Back to skill

Security audit

OpenClaw Marketing Skills

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent marketing skill pack, but it includes under-scoped guidance for high-impact account/tool actions and optional commands that execute mutable third-party code.

Review this skill before installing in environments with ad accounts, CRM/billing access, API keys, or private customer data. Avoid running the optional git clone/make or npx examples unless you pin versions, inspect the code, and use a disposable sandbox; require explicit confirmation before any campaign, CRM, billing, email, crawler-access, or voice-cloning action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
skills/ad-creative/references/generative-tools.md:416
Finding

Execution of Mutable Third-Party Repository Code Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skills/ad-creative/references/generative-tools.md:562
Finding

Unpinned npm Package Retrieval and Execution Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
Findings (84)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · skills/ad-creative/SKILL.md (reported line 319)May include surrounding context.

md
## Common Mistakes

- **Writing headlines that only work together** — RSA headlines get combined randomly
- **Ignoring character limits** — Platforms truncate without warning
- **All variations sound the same** — Vary angles, not just word choice
- **No CTA headlines** — RSAs need action-oriented headlines to drive clicks; include at least 2-3
- **Generic descriptions** — "Learn more about our solution" wastes the slot

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · skills/cold-email/references/frameworks.md (reported line 80)May include surrounding context.

md
**Structure:** Trigger/Pain → Solution hint → Binary CTA. 1–3 sentences, no intro.
**Best for:** High-velocity SDR teams. Mobile-optimized. Deliberately polarizing.

Spend max 1 minute on personalization. Use industry/persona-level signals. For top-tier prospects, quote their own words from interviews — they almost always respond.

## Vanilla Ice Cream (Lavender)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/content-strategy/references/headless-cms.md (reported line 93)May include surrounding context.

md
All major headless CMS platforms support draft previews:

- **Sanity**: Real-time preview with `useLiveQuery` or Presentation tool
- **Contentful**: Preview API (`preview.contentful.com`) with separate access token
- **Strapi**: Draft & Publish system with `status=draft` query parameter (v5; replaces v4's `publicationState`)

Set up a preview route in your frontend (e.g., `/api/preview`) that authenticates and renders draft content.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · skills/paywall-upgrade-cro/references/experiments.md (reported line 157)May include surrounding context.

md
- Cool-down period after dismiss (hours vs. days)
- Escalating urgency over time vs. consistent messaging
- Once per feature vs. consolidated prompts
- Re-show rules after major engagement

### Dismiss Behavior
- "Maybe later" vs. "No thanks" vs. "Remind me tomorrow"

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · skills/schema-markup/references/schema-examples.md (reported line 391)May include surrounding context.

md
<Head>
        <script
          type="application/ld+json"
          dangerouslySetInnerHTML={{ __html: JSON.stringify(schema) }}
        />
      </Head>
      {/* Page content */}

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · README.md (reported line 9)May include surrounding context.

