Back to skill

Security audit

Hope Client

Security checks for vulnerabilities and agentic risk

Overview

The skill is an API helper, but it ships live-looking credentials and password-based SSH commands that can access sensitive data and modify server state without clear safeguards.

Review this carefully before installing. Treat the exposed API key and SSH password as compromised, rotate them if they are real, and do not use the skill until it requires explicit secrets, removes password-based SSH or tightly scopes it, validates inputs, redacts sensitive fields, and adds confirmation for write operations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api_client.sh:18
Finding

Remote Command Injection Through Unsafe SSH Command Construction

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api_client.sh:8
Finding

Hardcoded API and SSH Credentials

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/response-format.md:55
Finding

Overbroad Raw Access to Sensitive API Data and State-Changing Operations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a simple API client, but its documented behavior includes password-based SSH access, hardcoded credentials, and state-changing operations against an internal service. This mismatch is dangerous because users and policy systems may permit it under a lower-risk assumption while it actually enables authenticated remote access and modification of server state.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill exposes a path to local secret storage and includes a concrete secret value in the example, indicating credential material is embedded in documentation. This is a direct credential-access risk because it teaches where secrets live and appears to disclose an actual API key that can be used against the service.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

OpenClaw 自动加载 ~/.openclaw/.env 文件中的环境变量:

bash
# ~/.openclaw/.env
HOPE_API_KEY=hope-openclaw-apikey-2026-0411
HOPE_HOST=hope05
HOPE_PORT=8088

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation claims configuration is sourced from environment variables, but the quick-call implementation bypasses them with hardcoded values. This is dangerous because it defeats secret-management expectations, encourages credential sprawl, and can silently direct traffic to a fixed internal host regardless of user configuration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The helper function hardcodes an SSH password, host, username, and API key, then executes a remote curl command. This directly enables credential reuse and unauthorized access to an internal system by anyone who can read or copy the skill, turning documentation into an operational access mechanism.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill demonstrates shell-based capabilities through curl/ssh/sshpass examples and helper functions, yet it declares no tool scope or allowed-tools restrictions. This increases the chance that an agent can invoke broader shell behavior than users expect, especially given the presence of authenticated network and remote-access commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The markdown publishes a concrete API key value in a sample .env block, which is effectively credential disclosure if the value is real or reused. Exposed secrets can be copied and used to authenticate to the service, especially in an internal environment with limited additional controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The examples show secrets being carried in HTTP headers and SSH commands to reach an internal service, but they provide no warning about protecting credentials, shell history exposure, or internal-network sensitivity. In this context, the omission materially increases the chance of unsafe handling of live secrets and broadening access to internal infrastructure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs use of sshpass and SSH to run remote commands on an internal host, which exceeds the stated role of an API client. Embedding remote-execution guidance normalizes privileged lateral access and can expose internal services and secrets if the skill is adopted as written.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is presented as common query examples, but it includes a bulk state-changing command that marks items as cleaned. In an agent skill, users or downstream automation may treat examples as safe read-only operations, so undocumented write actions increase the chance of accidental destructive or workflow-altering use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The bulk operation example performs state changes without any warning about operational impact, scope, or reversibility. In the context of an API client skill, such examples can be copied directly into automation or interactive sessions, causing unintended bulk data/status modification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script reads and uses an SSH password, and even provides a default password value, which is a hardcoded credential and an unnecessary privilege for a nominal API client. This can lead to credential disclosure, unauthorized host access, and lateral movement if the script or environment is exposed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script is presented as an API client, but it actually performs remote command execution over SSH and runs curl on the remote host. This expands its privilege and attack surface beyond a normal HTTP client, enabling access to localhost-only services on the remote machine and creating command-injection risk if endpoint, params, method, or data are attacker-controlled.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The script transmits an API key to a remote host and forwards requests to a localhost-bound service through SSH, meaning sensitive data and privileged API access are being relayed off-process and potentially off-machine. In this skill context, that is more dangerous because the declared purpose is a simple API client, yet it covertly brokers access to an internal service using additional credentials and transport layers.

Content

Scanner excerpt · scripts/api_client.sh (reported line 25)May include surrounding context.

sh
if [[ "$method" == "GET" ]]; then
        sshpass -p "$SSH_PASS" ssh "$HOPE_HOST" \
            "curl -s -H 'X-OpenClaw-Key: $HOPE_KEY' \
             'http://127.0.0.1:$HOPE_PORT${endpoint}?${params}'"
    else
        sshpass -p "$SSH_PASS" ssh "$HOPE_HOST" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This function triggers a channel cookie refresh via POST, which is a state-changing administrative action. The script includes no confirmation, prompt, or explicit warning near the function or in the help text that this operation modifies remote system state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function performs a PUT request to update download-instance cleanup state, which is a state-changing operation that could affect system/task handling. There is no confirmation prompt, visible user-facing warning, or inline disclosure indicating that this action modifies server state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description forces a specific language presentation, and the rest of the skill documentation is also Chinese-only. The policy for this audit flags language or locale constraints when they are imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document title and structure imply it only contains query examples, yet it also documents a batch write operation. This mismatch can mislead operators and agents into executing a mutating command under the assumption that it is informational only, creating a documentation-driven safety issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all headings, descriptions, and examples in Chinese only. The policy requires flagging language or locale constraints when a skill forces a specific language without offering a user choice or documenting the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-facing comments, warnings, and help text are written in Chinese throughout the script, with no option to choose another language. This creates a language/locale constraint in the skill's natural-language interface without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.