Back to skill

Security audit

UniFi Network

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate UniFi read-only administration helper, but it stores and exports sensitive network data with weak safeguards.

Install only for trusted administrators on machines where local users and logs are trusted. Use a narrowly scoped read-only UniFi API key, configure only an HTTPS UniFi URL, protect or periodically clear ~/.clawdbot/cache/unifi, avoid raw output unless needed, and treat topology exports and client-history lookups as sensitive records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cache_clear.sh:37
Finding

Path Traversal in Cache Key Allows Deletion of JSON Files Outside the Cache Directory

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac target="${CACHE_DIR}/${MODE}.json" cache_root=$(realpath -m -- "${CACHE_DIR}") resolved_target=$(realpath -m -- "${target}") case "${resolved_target}" in "${cache_root}"/*.json) ;; *) echo "ERROR: Target is outside the cache directory" >&2 exit 1 ;; esac if [[ -f "${resolved_target}" ]]; then rm -f -- "${resolved_target}" fi ``` Additional hardening should include: - Prefer an explicit allowlist of known cache keys. - Use `--` before path operands passed to file utilities. - Reject arguments containing `/`, `\`, `..`, or control characters. - Add regression tests for absolute paths and traversal sequences. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib.sh:33
Finding

Sensitive UniFi API Responses Are Cached Without Explicitly Restrictive Permissions

Content
View full analysis
"${CACHE_DIR}/${1}.json" } ``` ### Technical Analysis The cache contains raw UniFi API responses, including internal IP and MAC addresses, client identities, device inventory, network and WLAN configuration, alerts, WAN details, and port-forwarding rules. The code creates the cache directory and files without setting explicit permissions. Their effective permissions therefore depend on the invoking process's `umask`. Under a commonly used `022` umask, the directory may be created as mode `755` and files as mode `644`, potentially allowing other local users to read the cached network data. The credentials file is separately documented as requiring mode `600`, but equivalent protection is not applied to cached API data. ### Attack Path 1. A user invokes a script that calls `cached_api`. 2. The script retrieves raw infrastructure data from the UniFi controller. 3. `cache_set` creates the cache directory and writes the response without setting restrictive permissions. 4. On a multi-user system with a permissive `umask`, another local account enumerates: ```text ~/.clawdbot/cache/unifi/ ``` 5. The local account reads cached JSON responses and obtains internal network information. ### Impact Assessment An unprivileged local user may obtain security-relevant infrastructure data, subject to the actual filesystem permissions and parent-directory access controls. Exposed information may include: - Internal hosts, addresses, MAC addresses, and client names. - VLANs, subnets, WLAN names, and topology details. - Device models, firmware versions, and operational status. - Port-forwarding rules and internal destinations. - Alerts, WAN details, and traffic application data. This information can support ...[truncated 138 chars]
Remediation
View remediation
"${tmp}" mv -f -- "${tmp}" "${target}" } ``` Additional hardening should include: - Validate cache keys before using them as filenames. - Ensure all existing cache files are mode `600`. - Ensure the cache directory is mode `700`. - Use atomic replacement to prevent partially written cache entries. - Document that cached results contain sensitive network metadata. - Provide an option to disable caching in higher-security environments. - Consider deleting cache data automatically when it is no longer needed. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib.sh:21
Finding

