Back to skill

Security audit

BestYou Coach Dashboards

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-built for BestYou health dashboards, but it asks users to install an unpinned global tool and store a live health-data API key in plaintext without enough safeguards.

Review before installing. Use a pinned, verified mcporter version if possible; avoid pasting the live API key into chat; store any config file with restrictive permissions; revoke and rotate the BestYou key if exposed; and be aware that rendered widgets may contact Google Fonts and BestYou CDN. Treat workout and nutrition guidance as informational unless reviewed by an appropriate professional.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:23
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: INSTALL.md, lines 23-29
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Vulnerable Code

bash
### 2. Install mcporter

mcporter is the CLI that talks to MCP servers. It's a separate package, not bundled with OpenClaw.

npm install -g mcporter

The same unpinned installation instruction also appears in SKILL.md line 28 and references/setup.md line 11.

Technical Analysis

The installation command retrieves the latest version of mcporter from the npm registry without specifying an exact version or verifying package integrity. npm packages can run lifecycle scripts during installation, and global installation places package executables in a system-wide or user-wide command location.

Consequently, the reviewed skill is not tied to a specific, auditable dependency artifact. A future malicious or compromised release under the same package name could execute installation-time code or replace the expected mcporter behavior after this skill has been reviewed. The documentation also does not identify an expected publisher, package digest, lockfile, or provenance-verification procedure.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or its release pipeline.
  2. The attacker publishes a malicious version under the legitimate mcporter package name.
  3. A user or agent follows the documented npm install -g mcporter instruction.
  4. npm downloads the current compromised release rather than a version assessed with this skill.
  5. Malicious lifecycle code runs with the privileges of the account executing npm.
  6. The installed executable can subsequently access command arguments, the mcporter configuration, and the BestYou bearer credential when the documented commands are run.

Impact Assessment

Successful exploitation could execute arbitrary code with the operating-system p ...[truncated 410 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin mcporter to an explicitly reviewed version, for example npm install -g mcporter@X.Y.Z.
  • Record and verify the expected package integrity digest and publisher identity.
  • Prefer a project-local dependency with a lockfile over a global installation.
  • Use npm provenance or signature verification where supported.
  • Disable lifecycle scripts during installation when they are not required, such as with --ignore-scripts, after confirming compatibility.
  • Execute the dependency under a dedicated, unprivileged account with access only to the required configuration and network endpoint.
  • Document an upgrade-review process so dependency changes are audited before users install them.

T09 · Insecure Skill Coding Practices

Warning
Location
references/setup.md:17
Finding

Bearer API Key Is Collected and Stored in Plaintext Without File-Permission Hardening

Content
View full analysis

Vulnerability Details

File Location: references/setup.md, lines 17-43
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: Medium

Vulnerable Code

markdown
### 1. Get API Key

Tell the user:

> "Open BestYou on your iPhone. Go to More, then Connected Apps, then OpenClaw, then Generate Key. Paste the key here when you have it."

