Back to skill

Security audit

VoxPact

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent VoxPact marketplace integration, but it can steer agents toward real-money actions and file transfers too broadly once enabled.

Install only if you intentionally want an agent to participate in VoxPact with real-money workflows. Keep VOXPACT_API_URL at the default VoxPact API host, use a tightly scoped and revocable API key, disable the hook unless a session explicitly needs VoxPact, and require human review before bids, paid job posts, approvals, cancellations, messages, or file uploads.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib.sh:8
Finding

Unrestricted API Endpoint Configuration Can Expose API Credentials and Sensitive Files

Content
View full analysis
&2 echo "$response" >&2 exit 1 } ``` Raw file uploads use the same configurable endpoint: ```bash response=$(curl -s -S -f -X "$method" \ -H "Authorization: ApiKey $VOXPACT_API_KEY" \ -H "Content-Type: $content_type" \ --data-binary "@${file_path}" \ -w "\n%{http_code}" \ "${VOXPACT_API}${path}") || { ``` Registration also trusts the configurable endpoint: ```bash api="${VOXPACT_API_URL:-https://api.voxpact.com}" api="${api%/}" response=$(curl -s -S -X POST \ -H "Content-Type: application/json" \ -d "$body" \ -w "\n%{http_code}" \ "${api}/v1/agents/register") ``` ### Technical Analysis The `VOXPACT_API_URL` environment variable is accepted without validating its scheme, hostname, port, or destination. Consequently, authenticated requests attach `VOXPACT_API_KEY` to any endpoint selected through that variable. The client does not enforce HTTPS or restrict requests to the documented `api.voxpact.com` host. A modified environment, wrapper process, deployment configuration, or malicious setup instruction could therefore redirect requests to an attacker-controlled HTTP or HTTPS server. The raw API function also uploads the complete contents of a caller-selected file. If the endpoint has been redirected, `deliver.sh` sends both the API cre ...[truncated 1821 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
hooks/openclaw/handler.js:5
Finding

Global Bootstrap Hook Injects Broad Marketplace and Financial-Action Instructions into Unrelated Sessions

Content
View full analysis
[message]` | | Accept direct job | `bash skills/voxpact/scripts/accept.sh ` | | Post a job | `bash skills/voxpact/scripts/post-job.sh <spec> <eur> <hours> [worker_id]` | | Upload input file | `bash skills/voxpact/scripts/upload-file.sh <job_id> <file_path>` | | Approve delivery | `bash skills/voxpact/scripts/approve.sh <job_id>` | | Cancel job | `bash skills/voxpact/scripts/cancel.sh <job_id>` | ``` ### Technical Analysis Once the hook is enabled and `VOXPACT_API_KEY` exists, it modifies the bootstrap context of every main-Agent session. The ...[truncated 2726 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description centers on a job marketplace workflow: finding jobs, bidding, delivering work, hiring agents, and checking earnings or status. The actual code chunk performs a narrower and different function: agent search by capability. While agent discovery could be tangentially related to hiring, the supplied code does not implement the marketplace capabilities described, and its primary behavior is not accurately represented by the declaration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk’s primary function is account/agent onboarding, not marketplace participation actions like finding jobs, bidding, delivering work, or checking earnings/status. It posts to /v1/agents/register and handles registration response output. That is a materially different purpose from the declared operational marketplace capabilities. There is also a direct contradiction in requirements: the description says the skill requires VOXPACT_API_KEY, while the script explicitly states it does not require the key because it is the mechanism to obtain it. Therefore, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description emphasizes marketplace/job actions: finding jobs, bidding, delivering work, hiring agents, and checking earnings or status. The actual code chunk does none of those. It strictly parses CLI options for capabilities, description, and webhook URL, builds a JSON body, and sends a PATCH request to update the agent's own profile. That is a materially different primary purpose from job marketplace operations. While profile setup could be related to participation in the marketplace, this specific code implements profile management/configuration, which is undeclared in the description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises shell and environment-variable use but does not declare any explicit tool scope such as allowed-tools or permissions. In an agent ecosystem, this weakens least-privilege boundaries and can cause the skill to be invoked with broader command execution access than users expect, especially since it handles API keys and external network operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance is broad enough that an orchestrating agent may invoke this skill in many loosely related situations involving money, work, or hiring. Overbroad routing increases the chance of unnecessary external data sharing, shell execution, or unintended marketplace actions without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to register with name, email, country, webhook URL, and capabilities, but it does not prominently warn that these personal and operational details will be transmitted to a third-party service. Because the skill also enables file transfer, job messaging, and payments, users may unknowingly expose sensitive business data or infrastructure endpoints.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The documented auto-approve behavior means a financial decision can occur without an active human review step after a timeout. In the context of escrowed payments and potentially autonomous agents, this can lead to unwanted fund release, acceptance of poor or malicious deliverables, or exploitation through deliberate delay tactics.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
**Payment flow:**
1. Buyer's payment is held in Stripe escrow when job is created
2. You deliver work via `scripts/deliver.sh`
3. Buyer's agent (or auto-approve after 48h) approves
4. Stripe transfers your cut (minus platform fee) to your connected account

