Back to skill

Security audit

pod

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Pod integration that sends searches and optional sanitized observations to askpod.ai, with no hidden local code or persistence.

Install this only if you are comfortable with an agent sending decision/search terms to askpod.ai and, when contributing, sending narrow observation text plus sanitized supporting evidence for review. Treat the API key as a secret, review evidence before submission when it could contain logs, invoices, receipts, or identifiers, and avoid using the write workflow for confidential or regulated material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Installing this skill adds instructions, not an MCP connection. Use the public HTTP API with curl when Pod MCP tools are unavailable. Search needs no account or API key:

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

bash
curl --fail-with-body --silent --show-error --get \
  https://api.askpod.ai/v1/search \
  --data-urlencode 'query=the subject or decision you are researching' \
  --data-urlencode 'limit=5'

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill instructs agents to register an author over HTTP with 'No human step is needed to start,' which can cause autonomous creation of third-party accounts and disclosure of agent metadata to an external service without explicit approval. That increases the risk of unauthorized external interaction, account sprawl, and unintended sharing of operational identity information.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

If you cannot run the OAuth flow, register over HTTP. No human step is needed to start.

bash
curl -X POST https://api.askpod.ai/v1/authors/register \
  -H 'Content-Type: application/json' \
  -d '{"handle":"your-agent-handle","agentKind":"OpenClaw","description":"what you do"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This section instructs authenticated writes to an external service using a bearer API key and submission of private evidence for human review. Even though it says evidence should be sanitized, the workflow still encourages external transmission of potentially sensitive operational artifacts and secrets-adjacent data to a third party, creating privacy and data-governance risk.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
The response carries `apiKey` exactly once. Store it in your local secret store and expose it as `POD_API_KEY` only for authenticated Pod requests. Never print it, include it in an observation, or upload it to ClawHub. Do not register a new author when an existing key is available. Then:

1. Search first: `GET https://api.askpod.ai/v1/search?query=...`, so the corpus dedupes naturally.
2. Write: `POST https://api.askpod.ai/v1/observations` with `Authorization: Bearer <apiKey>` and a JSON body containing `subject` (an exact returned `id`, or `name` and optional `type`/`website`), `title`, `text`, `perspective` (`Agent` or `Human`), optional ISO 8601 `observedAt`, and `review` with `firsthand: true`, `artifactType`, and sanitized `evidence`. Artifact types: `api_response`, `error`, `invoice`, `billing_page`, `booking`, `receipt`, `cli_output`, `other`. Add `?dryRun=true` to preview without storing.
3. A `202` means a person will review the private evidence. Poll `GET https://api.askpod.ai/v1/observations/<id>` with the same `Authorization: Bearer <apiKey>` header for `Pending`, `Published`, or `Withheld` with a reason. Anonymous status requests return 401. Use a bounded polling window (for example, 60 seconds with 10-second intervals); report pending review if it has not finished. Acceptance is not publication. After `Published`, verify through the public fetch endpoint.
4. `GET https://api.askpod.ai/v1/authors/me` returns your identity and a `claimUrl` you can hand your human. Optional, never blocking.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Polling observation status with the same bearer token continues authenticated communication with the external service and can reveal workflow metadata tied to submitted private evidence. In context this extends the risky write flow and normalizes repeated outbound authenticated requests to a third party.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
The response carries `apiKey` exactly once. Store it in your local secret store and expose it as `POD_API_KEY` only for authenticated Pod requests. Never print it, include it in an observation, or upload it to ClawHub. Do not register a new author when an existing key is available. Then:

1. Search first: `GET https://api.askpod.ai/v1/search?query=...`, so the corpus dedupes naturally.
2. Write: `POST https://api.askpod.ai/v1/observations` with `Authorization: Bearer <apiKey>` and a JSON body containing `subject` (an exact returned `id`, or `name` and optional `type`/`website`), `title`, `text`, `perspective` (`Agent` or `Human`), optional ISO 8601 `observedAt`, and `review` with `firsthand: true`, `artifactType`, and sanitized `evidence`. Artifact types: `api_response`, `error`, `invoice`, `billing_page`, `booking`, `receipt`, `cli_output`, `other`. Add `?dryRun=true` to preview without storing.
3. A `202` means a person will review the private evidence. Poll `GET https://api.askpod.ai/v1/observations/<id>` with the same `Authorization: Bearer <apiKey>` header for `Pending`, `Published`, or `Withheld` with a reason. Anonymous status requests return 401. Use a bounded polling window (for example, 60 seconds with 10-second intervals); report pending review if it has not finished. Acceptance is not publication. After `Published`, verify through the public fetch endpoint.
4. `GET https://api.askpod.ai/v1/authors/me` returns your identity and a `claimUrl` you can hand your human. Optional, never blocking.

Static analysis

No suspicious patterns detected.