Back to skill

Security audit

Nox Influencer - Creator Discovery & Influencer Marketing

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for NoxInfluencer marketing work, but it deserves review because it installs an unpinned third-party CLI that can perform authenticated outreach, CRM, export, and account operations.

Review the NoxInfluencer CLI package and prefer a pinned, trusted version before installing. Use a restricted NoxInfluencer account, keep credentials scoped and revocable, and require explicit confirmation before sends, schedules, exports, unlocks, CRM changes, product changes, or deletions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party CLI Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 4 and 84
Vulnerability Type: Supply-chain risk from a mutable npm dependency
Risk Level: Medium

Complete Code Snippet

yaml
metadata: {"openclaw":{"requires":{"bins":["noxinfluencer"]},"install":[{"kind":"node","package":"@noxinfluencer/cli","bins":["noxinfluencer"]}],"homepage":"https://www.noxinfluencer.com/skills"}}
markdown
1. No CLI or stale command tree → ask the user to install `@noxinfluencer/cli@latest`; verify with `schema --all`.

Technical Analysis

The Skill delegates its operational behavior to the third-party npm package @noxinfluencer/cli, but neither the installation metadata nor the setup instructions pin it to an exact audited version. The explicit use of the mutable @latest tag means that the package installed in the future may differ from the version assessed during this audit.

The Skill grants this CLI access to sensitive workflows, including locally persisted or environment-provided credentials, API-backed data, local file uploads, exports, CRM changes, and email or message delivery. Package installation may also execute npm lifecycle scripts unless the environment disables them.

This finding does not establish that the current package is malicious. It identifies a supply-chain weakness through which a compromised publisher account, registry incident, or malicious future release could alter the effective executable payload without any change to the reviewed Skill files.

Attack Path

  1. An attacker compromises the npm publisher account or another part of the package publication pipeline.
  2. The attacker publishes a malicious release of @noxinfluencer/cli and assigns it the latest distribution tag.
  3. A user or Agent follows the instruction at SKILL.md:84 and installs @noxinfluencer/cli@latest.
  4. Malicious lifecycle code may execute during installation, or malicious runtime code executes when the Agent invokes noxinfluencer. 5 ...[truncated 1154 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @noxinfluencer/cli to an exact version that has been reviewed, rather than using an omitted version or @latest.
  2. Commit a lockfile containing npm integrity hashes and require lockfile-enforced installation, such as npm ci.
  3. Verify package provenance, publisher identity, signatures, and registry source before installation.
  4. Disable npm lifecycle scripts during installation where compatible with the package, or separately review every required lifecycle script.
  5. Run the CLI with least privilege in a sandbox or restricted service account with only the necessary filesystem and network access.
  6. Keep credentials out of broadly inherited environments and use narrowly scoped, revocable credentials.
  7. Establish a controlled dependency-update process in which new versions are reviewed, tested, and explicitly approved before the pinned version changes.
  8. Monitor package ownership and release metadata for unexpected publisher, repository, or distribution-tag changes.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/brand-monitor.md (reported line 36)May include surrounding context.

md
- Product signal commands currently support `youtube` only. Do not call product signal commands for TikTok or Instagram unless a future schema explicitly shows support.
- Asset list commands are JSON-first. Use `--body-file` and inspect schema usage notes before building selectors.

## Output Rules

- Brand overview: report brand name, `brand_id`, access/data level, quota state, and obvious blockers.
- Matrices and strategy reads: summarize top rows and the decision implication; do not dump every normalized field.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest description advertises a very wide execution scope across search, analysis, contacts, monitoring, campaigns, CRM, outreach, exports, account setup, quota, and troubleshooting. In systems that use descriptions for tool selection, this breadth can lead to over-selection of a high-privilege skill, exposing operational and data-mutation capabilities in contexts where they are not necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill's 'When to Use' section uses very broad marketing-oriented trigger language, which can cause the agent to invoke this skill for loosely related requests beyond narrowly scoped NoxInfluencer operations. Over-broad routing increases the chance of unnecessary access to creator data, CRM, outreach, or export capabilities when a simpler or lower-privilege tool would suffice.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
### Workflow

1. Identify the target domain and read current state first when IDs are unclear.
2. For platform email outreach to creators found in NoxInfluencer, use the standalone email-task path and add recipients with search `data.items[].id` or creator read `data.creator_id` in the recipient `creator_id` field; do not retrieve contacts first. Use `platform + channel_id` only when the user already has that canonical raw platform identity. Standalone `email create/update` is type 3 only and must not include `campaign_id` or `task_type`. Manage intelligent Campaign fixed tasks in SaaS because the current CLI cannot discover or write them safely. Discover bound senders with `email sender list [task_id]`; never ask the user to inspect browser Network for sender IDs. See the CLI schema and `{baseDir}/references/marketing-ops.md`.
3. Use `message send` or `message schedule` only for existing `thread_id` replies. If no thread exists, offer the email-task path for platform creators. For an explicit whole-conversation archive, use `message archive`; never substitute `crm archive`.
4. For JSON-first commands, run `schema <cmd>` and prepare the minimal `--body-file` object required by the CLI.
5. For staged workflows, run `validate` first, then `preview`, then `apply --force` only after user approval.

Static analysis

No suspicious patterns detected.