Back to skill

Security audit

Venn Nino

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to connect to Venn enterprise tools, but its installer runs unverified code from a mutable third-party GitHub branch before handling sensitive SaaS access.

Review this carefully before installing. Only use it if you trust the third-party mcporter source and are comfortable with it building local executable code that can participate in OAuth-backed access to enterprise services. Prefer a version that pins a reviewed commit or signed release, validates the Venn URL, limits activation to explicit @venn requests, and clearly discloses the persistent files it creates.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install-vennporter.sh:17
Finding

Mutable Remote Source and Unverified Dependencies Are Downloaded and Executed

Content
View full analysis
/dev/null 2>&1; then pnpm install pnpm build else npm install npm run build fi ``` The installer is invoked by the automated setup configuration in `SKILL.md`, lines 25-27: ```yaml on_ready: - command: "bash ~/.openclaw/workspace/skills/venn/scripts/install-vennporter.sh" help: "Install/build vennporter (device_code-capable fork)" ``` ### Technical Analysis The installer clones the mutable `feat/device-code-grant` branch from a third-party GitHub repository rather than checking out a reviewed, immutable commit. On subsequent executions, `git pull --ff-only` retrieves the latest branch contents without signature, commit allowlist, or checksum verification. After retrieval, the script executes `pnpm install` or `npm install` and then runs the project's build command. Package installation can execute dependency lifecycle scripts, while the build command executes scripts defined by the remotely retrieved project. Consequently, the effective code executed on the host can change after this skill package has been audited. The script also does not enforce a verified dependency lockfile or an installation mode such as `npm ci`. The security of the resulting executable therefore depends on the continued integrity of the remote repository, its maintainer account, the package registry, and the complete transitive dependency graph. ### Attack Path 1. An attacker compromises the upstream repository, its maintainer account, the mutable branch, or a dependency selected during installation. 2. The att ...[truncated 1416 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:76
Finding

User-Controlled Setup URL Is Shown Interpolated into an Unquoted Shell Command

Content
View full analysis
--auth oauth --deviceCodeGrant`. 3. **Authenticate:** Follow Venn Authentication. 4. **Verify Health:** Run `~/.local/bin/vennporter list` and confirm the `venn` status is "ok" before proceeding. ``` ### Technical Analysis The instructions tell the agent to replace `` with a value supplied by the user and immediately run the resulting shell command. The placeholder is not quoted, and the instructions do not require URL validation or argument-safe process invocation. If an implementation performs direct textual substitution and passes the resulting command to a shell, shell metacharacters in the supplied value can terminate or alter the intended command. Characters such as semicolons, command substitutions, redirection operators, or shell control operators could cause additional commands to execute. Other examples in `SKILL.md` use the safer quoted form `"$VENN_UNIVERSAL_URL"`, but the vulnerable bootstrap instruction remains independently ambiguous and unsafe. Exploitation depends on the agent substituting the value into shell text rather than using a structured process-execution interface. ### Attack Path 1. During setup, an attacker or untrusted user supplies a purported Venn URL containing shell syntax. 2. The agent follows the bootstrap instruction and substitutes the supplied text directly for the unquoted `` placeholder. 3. The constructed command is passed to a shell. 4. The shell interprets embedded metacharacters rather ...[truncated 800 chars]
Remediation
View remediation
` interpolation pattern from the instructions. 2. Store the supplied value in `VENN_UNIVERSAL_URL` and pass it as a quoted argument: ```bash ~/.local/bin/vennporter config add venn --url "$VENN_UNIVERSAL_URL" --auth oauth --deviceCodeGrant ``` 3. Prefer a structured process-execution API that accepts an argument array and does not invoke a shell. 4. Validate the value before use. Require a syntactically valid HTTPS URL and, if operationally appropriate, restrict the hostname to an explicit allowlist of official Venn domains. 5. Reject URLs containing credentials, unexpected schemes, control characters, whitespace, or malformed hostnames. 6. Keep the validated value separate from command text and never use `eval`, shell concatenation, or textual placeholder substitution. 7. Make all setup examples consistent so that the agent receives only the quoted, validated execution pattern. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes multiple shell commands, including installation and authentication flows, but does not declare any explicit tool scope such as allowed-tools or permissions. That creates an overly broad execution surface where a caller or host may permit more command execution than is necessary, increasing the risk of unintended command use, environment abuse, or escalation through shell-enabled setup paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation rule is broad enough to trigger whenever the user asks about common services like Gmail, Jira, or Notion, even without explicitly intending to invoke this skill. In a skill that can authenticate to enterprise systems and perform dynamic tool discovery plus shell-backed operations, accidental activation can expose metadata, prompt unexpected auth/setup flows, or cause actions in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs a git clone/git pull from the network and then runs pnpm install or npm install followed by a build, all without any explicit warning or consent prompt. That behavior executes a large remote dependency tree and repository-controlled lifecycle/build scripts, which materially increases remote code execution and supply-chain risk during installation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer for a skill branded as Venn fetches and installs code from a different GitHub repository owned by a third party account (mansilladev/mcporter) and even pins to a feature branch rather than an official release. This creates a serious supply-chain trust gap: users may believe they are installing Venn-provided software, while actually executing unverified remote code that can change over time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script creates directories under ~/.local and writes an executable wrapper to ~/.local/bin/vennporter, changing the user's local environment. While these actions are part of an installer and there is a final 'Installed' message, there is no prior user-facing disclosure that files will be created or modified in these paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.