Back to skill

Security audit

Connector

Security checks for vulnerabilities and agentic risk

Overview

This deprecated connector mostly matches its stated purpose, but it handles tokens and telemetry and can send them to an arbitrary or plaintext URL, so users should review it carefully before installing.

Prefer the replacement @launchthatbot/connect-openclaw-plugin for new installs. If you must use this legacy connector, set the base URL only to the intended LaunchThatBot HTTPS endpoint, avoid plaintext HTTP except isolated localhost development, do not pass tokens on the command line, use protected environment injection or a secure secret file, restrict egress to the expected domain, and rotate the ingest token if it may have appeared in shell history, logs, recordings, or terminal output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/connector.ts:48
Finding

Bearer Token and Operational Telemetry Can Be Sent to an Arbitrary or Plaintext Endpoint

Content
View full analysis
{ const url = `${this.config.launchThatBaseUrl.replace(/\/$/, "")}/api/openclaw/instances/${this.config.instanceId}/heartbeat`; const signedHeaders = this.createSignedHeaders(""); await this.retry(async () => { const response = await fetch(url, { method: "POST", headers: { authorization: `Bearer ${this.config.ingestToken}`, ...signedHeaders, }, }); if (!response.ok) { throw new Error(`Heartbeat failed (${response.status})`); } }); } ``` ```ts private async flushQueue(): Promise { if (this.isFlushing || this.queue.length === 0) return; this.isFlushing = true; try { while (this.queue.length > 0) { const batch = this.queue.slice(0, 100); const url = `${this.config.launchThatBaseUrl.replace(/\/$/, "")}/api/openclaw/ingest/events`; const requestBody = JSON.stringify({ instanceId: this.config.instanceId, events: batch, }); const signedHeaders = this.createSignedHeaders(requestBody); await this.retry(async () => { const response = await fetch(url, { method: "POST", headers: { "content-type": "application/json", authorization: `Bearer ${this.config.ingestToken}`, ...[truncated 3173 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/cli.ts:15
Finding

Command-Line and Echoed Prompt Inputs Can Expose Authentication Secrets

Content
View full analysis
=> { if (params.directValue?.trim()) return params.directValue.trim(); if (params.envVar?.trim()) { const envValue = process.env[params.envVar]; if (envValue?.trim()) return envValue.trim(); } if (params.filePath?.trim()) { const value = await readFile(params.filePath, "utf-8"); if (value.trim()) return value.trim(); } if (params.promptLabel && process.stdin.isTTY) { const rl = createInterface({ input: stdin, output: stdout }); try { const promptValue = await rl.question(params.promptLabel); if (promptValue.trim()) return promptValue.trim(); } finally { rl.close(); } } return undefined; }; ``` ```ts const ingestToken = await resolveSecret({ directValue: readArg("ingest-token"), envVar: readArg("ingest-token-env") ?? "LAUNCHTHAT_INGEST_TOKEN", filePath: readArg("ingest-token-file"), promptLabel: "Ingest token: ", }); const signingSecret = await resolveSecret({ directValue: readArg("signing-secret"), envVar: readArg("signing-secret-env") ?? "LAUNCHTHAT_SIGNING_SECRET", filePath: readArg("signing-secret-file"), }); ``` ### Technical Analysis The CLI supports passing an ingest token and signing secret directly as command-line arguments. Command-line values can be retained in shell history, captured by process-monitoring and observability systems, included in diagnostic output, or exposed to other local users depending on operating-system process visibility. The fallback ingest-token prompt uses the standard `readline` question mechanism. It does not disable terminal echo, so every character of the token is displayed while the operator enters it. ...[truncated 1842 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented behavior includes outbound API communication, heartbeat telemetry, event ingestion/transmission, local queue persistence, bearer token use, and optional HMAC signing, none of which are reflected in the declared skill scope. In context, this is more dangerous because the skill handles agent, room, and task event data plus authentication material, so understated capabilities can enable unintended data exfiltration, over-privileged deployment, or policy bypass.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior includes outbound API communication, heartbeat telemetry, event ingestion/transmission, local queue persistence, bearer token use, and optional HMAC signing, none of which are reflected in the declared skill scope. In context, this is more dangerous because the skill handles agent, room, and task event data plus authentication material, so understated capabilities can enable unintended data exfiltration, over-privileged deployment, or policy bypass.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
96% confidence
Finding

The CLI prompts for an ingest token using readline.question with normal terminal echo enabled, so the secret is visible on screen and may be captured by shoulder-surfing, terminal recording, or session logging. In a connector skill context that handles authentication material, interactive secret entry should be treated as sensitive input and masked.

Content

Scanner excerpt · src/cli.ts (reported line 34)May include surrounding context.

ts
const rl = createInterface({ input: stdin, output: stdout });
    try {
      const promptValue = await rl.question(params.promptLabel);
      if (promptValue.trim()) return promptValue.trim();
    } finally {
      rl.close();
    }

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises operational capabilities including outbound network access and use of secrets from environment variables, but it does not declare any explicit tool scope or permissions. This creates a trust and review gap: users or orchestrators may approve or run the skill under the assumption it is passive documentation, while it actually describes behavior that handles credentials and communicates externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The resolveSecret helper accesses secrets from environment variables, local files, and terminal input, which are safety-relevant operations involving credentials. While the code prompts for the ingest token value, it does not disclose that the CLI will read secrets from environment variables or files, and there are no comments or broader user-facing warnings in this file about that credential handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends heartbeat data and queued event payloads to remote API endpoints using fetch, including instance identifiers, event details, and bearer-token-authenticated requests. There is no confirmation prompt, user-facing log/print, or explanatory comment/docstring in this file disclosing that runtime data will be transmitted off-host.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: zod has 1 known advisory(ies) (CVE-2023-4316 (Zod denial of service vulnerability)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest declares zod using a non-specific catalog: reference rather than a pinned version, so consumers cannot verify whether the resolved version includes the known Zod DoS advisory (CVE-2023-4316). In a connector skill, schema validation libraries may process untrusted input, so an affected version could allow denial-of-service through maliciously crafted data if the vulnerable release is resolved.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.