Key format: `by_mcp_live_...`

### 2. Create the mcporter config

Write the config file at `~/.openclaw/workspace/config/mcporter.json`:

```json
{
  "mcpServers": {
    "bestyou": {
      "baseUrl": "https://mcp.bestyou.ai/mcp",
      "headers": {
        "Authorization": "Bearer <paste-key-here>"
      }
    }
  },
  "imports": []
}

The API key MUST go in the Authorization header with the Bearer prefix. The BestYou MCP server authenticates via this header. Do not pass it as a query parameter or body field.

text

`INSTALL.md` lines 44-62 and `SKILL.md` lines 32-33 repeat the plaintext configuration approach.

### Technical Analysis

The setup flow instructs the user to paste a live bearer credential into the conversation and directs the agent to write that credential directly into a JSON file. No requirement is provided to avoid chat capture, redact the token from logs, set restrictive file permissions, validate ownership, or exclude the configuration from backups and synchronization.

A bearer token grants access based solely on possession. Unlike a password protected by an additional challenge, a copied token can be replayed directly against the configured MCP endpoint until it expires or is revoked. Storing it in a predictable plaintext path increases exposure to other local users, overly broad backup tools, diagnostic collectors, workspace synchronization, and malicious processes running as the same account.

Although the project declares `BESTYOU_API_KEY` as its primary environment variable in `SKILL.md` lines 1
...[truncated 1302 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not ask users to paste live API keys into the conversation.
  • Use an interactive secret prompt, operating-system credential store, or OpenClaw secret-management facility that prevents the value from entering transcripts and logs.
  • Use the declared BESTYOU_API_KEY secret environment mechanism rather than embedding the token directly in ordinary JSON.
  • If a credential file is unavoidable, create it with mode 0600, verify that it is owned by the OpenClaw user, and reject operation when permissions are broader.
  • Store secret-bearing configuration outside synchronized workspaces and exclude it from backups, support bundles, and version control.
  • Redact Authorization headers and values matching by_mcp_live_* from logs, errors, and command output.
  • Grant only the minimum scopes needed for requested operations and use short-lived credentials where supported.
  • Add explicit rotation and revocation instructions for suspected exposure.

other

Note
Location
assets/shared.css:2
Finding

Undisclosed Third-Party Font Request Contradicts the Declared Network Boundary

Content
View full analysis

Vulnerability Details

File Location: assets/shared.css, line 2
Vulnerability Type: External resource loading and privacy disclosure
Risk Level: Low

Vulnerable Code

css
/* BestYou Dark Glass Design System */
@import url('https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap');

The security documentation makes the following conflicting assertion in references/security.md line 20:

markdown
All API calls go through mcporter to a single endpoint: `https://mcp.bestyou.ai/mcp`. No other outbound network calls are made. The skill does not download or execute external code.

A duplicate Google Fonts import appears in assets/daily-briefing.html line 9, and assets/workout.html line 7 also loads the font stylesheet externally. The workout template additionally loads images from https://cdn.bestyou.ai at lines 170-343.

Technical Analysis

Rendering a template that imports Google Fonts causes the canvas or browser environment to contact fonts.googleapis.com and normally a related Google font-content host. This occurs independently of the documented BestYou MCP request. The request can disclose the viewer's IP address, user-agent characteristics, request timing, and potentially referrer information, depending on canvas/browser policy.

The issue is especially relevant because the templates display health and wellness information. Even if the response values are not placed directly into the font URL, request timing may reveal that a user opened a BestYou health widget. The external request also makes rendering behavior dependent on remotely controlled content outside the stated mcp.bestyou.ai network boundary.

This is not remote script execution: the observed resource is a stylesheet/font. The confirmed issue is an inaccurate network/privacy claim and an unnecessary third-party request.

Attack Path

  1. The agent populates and presents a widget conta ...[truncated 1023 chars]
Remediation
View remediation

Remediation Suggestions

  • Bundle the required Inter font files within the skill or use the existing system-font fallback without any external import.
  • Remove Google Fonts imports from assets/shared.css, assets/daily-briefing.html, and assets/workout.html.
  • If external resources remain necessary, disclose every contacted domain and the metadata exposed in references/security.md.
  • Apply a restrictive Content Security Policy, with default-src 'none' and narrowly scoped style-src, font-src, and img-src directives appropriate to the rendering platform.
  • Set a strict referrer policy such as no-referrer.
  • Prefer bundled workout images; otherwise explicitly document and allowlist cdn.bestyou.ai.
  • Add automated checks that reject new external URLs in HTML and CSS unless they are approved and documented.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/weekly-summary.html (reported line 133)May include surrounding context.

html
<div class="overall-label">Good effort!</div>
</div>

<!-- Activity -->
<div class="domain-section">
  <div class="domain-header-row">
    <div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/workout.html (reported line 162)May include surrounding context.

html
</div>
</div>

<!-- WARMUP -->
<div class="block">
  <div class="block-header">
    <h2><span class="badge badge-warmup">Warmup</span> Full Body Activation</h2>

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This creates persistent local storage of a live API credential in a predictable path under the user's home directory, increasing the exposure window beyond a single session. Because the token appears to grant access to sensitive health/account data, persistence makes theft via local compromise, backup leakage, shared-machine access, or accidental inclusion in support bundles more damaging.

Content

Scanner excerpt · INSTALL.md (reported line 44)May include surrounding context.

md
2. Tap **Generate Key**
3. Copy the key (it starts with `by_mcp_live_...`)

