Back to skill

Security audit

Formatgate

Security checks for vulnerabilities and agentic risk

Overview

FormatGate is a straightforward local format-conversion skill with some reliability and dependency caveats but no evidence of hidden data access, persistence, or exfiltration.

Install only if you are comfortable running a local conversion API and downloading its Python dependencies. Avoid sending secrets or sensitive configuration through the endpoint unless you control the running server, and do not rely on perfect round-trip preservation for all TOML/YAML/JSON edge cases.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 4
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable code:

yaml
metadata: {"openclaw":{"emoji":"🔄","requires":{"bins":["python"]},"install":[{"id":"pip","kind":"uv","packages":["fastapi","uvicorn","pydantic","pyyaml"]}]}}

Technical Analysis

The installation metadata requests fastapi, uvicorn, pydantic, and pyyaml without exact version constraints or integrity hashes. Consequently, dependency resolution can produce different installations over time and may select a compromised, malicious, or incompatible future release.

The package names appear to correspond to legitimate dependencies, and the reviewed project contains no evidence that they are currently malicious. The risk arises because the dependency source and resulting artifacts are not cryptographically fixed to versions reviewed by the project maintainers.

Attack Path

  1. An attacker compromises the publishing account, distribution infrastructure, or a transitive dependency associated with one of the declared packages.
  2. The attacker publishes a malicious release under a dependency name used by the installation metadata.
  3. A user installs the skill after that release becomes eligible for unconstrained resolution.
  4. The uv-based installer resolves and downloads the malicious or compromised package.
  5. Malicious behavior executes during package installation, module import, or server startup, subject to the behavior of the compromised package and the privileges of the installation process.

This exploitation path depends on an upstream supply-chain compromise; no direct remote code retrieval or deliberately malicious dependency was identified in the project itself.

Impact Assessment

A compromised dependency could execute code with the privileges of the account installing or running FormatGate. Depending on that account's permissions ...[truncated 346 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed, exact version rather than using unconstrained package names.
  2. Generate and commit a lockfile that also fixes all transitive dependency versions.
  3. Require cryptographic hashes for downloaded distributions where the installation workflow supports hash verification.
  4. Configure installation to use an explicitly trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.
  5. Regularly scan pinned dependencies for known vulnerabilities and update them through a controlled review process.
  6. Perform installation and runtime execution under a dedicated, least-privileged account or isolated environment.
  7. Rebuild and test the locked environment reproducibly before publishing updated dependency versions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims 'round-trip safe' conversion across JSON, YAML, and TOML, but that guarantee is not generally true because these formats have different type systems and structural constraints. This can cause silent data loss, schema drift, or incorrect output assumptions in downstream agents that trust the claim, especially for TOML edge cases such as non-table top-level data or unsupported value representations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Convert JSON to YAML

bash
curl -s -X POST http://localhost:8008/v1/convert \
  -H "Content-Type: application/json" \
  -d '{"content": "{\"name\": \"Alice\", \"age\": 30}", "input_format": "json", "output_format": "yaml"}' | jq -r '.result'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Convert JSON to YAML

bash
curl -s -X POST http://localhost:8008/v1/convert \
  -H "Content-Type: application/json" \
  -d '{"content": "{\"name\": \"Alice\", \"age\": 30}", "input_format": "json", "output_format": "yaml"}' | jq -r '.result'

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This is a code file, so missing-warning checks apply to safety-relevant operations such as network/HTTP handling of user data. The FastAPI description states the service performs format conversion for AI agents, but there is no visible disclosure in the endpoint, comments, or surrounding description that submitted content is sent to and processed by the API, which may matter if users paste sensitive configuration or secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.