md
<p align="center">
  <a href="https://myclaw.ai"><b>MyClaw.ai</b></a> is the #1 OpenClaw host — the best way to run OpenClaw.<br>
  Get your own AI agent with a full server, complete code control, and unlimited tool access.<br>
  No setup. No DevOps. Just your agent, ready to work.
</p>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The section says users can "use any skill naturally" and then lists example utterances, but it does not define whether these are the only triggers, preferred examples, or merely illustrative mappings. Without clear boundaries or exclusion conditions, multiple skills may plausibly match common requests like writing copy or auditing SEO.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README presents "Help me with Google Ads" as a natural invocation for the paid-ads skill. This phrasing is broad, conversational language that could easily appear in ordinary chat, increasing the risk of unintended skill activation if trigger matching is based on natural-language examples.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents very broad natural-language phrases like '优化这个落地页的转化率' and '帮我投Google广告' as triggers for skill use. In agentic environments, generic requests can unintentionally match and invoke this skill during normal conversation, causing capability overreach, unexpected file access to shared context files, or execution of marketing-oriented workflows when the user did not explicitly request the installed skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says 'Just ask naturally' and provides examples like 'Help me with Google Ads,' which overlap with common user phrasing and do not define clear trigger boundaries. This can cause unintended invocation of the marketing skills when a user is speaking generally rather than explicitly requesting a specific skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list is excessively broad and includes generic phrases like "hypothesis," "which version is better," and "test this change," which can cause this skill to activate during ordinary product or strategy discussions rather than only explicit experimentation requests. In an agentic system, over-triggering can misroute user intent, override more appropriate skills, and lead to unnecessary file reads or follow-up actions under the wrong workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description contains many broad trigger phrases such as generic requests for ads or variations, which can cause the orchestration layer to invoke this skill in situations where a more specific or safer skill would be a better match. This is not directly exploitative, but it can lead to misrouting, over-collection of context, or unintended tool/use flows in multi-skill environments.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skills/ad-creative/references/generative-tools.md (reported line 50)May include surrounding context.

API example:

bash
# Using the Gemini API for image generation
curl -X POST "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash-image:generateContent" \
  -H "Content-Type: application/json" \
  -H "x-goog-api-key: $GEMINI_API_KEY" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends brand voice cloning workflows without warning that voice cloning requires explicit consent and can enable impersonation, fraud, or misuse of sensitive audio. In a marketing skill, this omission is more dangerous because it normalizes production use of cloned voices for ads at scale, increasing the chance of unauthorized cloning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The ElevenLabs section explicitly promotes cloning a spokesperson's voice and multilingual reuse but omits any consent, disclosure, or authorized-use safeguards. Because the content is instructional and operational, users may interpret cloning as a standard approved marketing tactic even when they lack rights to the voice or recording.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skills/ad-creative/references/generative-tools.md (reported line 322)May include surrounding context.

API example:

bash
curl -X POST "https://api.elevenlabs.io/v1/text-to-speech/{voice_id}" \
  -H "xi-api-key: $ELEVENLABS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skills/ad-creative/references/generative-tools.md (reported line 322)May include surrounding context.

API example:

bash
curl -X POST "https://api.elevenlabs.io/v1/text-to-speech/{voice_id}" \
  -H "xi-api-key: $ELEVENLABS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The open-source Voicebox section lowers cost and friction for local voice cloning while providing install and API usage details, but it lacks any warning about consent, rights-sensitive source audio, or impersonation abuse. That combination materially increases misuse risk because it enables private cloning outside hosted-provider safeguards.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says to use the skill 'whenever someone wants their content to be cited or surfaced by AI assistants and AI search engines,' which is a broad activation condition beyond the specific keyword list. This can overlap with many ordinary marketing or content-strategy requests and does not provide clear exclusion boundaries beyond two adjacent skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly advises users to allow multiple AI crawlers and states that options to separate citation from training are limited, but it does not warn about the privacy, confidentiality, licensing, and data-governance consequences of making content broadly accessible to those bots. In a marketing/SEO skill, users may apply this guidance directly to production sites and unintentionally expose sensitive, proprietary, customer, or regulated content to indexing and possible model-training pipelines.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is very broad and includes generic phrases like 'how do I measure this' or 'how to know if something is working,' which can cause the skill to activate outside narrow analytics-tracking tasks. This is not an exploit in itself, but it can misroute agent behavior, leading to irrelevant guidance, increased context consumption, or accidental use in situations where more appropriate skills should handle the request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This reference explicitly recommends tracking persistent identifiers and rich context such as user_id, account_id, session_id, referrer, campaign data, and transaction details, but provides no privacy, minimization, consent, retention, or redaction guidance. In a marketing analytics skill, that omission can lead downstream users to implement broad user tracking in ways that violate internal policy or privacy regulations, and may also result in accidental collection of sensitive data in fields like referrer or error_message.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.