Back to skill

Security audit

Github Bounty Finder

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do the advertised bounty scanning, but it asks users for more GitHub token permission than its read-only search behavior needs and gives weak secret-handling guidance.

Review before installing. Use the least-privileged, short-lived GitHub token possible, preferably read-only or unauthenticated public search if rate limits are acceptable; do not grant repository write, admin, workflow, or private-repo access. Keep .env out of source control and rotate keys if exposed. Be aware that JSON export can overwrite the path you provide and that dependencies are not pinned in the artifact.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:39
Finding

Documentation Requests an Overprivileged GitHub Personal Access Token

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:39-41; duplicated in README.md:72-75
Vulnerability Type: Violation of least privilege through excessive API token permissions
Risk Level: Medium

Complete Vulnerable Snippets:

SKILL.md:39-41

markdown
1. **GitHub Token**: 
   - Go to GitHub Settings → Developer settings → Personal access tokens
   - Create a token with `public_repo` scope

README.md:72-75

markdown
**Getting GitHub Token:**
1. Visit https://github.com/settings/tokens
2. Create new token with `public_repo` scope
3. Copy and save to `.env`

Technical Analysis

The Skill instructs users to create a GitHub personal access token with the classic public_repo scope. That scope provides broader access to public repositories than the implemented functionality requires.

The relevant implementation in src/scanner.js:24-34 only submits a read-only request to GitHub's issue search endpoint:

javascript
const response = await axios.get(`${this.baseURL}/search/issues`, {
  headers: {
    'Authorization': `token ${this.githubToken}`,
    'Accept': 'application/vnd.github.v3+json'
  },
  params: {
    q: `${query} is:issue is:open sort:created-desc`,
    per_page: limit
  }
});

No repository modification, issue creation, source-code update, or other write operation is implemented. Requiring public_repo therefore violates the principle of least privilege. Public issue searches can be performed without authentication at lower rate limits, or with a fine-grained token limited to read-only metadata and issue access when authentication is necessary.

The audited code sends the token only to the fixed HTTPS GitHub API endpoint and does not itself expose or exfiltrate it. Exploitation consequently requires a separate compromise of the token, local .env file, process environment, dependency, or host account. The excessive permission increases th ...[truncated 1487 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to create a classic token with the public_repo scope.
  2. Make unauthenticated GitHub searching the default when its lower rate limit is acceptable.
  3. If authentication is required, instruct users to create a fine-grained personal access token with:
    • Read-only access.
    • Only the metadata and issue permissions required for search.
    • Access restricted to the smallest feasible repository set.
    • A short expiration period.
  4. Explicitly state that repository contents, administration, workflows, pull requests, and issue write permissions are not required.
  5. Update both SKILL.md and README.md so their guidance remains consistent.
  6. Add a warning that .env must not be committed, shared, included in logs, or copied into exported scan results.
  7. Consider rejecting or warning about known overprivileged classic token configurations where GitHub APIs provide enough metadata to identify them.
  8. Recommend periodic token rotation and immediate revocation if disclosure is suspected.

Suggested replacement documentation:

markdown
GitHub authentication is optional for public searches. To obtain higher rate
limits, use a short-lived fine-grained personal access token with read-only
Metadata and Issues access. Do not grant repository write, administration,
workflow, or private-repository permissions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 16)May include surrounding context.

md
clawhub install github-bounty-finder

# Configure
echo "GITHUB_TOKEN=your_token" > .env
echo "ALGORA_API_KEY=your_key" >> .env

# Scan for bounties

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 17)May include surrounding context.

md
clawhub install github-bounty-finder

# Configure
echo "GITHUB_TOKEN=your_token" > .env
echo "ALGORA_API_KEY=your_key" >> .env

# Scan for bounties

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · RELEASE.md (reported line 87)May include surrounding context.

md
clawhub install github-bounty-finder

# Configure
echo "GITHUB_TOKEN=your_token" > .env
echo "ALGORA_API_KEY=your_key" >> .env

# Scan for bounties

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · bin/cli.js (reported line 99)May include surrounding context.

js
clawhub install github-bounty-finder

# Configure
echo "GITHUB_TOKEN=your_token" > .env
echo "ALGORA_API_KEY=your_key" >> .env

# Scan for bounties

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · RELEASE.md (reported line 86)May include surrounding context.

配置

bash
cd skills/github-bounty-finder
cp .env.example .env
# 编辑 .env 添加 GITHUB_TOKEN 和 ALGORA_API_KEY

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
### Getting API Keys

1. **GitHub Token**: 
   - Go to GitHub Settings → Developer settings → Personal access tokens
   - Create a token with `public_repo` scope

2. **Algora API Key**:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawhub.json (reported line 85)May include surrounding context.

json
},
  "requirements": [
    "Node.js 18.0.0 or higher",
    "GitHub Personal Access Token (free)",
    "Algora API Key (free)"
  ],
  "changelog": [

