Back to skill

Security audit

ModelPool (Free)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate OpenClaw model manager, but it handles API keys and local OpenClaw configuration in ways users should review carefully before installing.

Install only after verifying the package name and source you are installing, and treat this as a tool with authority to store API keys, rewrite OpenClaw model configuration, contact provider APIs, and restart OpenClaw. Rotate any keys previously passed on a command line, check permissions on `~/.openclaw`, and avoid running `modelpool repair` unless you are comfortable with it testing configured provider URLs and changing local state.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
README.md:16
Finding

Documented Installation Command Resolves a Different Python Distribution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/freeswitch.py:76
Finding

OpenRouter Bearer Credentials Are Stored in Plaintext Without Enforced File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/freeswitch.py:542
Finding

API Keys Accepted as Command-Line Arguments Can Leak Through Shell and Process Metadata

Content
View full analysis
``` ### Technical Analysis The `keys add` command accepts a bearer credential as a positional command-line argument. Command arguments commonly appear in: - Shell history files. - Process listings while the command is running. - Terminal session recordings. - Audit and endpoint-monitoring telemetry. - Wrapper-script logs and command execution traces. Masking keys in `cmd_keys_list()` does not protect credentials already exposed through the invocation command. ### Attack Path 1. A user executes `modelpool keys add sk-or-...`. 2. The interactive shell records the complete command in its history, or a process/audit monitor captures the argument vector. 3. A local user, support operator, log reader, or compromised process retrieves that record. 4. The attacker extracts the bearer key. 5. The attacker uses the key against OpenRouter until it is revoked. The process-listing exposure may be brief, but shell history and monitoring records can retain the secret lo ...[truncated 471 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/repair.py:114
Finding

Repair Command Sends Provider Bearer Credentials to Unrestricted Configured URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README advertises automated diagnostics, cleanup, config modification, and service restarts, but does not clearly warn users that running the repair flow will change local state and may disrupt active sessions or alter configuration unexpectedly. In an agent-skill context, users may trigger commands with elevated trust and limited review, making undocumented state-changing behavior more dangerous even if the underlying intent is operational convenience rather than harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup flow shows users entering API keys, saving them, reconfiguring providers, and restarting OpenClaw, but it does not disclose how credentials are stored, whether they are encrypted or file-permission protected, or that service interruption will occur. Because this is an installation/setup skill intended for quick execution, the omission increases the risk of insecure secret handling and unexpected downtime in local development environments.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises behaviors implying file access, configuration changes, network calls, and process/control actions, but it declares no explicit tool scope or permissions. In an agent ecosystem, this creates an authorization ambiguity where a user may invoke a seemingly simple setup command without understanding that it can read/write config, contact external services, and trigger repair or restart flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The invocation language is highly promotional and underspecified, using phrases like 'one command' and 'everything auto-configured' without defining boundaries, side effects, or safety checks. This can mislead users and agent runtimes into approving broad autonomous actions that include credential handling, network access, and configuration changes beyond what the user reasonably expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to enter and manage multiple API keys but provides no warnings about secret handling, masking, storage, redaction, or display in status/list commands. Because the skill explicitly includes commands like 'status' and 'keys list', omission of key-safety guidance materially increases the risk of credential exposure in terminal output, logs, screenshots, or persisted config.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'one-click repair' workflow promises automatic diagnosis, cleanup, memory/log cleanup, and full restart, but it does not warn users about system-state changes, interruption risk, or the scope of those actions. In context, this is dangerous because the skill is positioned as a convenience tool for OpenClaw management, so users may trigger disruptive or potentially destructive maintenance actions without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide tells users to copy and paste an API key but does not clearly state that the key is a sensitive secret that must never be shared, committed to source control, pasted into chats, or stored insecurely. In a skill that targets non-expert users and encourages quick setup, this omission materially increases the risk of credential leakage and unauthorized use of the user's OpenRouter account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide explicitly encourages creating multiple OpenRouter accounts to multiply free quota, which may violate provider terms, trigger abuse detection, or lead users to account suspension. In the context of a tool marketed around free-quota maximization and key rotation, this behavior normalizes circumvention of platform limits and increases both compliance and operational risk for users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

