Back to skill

Security audit

Xtoys.app Webhook Controller

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for controlling xtoys.app devices, but its packaged stop command can report success without actually sending a stop request, which is a safety-critical concern for physical device control.

Review carefully before installing. The main risk is not hidden exfiltration; it is that stop/pause may falsely succeed and fail to stop an active physical device when invoked through the packaged OpenClaw tools. Use an independent stop method in xtoys.app or the device itself, do not rely on this skill as a safeword mechanism until fixed, and prefer pinned dependencies before deployment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/xtoys_control.py:256
Finding

Stop Tool Silently Succeeds Without Sending a Stop Command

Content
View full analysis
bool: """Stop the body part currently being stimulated.""" if self._current_part: logger.info(f"Stopping current part: {self._current_part}") result = self._send_raw_command(self._current_part, 0) if result: self._current_part = None return result else: logger.info("There is currently no stimulated body part") return True def stop_all(self) -> bool: """Stop the body part currently being stimulated (legacy compatibility).""" return self.stop() ``` The command-line handler calls this method and treats its result as success: ```python elif args.stop: if not controller.stop_all(): sys.exit(1) ``` The packaged tool launches a new Python process for every stop invocation: ```json { "name": "xtoys_stop", "description": "Stop current xtoys.app stimulation", "parameters": { "type": "object", "properties": {} }, "command": "python3 {{SKILL_DIR}}/scripts/xtoys_control.py --stop" } ``` ### Technical Analysis The implementation assumes that `_current_part` remains populated between a control command and a later stop command. That assumption is invalid for the declared tool interface because every tool invocation starts a separate Python process. After a control process exits, its `_current_part` value is lost. A subsequent `x ...[truncated 2230 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Third-Party Dependencies Are Not Reproducibly Pinned

Content
View full analysis
=2.25.0 urllib3>=1.26.0 ``` The documentation also recommends installing the packages without version or integrity constraints: ```bash pip install requests urllib3 ``` ### Technical Analysis Both requirements specify only a minimum version. There is no upper bound, reviewed lock file, or package hash. As a result, installations performed at different times may resolve to different dependency versions, including future releases that were not reviewed with this Skill. The package names are legitimate and common, and the audit found no evidence of dependency confusion, typosquatting, or a currently malicious package. The risk arises from mutable dependency resolution and absent integrity verification rather than from a confirmed malicious dependency. Because Python packages execute code during installation and import, compromise of the configured package index, a malicious future release, or an incompatible dependency change could introduce code execution or unexpected behavior into the Skill environment. ### Attack Path A conditional supply-chain exploitation path is: 1. A user follows the documented installation instructions or installs from `requirements.txt`. 2. The package resolver selects the newest release satisfying the minimum-version constraint. 3. A future compromised, malicious, or incompatible release is available from the configured package source. 4. The unpinned requirement accepts that release without verifying an expected artifact hash. 5. Package installation or later import executes the affected dependency code with the privileges of the user running the installation or Skill. This audit did not establish that such a compromised release currently exists; the path describes the exposure cre ...[truncated 759 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all operational instructions, warnings, and publishing steps only in Chinese. Under the language/locale policy rule, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises code-driven capabilities that can access environment variables, read files, and make network requests, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: a host agent may grant broader capabilities than users expect, and sensitive data such as the webhook ID could be accessed or transmitted without clear restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

User-facing descriptions, help text, errors, and logs are written entirely in Chinese, and the script provides no language selection or opt-in mechanism. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale limitation is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code sends command data to an external webhook service, which is a safety-relevant network operation. Although the file documents functionality and logs command execution, it does not include a clear user-facing warning or confirmation that commands and the webhook identifier will be sent to a remote third-party endpoint.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specifier requests>=2.25.0 is unpinned, so installs may resolve to different versions over time and across environments. This weakens reproducibility and can unintentionally introduce vulnerable or breaking releases, especially in a skill that performs remote device control over HTTP.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.25.0
urllib3>=1.26.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin a specific version, there is no way to verify that deployments will avoid affected releases. In a webhook-driven remote-control skill, HTTP client flaws can matter more because they may expose credentials, mishandle redirects, or weaken request validation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specifier urllib3>=1.26.0 is also unpinned, which allows dependency resolution to drift and makes it unclear which code will actually run in production. Because this library handles HTTP transport, unexpected vulnerable versions could affect network security behavior.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.25.0
urllib3>=1.26.0

Unverifiable Dependency: urllib3 has 16 known advisory(ies) (CVE-2025-66471 (urllib3 streaming API improperly handles highly compressed data); CVE-2024-37891 (urllib3's Proxy-Authorization request header isn't stripped during cross-origin ); CVE-2026-21441 (Decompression-bomb safeguards bypassed when following HTTP redirects (streaming ) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

urllib3 has known advisories, but the current requirement does not specify an exact version, making the installed release unverifiable from this manifest alone. Since urllib3 underpins HTTP communication, unresolved advisory exposure could affect request handling or resilience against malicious network inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.