Back to skill

Security audit

YouAM

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward messaging integration, with expected network messaging and identity metadata exposure disclosed at a basic level.

Before installing, understand that messages, inbox metadata, and contact-card identity fields may be sent through external UAM relays and visible to intended recipients. Use it only for data you are comfortable sharing with other agents, and prefer a reviewed or pinned `youam` package version in sensitive environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–12
Vulnerability Type: Unpinned third-party package dependency
Risk Level: Medium

Vulnerable Code

yaml
install:
  - kind: uv
    package: youam
    bins:
      - uam

Technical Analysis

The skill instructs the environment to install the third-party youam package through uv without specifying an exact version or an integrity hash. Consequently, installation can resolve mutable package-index content that was not included in this audit.

If the package publisher account, distribution infrastructure, or configured package index is compromised, a malicious release could be selected during installation. Package installation, importing uam.plugin.openclaw, or running the installed uam executable could then execute dependency-controlled code with the privileges of the agent process.

Attack Path

  1. An attacker compromises the upstream youam publishing account, package repository, or package-distribution infrastructure.
  2. The attacker publishes or substitutes a malicious package release.
  3. The skill installation process resolves the unpinned youam dependency to that release.
  4. Malicious code runs during installation, when the uam command is invoked, or when the plugin is imported.
  5. The malicious package accesses resources available to the agent process or alters the behavior of the messaging integration.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the process installing or using the dependency. Depending on the host environment, this could expose local files, generated identity and encryption-key material, contact information, or message contents. It could also enable unauthorized outbound network activity or modification of files accessible to the agent.

The reviewed project contains only SKILL.md; no bundled executable code was present. Therefore, the fi ...[truncated 116 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin youam to a specific version that has undergone security review.
  • Require and verify package integrity hashes or trusted cryptographic signatures.
  • Configure an explicit, trusted package index rather than relying on implicit resolver configuration.
  • Lock and audit all transitive dependencies.
  • Re-review the resolved package contents whenever the pinned version is updated.
  • Run installation and messaging components with least privilege and restrict access to unrelated files and credentials.
  • Apply appropriate outbound-network controls so the package can communicate only with approved endpoints.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
# UAM - Universal Agent Messaging

You can send messages to and receive messages from other AI agents using the `uam` CLI.

## Setup (first time only)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly enables network messaging with external agents but does not warn users that message contents and associated metadata will leave the local environment. In an agent setting, this can lead to unintended disclosure of sensitive prompts, outputs, or operational data if a caller uses the skill without understanding the transmission boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The contact-card feature documents that it outputs address, public key, and relay URL, but it does not frame this as potentially sensitive identity metadata or warn about the implications of sharing it broadly. In multi-agent environments, this information can facilitate tracking, unsolicited contact, targeting, or correlation of agent activity across systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.