API Key Can Be Transmitted over Unencrypted HTTP

Content
View full analysis
``` 4. An attacker able to observe the local network captures the request. 5. The attacker reuses the API key against the controller. 6. The resulting access is bounded by the scopes granted to that API key. A configuration-tampering attacker could also replace the URL with an attacker-controlled HTTP endpoint, causing direct disclosure of the key when a script is run. ### Impact Assessment Successful exploitation can disclose the UniFi API key and sensitive API responses. The privileges obtained are those assigned to the compromised key. The documentation recommends a read-only key, which reduces impact, but a compro ...[truncated 363 chars]
Remediation
View remediation
&2 exit 1 } UNIFI_URL=$(jq -r '.url' "${CONFIG_FILE}") UNIFI_API_KEY=$(jq -r '.api_key' "${CONFIG_FILE}") UNIFI_SITE=$(jq -r '.site // "default"' "${CONFIG_FILE}") fi UNIFI_SITE="${UNIFI_SITE:-default}" case "${UNIFI_URL}" in https://*) ;; *) echo "ERROR: UNIFI_URL must use HTTPS" >&2 exit 1 ;; esac } ``` Additional hardening should include: - Permit HTTP only through an explicit, prominently warned insecure-development option. - Continue using curl's default TLS certificate and hostname verification. - Avoid adding `--insecure` or `-k`. - Recommend a narrowly scoped, read-only API key. - Rotate the API key immediately if it was ever used over HTTP. - Consider restricting acceptable controller hosts to an administrator-defined allowlist. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/cache_clear.sh (reported line 14)May include surrounding context.

sh
case "${MODE}" in
  --all)
    rm -f "${CACHE_DIR}"/*.json
    echo "Cache cleared."
    ;;
  ""| --status)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The invalidate function uses unsanitized user-controlled input to construct a filesystem path for rm -f. An attacker who can influence the cache key could supply path traversal sequences such as ../../ to delete arbitrary files writable by the current user outside the cache directory.

Content

Scanner excerpt · scripts/lib.sh (reported line 68)May include surrounding context.

sh
}

invalidate() {
  rm -f "${CACHE_DIR}/${1}.json"
}

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims 'read-only access' but also documents topology_export.sh writing network topology to an arbitrary user-specified path. Even if it does not modify UniFi itself, this is still local file write behavior and can mislead downstream agents or users into treating the skill as non-mutating, increasing the chance of unintended persistence of sensitive infrastructure data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The skill instructs storing a long-lived API key in a persistent plaintext config file under the user's home directory. Although file permissions are tightened, persistent local credential storage increases the blast radius of host compromise, accidental backup leakage, or unintended reuse by other local processes.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Setup

Create ~/.clawdbot/credentials/unifi/config.json:

json
{
  "url": "https://UniFi.Url.Here.local",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

"site": "default" }

text
`chmod 600 ~/.clawdbot/credentials/unifi/config.json`

API key: UniFi OS → Settings → System → API → Create API Key (read-only scopes).

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad trigger phrases such as generic status or connectivity questions can cause the skill to activate unexpectedly in ordinary conversation. In this skill's context, unintended invocation can disclose sensitive network inventory, client presence, VLAN, topology, or alert data to an agent workflow that did not clearly request infrastructure inspection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill encourages exporting complete topology data to an output path without warning that the content may include sensitive infrastructure details or that the destination may be long-lived and accessible by other tools. This increases the likelihood of unintentional disclosure, persistence in shared memory stores, or placement into unsafe paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The topology export trigger list includes especially broad phrases like 'write to memory' and 'document the network,' which could map loosely to many benign user requests. Because topology_export.sh can persist a full infrastructure map to disk or memory-like destinations, accidental activation materially increases the risk of sensitive network data exfiltration or unwanted persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This shell script performs cached API calls to retrieve client, device, and network data, which includes location-related and potentially sensitive network information, but the file provides no user-facing warning, confirmation, or disclosure beyond terse header comments. The same pattern recurs for historical client lookup, increasing the privacy impact without any explicit notice to the operator.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

When --include-history is supplied, the script queries historical client records via the alluser endpoint, which can expose prior device presence and movement information. There is no visible disclosure, confirmation, or warning in the script that this option expands the query into historical tracking data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The comment at L04 explicitly claims the script always fetches fresh data. However, L15 calls cached_api with TTL_INVENTORY, meaning it may return cached results instead of performing a live fetch. This is a direct contradiction between documentation and behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The --raw mode prints the full API response directly, which may include more fields than the sanitized default and JSON views expose, such as identifiers, topology details, timestamps, or other sensitive metadata. Because this happens with no warning, redaction, or access check in the script itself, a user can unintentionally disclose inventory and network information to logs, terminals, or downstream tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script reads UNIFI_API_KEY from environment variables or a credentials file and sends it in the X-API-Key request header during curl calls. Access to sensitive credentials and network transmission of authentication data occur without any user-facing warning, prompt, or explanatory comment about this behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The library persists API response bodies to ${HOME}/.clawdbot/cache/unifi via cache_set, and upstream comments indicate these responses include inventory, clients, health, and alerts data. This is a file-write of potentially sensitive system and user-network information, but the code provides no user-facing warning, confirmation, or disclosure about local persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script prints a concise inventory of the UniFi environment, including WAN IP, device names/models/status, network/VLAN configuration, and alert messages. In an agent skill context, this can expose sensitive internal infrastructure details to any caller or downstream log/trace system without an explicit access check, redaction step, or user warning, increasing reconnaissance value for an attacker.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation gives an absolute instruction to always call snapshot.sh first before any other script. Later examples contradict that directive by explicitly recommending single-script flows such as client_locate.sh, device_detail.sh, and topology_export.sh without first running snapshot.sh.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script prints device-identifying information directly to stdout in both JSON and text modes. There is no confirmation prompt, warning message, or explanatory comment indicating that the command reveals potentially sensitive client/network data, which fits the missing user warning criterion for code files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.