Back to skill

Security audit

WOLP LAN Power Control

Security checks for vulnerabilities and agentic risk

Overview

This skill's basic LAN wake/shutdown behavior is disclosed, but it also directs installation of a persistent third-party service with default web credentials and unverified privileged packages.

Review carefully before installing. The packet-sending script is understandable, but do not install the WOL-plus client service unless you trust the release source, verify downloaded artifacts yourself, and change the default web password before exposing the service on your LAN. Expect the skill to store MAC addresses, IP addresses, and recent action timestamps in its device inventory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:36
Finding

Unpinned and Unverified Third-Party Dependencies and Privileged Release Packages

Content
View full analysis
:2025` - username: `admin` - password: `admin123` Agent standard install procedure: 1. Confirm the minimum missing inputs only: - target OS: Windows, Debian/Ubuntu, or RPM-based Linux - target architecture when relevant: `amd64` or `arm64`/`aarch64` - whether the agent can install directly on the target machine or must only provide user instructions - target machine IP if the user wants Web UI verification 2. Choose the install source: - prefer a matching package from Releases - prefer the Debian package when the agent can reach a Debian/Ubuntu host over SSH - only build from this repo when a needed Debian package is unavailable from Releases 3. Install by platform: - Windows: - download `installer_windows_amd64_v.exe` from Releases - if the agent cannot control the Windows desktop session, tell the user to run the installer manually - after installation, verify the service is running and open `http://:2025` - Debian/Ubuntu: ```bash sudo dpkg -i wolp-client__amd64.deb sudo systemctl status wolp.service ``` - RPM Linux: ```bash sudo rpm -ivh wolp-client--1.x86_64.rpm sudo systemctl status w ...[truncated 3373 chars]
Remediation
View remediation
wolp-client__amd64.deb" | sha256sum --check - ``` 5. Prefer cryptographic publisher signatures in addition to checksums: - Verify Authenticode signatures for Windows installers. - Verify repository or package signatures for Debian and RPM packages. - Document the expected publisher identity and signing-key fingerprint. 6. Pin GitHub downloads to a specific release version and immutable asset digest. Do not use floating “latest” URLs. 7. Separate download and verification from privileged installation. Do not invoke `sudo`, administrator elevation, or service installation unless artifact verification has succeeded. 8. Execute third-party components with the least privileges required. Harden the installed service with platform controls such as a dedicated service account, restricted filesystem access, and systemd sandboxing where supported. 9. Record the reviewed dependency versions, release URLs, checksums, signatures, and verification date in the Skill documentation so future changes can be detected. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents persistent reads and writes to assets/devices.json but does not declare any permissions or allowed-tools scope. That mismatch weakens security review and policy enforcement because an agent may perform filesystem actions that are not explicitly surfaced to users or runtime controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill exposes a network-accessible Web UI with default credentials admin / admin123, and the warning to change them appears only later in the document. Default credentials on a service bound to a LAN host are a common takeover path, especially if users follow install steps without hardening first.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
- after installation, verify the service is running and open `http://<windows-ip>:2025`
   - Debian/Ubuntu:
     ```bash
     sudo dpkg -i wolp-client_<version>_amd64.deb
     sudo systemctl status wolp.service
     ```
   - RPM Linux:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
- after installation, verify the service is running and open `http://<windows-ip>:2025`
   - Debian/Ubuntu:
     ```bash
     sudo dpkg -i wolp-client_<version>_amd64.deb
     sudo systemctl status wolp.service
     ```
   - RPM Linux:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
- after installation, verify the service is running and open `http://<windows-ip>:2025`
   - Debian/Ubuntu:
     ```bash
     sudo dpkg -i wolp-client_<version>_amd64.deb
     sudo systemctl status wolp.service
     ```
   - RPM Linux:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
- after installation, verify the service is running and open `http://<windows-ip>:2025`
   - Debian/Ubuntu:
     ```bash
     sudo dpkg -i wolp-client_<version>_amd64.deb
     sudo systemctl status wolp.service
     ```
   - RPM Linux:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
- after installation, verify the service is running and open `http://<windows-ip>:2025`
   - Debian/Ubuntu:
     ```bash
     sudo dpkg -i wolp-client_<version>_amd64.deb
     sudo systemctl status wolp.service
     ```
   - RPM Linux:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

This instruction tells the agent to build a package from the repository and then install it as root, creating a supply-chain and privilege-boundary risk. If the repository contents or build scripts are malicious or compromised, the resulting package would execute or install attacker-controlled code with elevated privileges.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

  1. Debian build fallback from this repo:
    bash
    bash scripts/build-deb.sh amd64 0.0.0-dev
    sudo dpkg -i release/client/wolp-client_0.0.0-dev_amd64.deb
    sudo systemctl status wolp.service
    
  2. Verify the client after install:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script does more than the skill description advertises: it creates, modifies, and persists a local device inventory, including MAC addresses, IPs, action history, and timestamps. That hidden state expansion increases the skill’s effective privileges and data-handling footprint, which is dangerous because users invoking a packet-sending skill may not expect filesystem writes, inventory growth, or retention of network asset metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest presents the skill as a mechanism to power devices on or off by sending magic packets. The separate list action enumerates and returns the resolved contents of the local device inventory, which is an information-disclosure capability beyond the core wake/shutdown function described.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.