Back to skill

Security audit

Map Content Dependencies Across Multiple Sources Automatically

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only content-audit skill whose API and OpenAI usage is disclosed and aligned with its purpose, though one troubleshooting command has unsafe variable guidance.

Install only if you are comfortable giving the agent access to your content export/API and sending content selected for semantic analysis to OpenAI. Do not copy the troubleshooting curl command as written; use a real API token variable for Authorization and keep CONTENT_SOURCE_URL only as the request URL.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
{"openclaw":{"requires":{"env":["OPENAI_API_KEY","CONTENT_SOURCE_URL"],"bins":["curl","jq"]},"os":["macos","linux","win32"],"files":["SKILL.md"],"emoji":"🗺️"}}

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill whenever a user needs 'content audit insights, editorial prioritization, or content fragility analysis for strategic planning,' which is a wide natural-language scope rather than a narrowly defined trigger. It does not provide explicit trigger phrases, exclusions, or negative examples to clarify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

text
I have a Notion database with 200+ articles, guides, and videos 
at https://api.notion.com/v1/databases/[DB_ID]/query.

Create a Content Criticality Score for each asset that factors in:
- Inbound links from other content

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The example sends an Authorization header to an external API using the wrong environment variable, which could cause users to transmit incorrect values in a credential context. In this skill, external requests are expected, but malformed auth guidance increases the risk of accidental data leakage, broken authentication, and unsafe copy-paste behavior.

Content

Scanner excerpt · SKILL.md (reported line 357)May include surrounding context.

md
- API response is in unexpected format

**Solutions**:
1. Verify API token: `curl -H "Authorization: Bearer $CONTENT_SOURCE_URL" https://api.example.com/posts`
2. Check content format: Skill expects `url`, `title`, `content` fields at minimum
3. Enable verbose logging: `--debug true`

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The limitation notes that the skill 'Works best with single-language libraries,' which introduces a language-related constraint. While framed as a limitation rather than a hard requirement, it does not offer a user choice, mitigation path, or clear region/compliance justification for the language preference.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The troubleshooting command incorrectly places CONTENT_SOURCE_URL in an Authorization Bearer header, which trains users to treat a URL-like value as a secret and may cause accidental disclosure of sensitive connection information or misuse of authentication flows. While the immediate impact is limited, misleading credential-handling examples in security-adjacent documentation can propagate unsafe operational practices.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.