Back to skill

Security audit

Tabstack

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed wrapper for Tabstack web research and browser automation, with expected external data sharing and no evidence of hidden persistence or malicious behavior.

Install this only if you are comfortable sending processed URLs, schemas, instructions, research queries, and optional form data to Tabstack. Avoid using it with secrets, passwords, payment data, private intranet URLs, or sensitive documents unless your organization approves Tabstack for that data. Use guardrails for automation, especially when a task could click buttons or submit forms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description claims a powerful web/PDF research and browser automation skill. However, the supplied code chunk only acts as a launcher script for another TypeScript file. Since the actual functional behavior is not present in this chunk, the code shown does not substantiate the declared purpose. This is a material description-to-code mismatch for the supplied code chunk: the observable behavior is just delegation/execution, while the declared purpose is a full-featured research and automation tool.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list is extremely broad and includes catch-all patterns such as common research phrases and any URL/link, making accidental activation likely during normal conversation. Because this skill can perform remote browsing, data extraction, and browser automation, over-triggering can cause unintended network access, third-party data disclosure, unnecessary spending, or automated interaction with untrusted sites.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly requires environment access to read TABSTACK_API_KEY but does not declare a restrictive tool scope such as allowed-tools or permissions. In a skill that can trigger on broad research prompts and invoke shell commands, undeclared capability boundaries make it harder to enforce least privilege and increase the chance of unintended tool or secret exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Using npx tsx without pinning an exact package version allows resolution of whatever version of tsx is locally available or fetched at runtime from the registry. That creates a supply-chain risk: a compromised, malicious, or breaking upstream release could execute arbitrary code when this launcher runs, which is especially concerning for a skill intended to drive web automation and data extraction.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The extract/generate paths send user-supplied URLs, schemas, and instructions to the external Tabstack service without any explicit disclosure, consent check, or data-sensitivity guard. In a skill intended for web reading, scraping, and extraction, users may provide internal URLs, sensitive documents, or proprietary prompts, causing unintended third-party data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The automation feature forwards task text, target URLs, guardrails, and optional structured data to an external agent service and may drive multi-step browser automation. Because the skill description explicitly encourages form filling, login flows, and site interaction, this materially increases the risk of transmitting credentials, personal data, or sensitive operational instructions to a third party without clear warning.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.3 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The dependency uses a caret range, which allows newer minor and patch versions of @tabstack/sdk to be installed over time. This can introduce supply-chain risk by pulling in unreviewed upstream changes or a compromised release, which is more relevant here because the skill is a web-browsing and automation component that may process untrusted web content and handle sensitive session data.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"private": true,
  "description": "OpenClaw skill for web browsing via the Tabstack API",
  "dependencies": {
    "@tabstack/sdk": "^2.2.0",
    "tsx": "^4.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The tsx dependency is also specified with a caret range, so builds may resolve to different versions over time. Even though this is likely a development/runtime helper, unpinned packages still create a supply-chain exposure and can affect execution if a malicious or breaking upstream version is published.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"description": "OpenClaw skill for web browsing via the Tabstack API",
  "dependencies": {
    "@tabstack/sdk": "^2.2.0",
    "tsx": "^4.0.0"
  }
}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Research queries are sent to Tabstack without any explicit notice that the query content leaves the local environment. Even though research is lower risk than browser automation, users may include confidential business questions, incident details, or regulated data in free-form queries, leading to unintended external disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.