API keys are stored in plaintext in a predictable path under the user's home directory without permission hardening or a clear warning to the user. If the file is exposed through permissive filesystem permissions, backups, or local compromise, the credentials can be recovered and abused to access the user's provider account and quota.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/freeswitch.py (reported line 340)May include surrounding context.

python
# Validate and restart
    print("\n  🔍 Validating...")
    subprocess.run(["openclaw", "config", "validate"], capture_output=True)

    print("  🔄 Restarting OpenClaw...")
    subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/freeswitch.py (reported line 343)May include surrounding context.

python
subprocess.run(["openclaw", "config", "validate"], capture_output=True)

    print("  🔄 Restarting OpenClaw...")
    subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)
    time.sleep(15)

    print("")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/freeswitch.py (reported line 391)May include surrounding context.

python
subprocess.run(["openclaw", "config", "validate"], capture_output=True)

    print("  🔄 Restarting OpenClaw...")
    subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)
    time.sleep(15)

    print("")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/freeswitch.py (reported line 439)May include surrounding context.

python
subprocess.run(["openclaw", "config", "validate"], capture_output=True)

    print("  🔄 Restarting OpenClaw...")
    subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)
    time.sleep(15)

    print("")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The auto-configuration path writes a new OpenClaw configuration and restarts the daemon without explicit confirmation, which can silently alter provider settings and operational behavior. In a security-sensitive environment, unexpected config replacement can disrupt existing safeguards, reroute model traffic, or overwrite carefully managed settings.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/freeswitch.py (reported line 474)May include surrounding context.

python
print(f"    {i}. {fb}")

    # Test gateway
    result = subprocess.run(["ss", "-tlnp"], capture_output=True, text=True)
    gw_ok = "18789" in result.stdout
    print(f"\n  Gateway: {'✅ running' if gw_ok else '❌ down'}")
    print("")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/freeswitch.py (reported line 485)May include surrounding context.

python
script_dir = os.path.dirname(os.path.abspath(__file__))
    repair_script = os.path.join(script_dir, "repair.py")
    if os.path.exists(repair_script):
        subprocess.run([sys.executable, repair_script])
    else:
        print(f"  ❌ repair.py not found at {script_dir}")
        print("  Try running from the freeswitch/scripts directory")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/repair.py (reported line 29)May include surrounding context.

python
try:
        if isinstance(cmd, str):
            cmd = shlex.split(cmd)
        r = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout)
        return r.stdout.strip(), r.returncode
    except subprocess.TimeoutExpired:
        return "TIMEOUT", -1

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The save_config function unconditionally backs up and rewrites ~/.openclaw/openclaw.json, with no prior disclosure at the point of execution and no user consent gate. Automatic modification of a user's application config is security-relevant because it can change operational behavior, break trust assumptions, or overwrite intentional settings if the script's logic is wrong or manipulated upstream.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The repair workflow automatically rewrites the user's OpenClaw model configuration when rebuilding the fallback chain, without interactive confirmation or a dry-run mode. This can silently alter service behavior and model routing, which is risky in an agent-install/repair context because it changes trusted local configuration based on network test results and script logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script stops and restarts the OpenClaw daemon automatically, causing service interruption without prior warning or confirmation. In an agent skill context, unexpected daemon restarts can disrupt active workloads and may be abused socially by packaging impactful operational changes as a 'repair' action users might run without understanding the consequences.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · setup.py (reported line 7)May include surrounding context.

python
name="modelpool-free",
    version="1.0.3",
    description="Free AI Model Manager for OpenClaw — auto-discover, multi-key rotation, smart fallback, one-click repair",
    long_description=open("README.md", encoding="utf-8").read() if __import__("os").path.exists("README.md") else "",
    long_description_content_type="text/markdown",
    author="LeeHub",
    url="https://github.com/meilihulee/modelpool",

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes discovery, configuration, fallback setup, and repair of free AI models for OpenClaw. In addition to that, the status command runs ss -tlnp to inspect local listening sockets/process information and infer gateway health, which is host-level introspection not clearly justified by the stated model manager role.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The cleanup step removes .log files older than three days using os.remove. While cleanup may be part of maintenance, the script gives only a post-action status message and no advance warning that files will be deleted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.