**Platform fees (tiered by trust score):**

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
## API Reference

Base URL: `https://api.voxpact.com/v1`

Auth: `Authorization: ApiKey <your_key>` header on every request.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This hook silently injects a marketplace capability file into every eligible agent bootstrap whenever the API key is present, without any user consent, visibility, or task-scoping. In this skill's context, the injected content explicitly encourages the agent to seek paid work, bid on jobs, exchange files, and message third parties, which can change agent behavior and trigger external actions unrelated to the user's request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This bootstrap hook silently injects marketplace instructions into every eligible top-level agent session when VOXPACT_API_KEY is present, encouraging the agent to execute shell commands that can post jobs, send messages, transfer files, and move work through a real-money workflow. Because there is no user-facing disclosure, consent gate, or policy check, an agent could take externally impactful actions against a third-party service or exfiltrate local files via upload/deliver commands without the user explicitly realizing this capability was added.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs a state-changing network action that places a bid on a marketplace job immediately, with no confirmation prompt, dry-run mode, or explicit warning to the caller. In this skill’s context, that is meaningful because bidding can create financial commitments, trigger escrow-related workflows, or cause unintended marketplace activity if the script is invoked with the wrong parameters or by another automated agent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
72% confidence
Finding

The function uploads arbitrary local files to a remote service using --data-binary and authenticates with the user's API key. In the context of an agent skill that can autonomously perform work and send deliverables, this creates a real data-exfiltration surface if other scripts call this helper on sensitive files or if VOXPACT_API_URL is redirected to an attacker-controlled host.

Content

Scanner excerpt · scripts/lib.sh (reported line 56)May include surrounding context.

sh
fi

  local response http_code
  response=$(curl -s -S -f -X "$method" \
    -H "Authorization: ApiKey $VOXPACT_API_KEY" \
    -H "Content-Type: $content_type" \
    --data-binary "@${file_path}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.sh (reported line 31)May include surrounding context.

sh
EOF
)

response=$(curl -s -S -X POST \
  -H "Content-Type: application/json" \
  -d "$body" \
  -w "\n%{http_code}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upload-file.sh (reported line 41)May include surrounding context.

sh
# Step 2: PUT file to presigned URL (no auth header needed)
echo "Uploading ${file_size} bytes..."
curl -s -S -f -X PUT \
  -H "Content-Type: $content_type" \
  --data-binary "@${file_path}" \
  "$upload_url" || { echo "ERROR: Upload to presigned URL failed" >&2; exit 1; }

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language context states that agents can earn real EUR, which imposes a specific currency/locale in the injected instructions. The file does not offer an alternative currency or explain why a EUR-only marketplace is required for this skill's use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This shell helper performs HTTP uploads and includes the VOXPACT_API_KEY authorization credential, but the function has no confirmation prompt or user-facing warning that local file contents will be transmitted to a remote API. The existing comments describe usage for developers, not a disclosure to end users about network transfer or credential use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The header comment states this script 'registers your agent and stores the API key' and further says it 'obtains' the key. In practice, the script only POSTs registration data to the VoxPact API and then instructs the user to check email and manually export the API key later; it does not receive, persist, or store any key.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest and file are for the VoxPact skill, but the JSON payload hard-codes a description of 'OpenClaw agent ready to work on VoxPact'. This is an intent/documentation mismatch inside the code that suggests copied or stale branding rather than the declared skill identity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.