Back to skill

Security audit

Fieldy AI Webhook

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to connect Fieldy voice webhooks to Moltbot, but it persistently stores raw voice transcripts and exposes an agent-triggering webhook with under-scoped controls.

Review before installing. Use a dedicated low-privilege webhook token, prefer Authorization headers over query-string tokens, restrict and rate-limit the webhook, and keep the receiving agent least-privileged. Install only if you are comfortable with raw voice transcripts being stored locally, or modify the transform to disable logging, use a fixed protected log directory, set restrictive permissions, redact sensitive content, and add retention controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/fieldy-webhook.js:43
Finding

Unprotected Plaintext Storage of Sensitive Voice Transcripts

Content
View full analysis
/fieldy/transcripts/`, including transcripts that do not contain a wake word. The stored record includes the complete transcript, supplied timestamp, and speaker metadata. The code does not explicitly assign restrictive directory or file permissions, encrypt records, redact credentials or other sensitive content, limit file growth, or delete old records. Consequently, effective permissions depend on the process umask and surrounding workspace configuration. Transcript records can also remain available indefinitely and may be copied into backups. Voice transcripts may include personal data, authentication secrets, confidential business information, or private conversati ...[truncated 1539 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:61
Finding

Webhook Bearer Token Recommended in URL Query String

Content
View full analysis
` as documented. 2. A reverse proxy, webhook provider, monitoring service, command history, screenshot, or support export records the full URL. 3. An attacker obtains access to that record and extracts the webhook token. 4. The attacker sends a POST request to `/hooks/fieldy?token=` with a transcript such as `Fieldy `. 5. Moltbot accepts the valid token and invokes the transform ...[truncated 1080 chars]
Remediation
View remediation
` header and make header-based authentication the primary documented configuration. 2. Where supported, use signed webhook requests with a timestamp, request-body digest, and replay window instead of a static bearer token. 3. If a provider only supports query parameters: - Use a dedicated, randomly generated, narrowly scoped webhook secret. - Never reuse an account, API, or administrative token. - Redact query strings from reverse-proxy, load-balancer, application, tracing, and monitoring logs. - Restrict webhook requests by provider source addresses or authenticated network paths where practical. - Apply request-size limits, rate limits, and replay protections. - Rotate the token regularly and immediately after suspected exposure. 4. Prevent the webhook token from appearing in examples that users may copy into shell history without suitable precautions. 5. Keep the receiving agent least-privileged and require confirmation for consequential operations. 6. Treat all transcript-derived messages as untrusted input regardless of successful webhook authentication. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose only says the skill wires a webhook transform into hooks, but the behavior includes transcript logging, wake-word parsing, metadata handling, and environment/workspace discovery. This mismatch is dangerous because administrators may enable the skill expecting simple routing while actually deploying functionality that stores potentially sensitive speech transcripts and conditionally triggers an agent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope or permissions even though the described setup and referenced transform behavior imply access to environment/workspace context and local filesystem operations. Missing scope declarations reduce transparency and make it harder for operators to evaluate what the skill can access, increasing the chance of overprivileged deployment or unsafe execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill notes that non-wake-word transcripts are logged to JSONL files, but it does not present this as a prominent privacy/security warning despite the data potentially containing sensitive spoken content. Silent or weakly disclosed retention of non-triggering audio transcripts can create an unexpected local surveillance/logging risk and broaden exposure in case of host compromise.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

Example request (adjust host/port and token):

bash
curl -X POST "http://127.0.0.1:18789/hooks/fieldy" \
  -H "Authorization: Bearer insert-your-token" \
  -H "Content-Type: application/json" \
  -d '{"transcript":"Hey Fieldy summarize this: hello world"}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code probes environment and filesystem state to discover a workspace and then uses that location to store transcript archives, capabilities broader than a simple transform requires. In a skill-processing context, this expands access to local filesystem structure and can cause sensitive data to be written into an inferred workspace without explicit user consent or a fixed trusted path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill persistently writes raw transcript content and speaker metadata to workspace files even though its stated purpose is a webhook transform into hooks. This creates an unnecessary data-retention surface for potentially sensitive voice content, increasing the risk of privacy exposure, accidental disclosure, or later misuse if the workspace is shared, synced, or exfiltrated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.