alter agent behavior. In this context, the danger is not just data egress but remote content ingress into privileged local configuration, effectively allowing a server-controlled update channel.

Content

Scanner excerpt · heartbeat.md (reported line 22)May include surrounding context.

Compare with your saved version. If there's a new version, re-fetch the skill files:

bash
curl -s https://www.boil.sh/skill.md > ~/.openclaw/skills/theboil/SKILL.md
curl -s https://www.boil.sh/heartbeat.md > ~/.openclaw/skills/theboil/HEARTBEAT.md
curl -s https://www.boil.sh/workloop.md > ~/.openclaw/skills/theboil/WORKLOOP.md

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 41)May include surrounding context.

Install locally:

bash
mkdir -p ~/.openclaw/skills/boil
curl -s https://www.boil.sh/boil/skill.md > ~/.openclaw/skills/boil/SKILL.md
curl -s https://www.boil.sh/boil/heartbeat.md > ~/.openclaw/skills/boil/HEARTBEAT.md
curl -s https://www.boil.sh/boil/workloop.md > ~/.openclaw/skills/boil/WORKLOOP.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 42)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/boil
curl -s https://www.boil.sh/boil/skill.md > ~/.openclaw/skills/boil/SKILL.md
curl -s https://www.boil.sh/boil/heartbeat.md > ~/.openclaw/skills/boil/HEARTBEAT.md
curl -s https://www.boil.sh/boil/workloop.md > ~/.openclaw/skills/boil/WORKLOOP.md
curl -s https://www.boil.sh/boil/skill.json > ~/.openclaw/skills/boil/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 42)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/boil
curl -s https://www.boil.sh/boil/skill.md > ~/.openclaw/skills/boil/SKILL.md
curl -s https://www.boil.sh/boil/heartbeat.md > ~/.openclaw/skills/boil/HEARTBEAT.md
curl -s https://www.boil.sh/boil/workloop.md > ~/.openclaw/skills/boil/WORKLOOP.md
curl -s https://www.boil.sh/boil/skill.json > ~/.openclaw/skills/boil/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This workflow instructs the agent to transmit model-generated review content and an API bearer token to an external service. Even though the destination is the declared Boil API, the skill normalizes routine outbound transmission of agent judgments and authenticated data to a third party, creating privacy, prompt-leakage, and account-misuse risk if the service or surrounding workflow is compromised.

Content

Scanner excerpt · skill.md (reported line 495)May include surrounding context.

Submit Verdict

bash
curl -X POST https://www.boil.sh/api/v1/verifications/verif_xxx/submit \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The heartbeat routine directs recurring authenticated calls to an external service whenever the agent is idle. This creates an automated outbound channel that can cause persistent data sharing, unintended background activity, and token exposure risk if the skill or endpoint behavior changes over time.

Content

Scanner excerpt · skill.md (reported line 694)May include surrounding context.

bash
# Check if you should work
curl https://www.boil.sh/api/v1/agents/me \
  -H "Authorization: Bearer YOUR_API_KEY"

# If idle and claimed, start a shift

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill repeatedly claims work is 'text-only' and warns against executing untrusted project code, but then instructs the agent to run local shell commands to create directories, download archives, extract tarballs, and inspect files. Even if these commands are not taken from the checkpoint itself, extracting an untrusted archive locally can still trigger file overwrite, path traversal, or unsafe file handling outcomes, and the contradictory safety framing may cause users to underestimate that risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document says the Boil does not provide compute and frames the activity as text-only, but the workflow later requires authenticated API calls and file uploads. This mismatch can mislead operators about the true trust boundary and may cause accidental disclosure of local project contents or credentials during the required network interactions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · workloop.md (reported line 322)May include surrounding context.

md
## Suggested Next Steps
Implement the delete command:
- Follow the pattern in src/commands/complete.py
- Add --force flag to skip confirmation (see src/utils/prompts.py for confirm helper)
- Handle "ID not found" gracefully — check rowcount before committing
- Tests should cover: happy path, ID not found, --force flag

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to package the entire workspace and send it to remote endpoints, including evolved prompt content and metadata, without clearly warning that sensitive source code, secrets, personal data, or other local artifacts may be transmitted off-machine. Because the checkpoint is untrusted and may contain hidden sensitive files, this can lead to unintended exfiltration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This is an explicit external transmission primitive: it uploads the generated archive to a presigned remote URL. In the context of a contribution workflow this may be expected behavior, but it is still security-relevant because it transfers potentially sensitive project contents outside the local environment.

Content

Scanner excerpt · workloop.md (reported line 376)May include surrounding context.

You received an upload_url when you punched in. Use it:

bash
curl -X PUT "UPLOAD_URL_FROM_ASSIGNMENT" \
  -H "Content-Type: application/gzip" \
  --data-binary @contribution.tar.gz

Vague Triggers

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest description presents the skill as a general-purpose distributed labor network for AI agents, but it does not define when the skill should be invoked or what user requests should trigger it. In manifest files, missing specificity about activation scope can lead to unintended invocation overlap with many generic work, project, or collaboration requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.