### 4. Create the mcporter config file

Create the file at `~/.openclaw/workspace/config/mcporter.json` with this exact content, replacing `YOUR_KEY_HERE` with the key from step 3:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to place a live bearer token in a plaintext local config file and emphasizes the exact authentication format, but provides no warning about protecting the file, least-privilege access, or rotation if exposed. If the workstation, backup set, logs, or dotfiles are accessed by another local user, malware, or accidentally committed/synced, the token could be reused to access the user's health data via the MCP server.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The install guide says 'just talk naturally' and gives examples like 'How am I doing?' and 'How was my week?', which are common conversational phrases not clearly scoped to this specific skill. There are no exclusion conditions or constraints explaining when these phrases should or should not invoke the skill, increasing the risk of accidental activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The setup instructions direct the user to place a sensitive API key into a local configuration file without any warning about credential sensitivity, storage permissions, or leakage risks. This increases the chance the bearer token is stored insecurely, committed to source control, exposed in backups, or shared during troubleshooting, which could permit unauthorized access to health-related account data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill instructs persistent storage of a bearer token in config/mcporter.json, which creates a reusable long-lived secret on disk. If the workstation, repository, logs, support bundles, or config directory are accessed by another user or process, the token could be reused to call BestYou APIs and access or manipulate personal health data.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
Setup summary:
1. User generates an API key in BestYou iOS (More → Connected Apps → OpenClaw)
2. Create `config/mcporter.json` with the key in the Authorization Bearer header (see `references/setup.md` for the exact JSON format)
3. Restart the OpenClaw gateway

## Calling Tools via mcporter

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The HTML presents personalized-sounding nutrition analysis and health guidance such as protein adequacy, micronutrient benefits, and dietary recommendations without any disclaimer that the content is informational only and not medical or dietetic advice. In a health-coaching skill, users may rely on this guidance for real dietary decisions, increasing the risk of harm for people with medical conditions, allergies, eating disorders, or individualized nutrition needs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file presents specific weighted, intermediate exercise prescriptions including reps, loads, and effort targets without any warning about injury risk, contraindications, or consulting a professional. In a health/fitness coaching context, omission of basic safety guidance can increase the chance of user harm, especially for users with medical conditions, poor form, or mismatched training level.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup flow instructs the user to paste a live API key and store it in a persistent local JSON config file, but it does not warn that the credential is sensitive, long-lived, or accessible to other local processes/users depending on filesystem permissions. This increases the chance of accidental disclosure through backups, screen sharing, shell history, repo inclusion, or weak workstation security.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The instructions create session-like persistent authentication by placing a bearer token in ~/.openclaw/workspace/config/mcporter.json, where it can remain valid across sessions. Persistent bearer tokens broaden the window for misuse if the host is compromised or the file is accessed by another user, process, backup system, or malware.

Content

Scanner excerpt · references/setup.md (reported line 25)May include surrounding context.

md
Key format: `by_mcp_live_...`

### 2. Create the mcporter config

Write the config file at `~/.openclaw/workspace/config/mcporter.json`:

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The conversation patterns list example user utterances such as "What's my day look like?", "How am I doing?", and "Give me a workout," which are broad everyday phrases and are not paired with exclusion conditions or scope constraints. In a manifest/markdown skill description, this can make activation boundaries unclear and increase the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document declares lang="en", which imposes a specific language/locale in natural-language-facing content. Under the policy, locale constraints should either offer user choice or be clearly justified as region-specific, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document declares lang="en", which hard-codes English as the content language. Under the policy, locale constraints should either offer user choice or be clearly justified as region-specific; no such opt-in or justification appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document declares lang="en", which sets a specific language/locale for the skill output. Under the stated policy, forcing a language without user opt-in or clear justification is a natural-language policy concern, and this file does not indicate any user choice or region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document sets lang="en", which hard-codes English as the page language. Under the stated policy, forcing a specific language without user opt-in or documented justification is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stylesheet imports Google Fonts from a third-party domain, which causes clients rendering the dashboard to make an external network request. Even though this is common for styling, it can leak metadata such as user IP address, user agent, timing, and usage patterns to Google, and it introduces a dependency on external availability for rendering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document sets lang="en", which imposes a specific language/locale choice in natural-language content. The file does not indicate that English is optional, user-selected, or required for a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The page imports a Google Fonts stylesheet, which causes the client to contact a third-party service when rendering the workout dashboard. In a health-related skill, that creates an unnecessary external dependency and can leak user metadata such as IP address, user agent, timing, and referrer context to a third party.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.