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to place a GitHub token and Algora API key in a local .env file but provides no warning about secret handling, accidental commits, file permissions, or rotation. While using environment variables is common, omitting basic secret-safety guidance increases the chance that users expose credentials through source control, logs, or shared systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scan command writes results directly to the path supplied by --output using fs.writeFileSync, which can overwrite an existing file. Although the CLI logs after saving, there is no prior warning, confirmation, or comment/docstring disclosing that this operation modifies the filesystem.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a JSON manifest file, so vague-trigger review applies. The description says the skill will "Scan Algora/GitHub" but provides no explicit trigger phrases, activation conditions, or exclusions, which makes it unclear when the skill should be invoked versus ordinary requests about GitHub, bounties, or opportunity scoring.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/scanner.js (reported line 64)May include surrounding context.

js
try {
      // Algora API endpoint (adjust based on actual API)
      const response = await axios.get('https://api.algora.io/v1/bounties', {
        headers: {
          'Authorization': `Bearer ${this.algoraApiKey}`
        },

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file instructs users to create a .env file containing a GitHub token and Algora API key, but it does not include any warning about protecting those credentials, avoiding commits, or the fact that the skill will use them to access external services. Under the markdown variant of SQP-2, credential- and privacy-affecting behavior should be disclosed to users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing natural-language content exclusively in Chinese, including headings, usage instructions, warnings, and support information. Under the policy rule for language/locale, forcing a single language without opt-in or justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest targets generic groups like "Job seekers" and promotes automated recommendations, but it does not narrow the contexts in which the skill should activate. Without concrete trigger phrases or exclusions, the skill could be invoked for broad career or GitHub-related conversations rather than only bounty-finding tasks.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency uses a caret range instead of an exact pinned version, which allows different patch/minor releases to be installed over time. That weakens build reproducibility and increases supply-chain risk because a later vulnerable or malicious release could be pulled without changes to this manifest.

Content

Scanner excerpt · package.json (reported line 25)May include surrounding context.

json
"author": "OpenClaw Skills",
  "license": "MIT",
  "dependencies": {
    "axios": "^1.6.0",
    "chalk": "^4.1.2",
    "commander": "^11.1.0",
    "dotenv": "^16.3.1",

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
85% confidence
Finding

Axios has multiple known advisories, and because the manifest uses an unpinned range, it is not possible to verify from this file whether the installed release is affected. Given this skill appears to scan external services over HTTP, a vulnerable axios version could increase exposure to SSRF, request handling flaws, or response manipulation issues depending on usage in code.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The chalk dependency is not pinned to an exact version, so installs may resolve to different releases over time. In a CLI-oriented skill, this increases supply-chain exposure because a compromised or malicious upstream release could be introduced implicitly.

Content

Scanner excerpt · package.json (reported line 26)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "axios": "^1.6.0",
    "chalk": "^4.1.2",
    "commander": "^11.1.0",
    "dotenv": "^16.3.1",
    "node-fetch": "^2.7.0"

Unverifiable Dependency: chalk has 1 known advisory(ies) (MAL-2025-46969 (Malicious code in chalk (npm))), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
74% confidence
Finding

The manifest does not pin chalk, and static analysis reports at least one advisory associated with the package namespace, making it impossible to verify safety from this file alone. Since chalk is typically used for terminal formatting rather than sensitive logic, the direct impact is lower, but it still represents a supply-chain trust risk if a malicious release is resolved.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Using a version range for commander permits non-deterministic dependency resolution across environments and over time. While not an immediate exploit by itself, it creates a real supply-chain weakness by making it harder to verify exactly what code is installed.

Content

Scanner excerpt · package.json (reported line 27)May include surrounding context.

json
"dependencies": {
    "axios": "^1.6.0",
    "chalk": "^4.1.2",
    "commander": "^11.1.0",
    "dotenv": "^16.3.1",
    "node-fetch": "^2.7.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

dotenv is specified with a caret range, allowing future compatible releases to be installed automatically. This undermines reproducibility and could expose the skill to unexpected behavior or vulnerable code introduced upstream.

Content

Scanner excerpt · package.json (reported line 28)May include surrounding context.

json
"axios": "^1.6.0",
    "chalk": "^4.1.2",
    "commander": "^11.1.0",
    "dotenv": "^16.3.1",
    "node-fetch": "^2.7.0"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

node-fetch is unpinned, so the actual installed version may vary between installations. Because this package performs network operations, supply-chain drift is more concerning in this skill's context, especially if a bad release affects request handling or data exposure.

Content

Scanner excerpt · package.json (reported line 29)May include surrounding context.

json
"chalk": "^4.1.2",
    "commander": "^11.1.0",
    "dotenv": "^16.3.1",
    "node-fetch": "^2.7.0"
  },
  "engines": {
    "node": ">=18.0.0"

Unverifiable Dependency: node-fetch has 3 known advisory(ies) (CVE-2022-0235 (node-fetch forwards secure headers to untrusted sites); CVE-2022-2596 (node-fetch Inefficient Regular Expression Complexity ); CVE-2020-15168 (The `size` option isn't honored after following a redirect in node-fetch)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

node-fetch has known historical advisories, and because only a range is declared, the resolved installed version cannot be verified from the manifest. In a network-scanning CLI, an affected fetch library could leak headers across redirects or mishandle responses, making this more dangerous than a purely local utility dependency.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/scanner.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:69