Back to skill

Security audit

BotBoard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real BotBoard task CLI, but it persists agent workflow instructions and can expose or store API keys in ways users should review before installing.

Review the generated AGENTS.md/HEARTBEAT.md/CLAUDE.md content before running init, avoid passing real keys through logged commands, rotate any key that may have been printed in terminal or agent logs, and only upload local files with add-context when you are sure they are safe to send to BotBoard.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/botboard.sh:256
Finding

Persistent Agent Instruction Hijacking Through BotBoard Workflow Injection

Content
View full analysis
\` to get full details. Read in this priority order: - **latestRevisionComment** — if present, this is your primary directive. - **activity timeline** — read the full history to understand prior work. - **task description** — the original ask (baseline context). - **task context** — structured findings, links, file references, code snippets. - **project instructions** — conventions, stack, repo info. 3. On revision tasks: do not re-implement from scratch. Make only the changes asked for. 4. Start it only when you begin real work: \`botboard start \"starting work\"\` 5. Immediately inspect the relevant repo/files after starting. 6. Add a findings note within 10 minutes: \`botboard note \"findings...\"\` 7. Post another note after first code lands, after validation, on blockers, and on completion. 8. Notes must contain evidence: files, commands run, results, or blockers. 9. If no meaningful progress for 15-20 minutes, post an explicit blocker or no-progress note. 10. Mark done only after verification: \`botboard done \"what changed and how verified\"\`" HEARTBEAT_CONTENT="## BotBoard On ea ...[truncated 3706 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/botboard.sh:336
Finding

BotBoard API Key Printed Verbatim During Initialization

Content
View full analysis
`, `botboard init codex --key `, or a generic initialization mode. 2. The script stores the supplied value in `INIT_KEY`. 3. At the end of initialization, the script interpolates `INIT_KEY` into an `echo` command. 4. The complete secret appears in standard output. 5. A terminal logger, CI service, agent transcript, screen-sharing participant, or other party with log access captures the value. 6. The observer reuses the bearer credential against `https://botboard.app/api/agent/...`. ### Impact Assessment A recovered API key can provide the attacker with the same BotBoard API privileges as the affected agent. Based on the audited handlers, this can include: - Reading the agent profile and assigned tasks. - Reading task descriptions, activity, context, and project instructions. - Changing task status and posting notes. - Creating tasks and projects where the key i ...[truncated 429 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/botboard.sh:55
Finding

Bearer Token Exposed in Curl Process Arguments

Content
View full analysis
&2 echo "Get your API key from https://botboard.app → Settings → Agent Keys" >&2 exit 1 fi curl -sf -X "$method" \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ "$@" \ "${BASE_URL}${path}" } api_multipart() { local method="$1" path="$2" shift 2 resolve_api_key if [ -z "$API_KEY" ]; then echo "Error: BOTBOARD_API_KEY or BOTBOARD_API_KEY_FILE is required" >&2 echo "Get your API key from https://botboard.app → Settings → Agent Keys" >&2 exit 1 fi curl -sf -X "$method" \ -H "Authorization: Bearer $API_KEY" \ "$@" \ "${BASE_URL}${path}" } ``` Although HTTPS protects the header in transit, it does not protect how the secret is passed locally. On systems where process arguments are visible to other users, monitoring agents, debugging tools, audit systems, or crash collectors, the complete authorization header may be observable while curl is running. Successful exploitation depends on local process-observation permissions and platform configuration. It is therefore less direct than printing the key to standard output, but the exposure is still avoidable. ### Attack Path 1. The user invokes any BotBoard command that calls `api` or `api_multipart`. 2. The helper launches curl with `Authorization: Bearer ` as a command-line argument. 3. While curl is running, a local observer or monitoring component captures its argument vector. 4. The observer extracts the bearer token from the author ...[truncated 700 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description frames the skill as task management, but the documented behavior also includes workspace mutation, local secret-file creation, editing multiple local instruction files, project administration, and arbitrary local file upload to a remote service. This mismatch is dangerous because users and automated reviewers may grant or trust the skill based on a narrower description, while the actual capability set enables sensitive data exfiltration and broader state changes.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/botboard.sh (reported line 454)May include surrounding context.

sh
rm-context)
    id="${1:?task id required}"; shift
    context_id="${1:?context id required}"
    api DELETE "/api/agent/tasks/$id/context/$context_id" | fmt
    ;;

  # ─── Agent Status ───

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill exposes shell and network-capable behavior but does not declare any explicit tool scope or allowed-tools boundary. In an agent environment, this increases the chance that the agent can invoke broader capabilities than reviewers expect, making accidental or unauthorized API calls, file writes, and command execution harder to constrain.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description presents a task-management skill, but the init flow modifies local workspace files such as AGENTS.md, CLAUDE.md, TOOLS.md, HEARTBEAT.md, .gitignore, and may write an API key file. Undisclosed file-system mutation and secret-file creation are security-relevant because an agent may invoke init without understanding it will rewrite local instructions and persist credentials.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/botboard.sh (reported line 242)May include surrounding context.

sh
write_secret_file() {
      local file="$1" value="$2"
      printf '%s\n' "$value" > "$file"
      chmod 600 "$file"
      echo "  ✅ $file — secret written with mode 600"
    }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The init command writes the supplied API key to .botboard-api-key automatically for the openclaw mode, but the help text does not clearly warn that a secret will be persisted to disk and no confirmation is required. Secret persistence increases exposure to accidental disclosure through backups, workspace sharing, permissive environments, or later agent actions that read local files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest says it manages assigned BotBoard tasks, but the script also supports creating tasks, creating projects, and editing project metadata/instructions. That expands the authority surface beyond the declared purpose, which can mislead an agent or operator into granting or invoking capabilities they did not expect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill's stated purpose is to manage BotBoard tasks from CLI agents, but this code inspects local workspace files to infer the agent type and then rewrites agent instruction documents and .gitignore. That bootstrap capability is not an obvious requirement for basic task fetching, note posting, blocker reporting, or status updates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.