Back to skill

Security audit

tescmd

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Tesla/OpenClaw setup guide, but it asks users to install mutable external components and handle vehicle/gateway credentials without enough safety guidance.

Review carefully before installing. Prefer package-manager or signed-install methods over curl|sh, pin reviewed versions where possible, use a virtual environment for Python, avoid putting secrets on command lines, restrict permissions on ~/.config/tescmd files, and be prepared to rotate Tesla/OpenClaw credentials if they are exposed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:108
Finding

Unverified Remote Installation Script Executed Directly by Shell

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:124
Finding

Security-Critical Third-Party Packages Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` - For the OpenClaw plugin, use an exact supported version or immutable package digest if the package manager supports it. - Verify package signatures, provenance attestations, and publisher identity before installation. - Review and lock transitive dependencies. - Install the CLI inside a dedicated virtual environment rather than into the system Python environment. - Avoid administrative installation unless it is demonstrably required. - Document a controlled upgrade process in which new releases are reviewed before version pins are changed. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:224
Finding

Gateway and OAuth Secrets May Be Exposed Through Process Arguments and Plaintext Configuration

Content
View full analysis
--openclaw --openclaw-token ``` ```text | `--client-secret ` | MCP OAuth client secret | ``` ```bash These can be set in `~/.config/tescmd/.env`: TESLA_CLIENT_ID=your-client-id TESLA_CLIENT_SECRET=your-client-secret TESLA_VIN=5YJ3E1EA1NF000000 TESLA_REGION=na # na, eu, or cn OPENCLAW_GATEWAY_URL=ws://gateway.example.com:18789 OPENCLAW_GATEWAY_TOKEN=your-token TESLA_COMMAND_PROTOCOL=auto # auto, signed, or unsigned ``` ### Technical Analysis The guide permits gateway tokens and OAuth client secrets to be supplied as command-line arguments. Depending on the operating system and shell configuration, command arguments may be visible in process listings, diagnostic output, audit records, terminal logs, and shell history. The guide also directs users to store secrets in `~/.config/tescmd/.env`, but it does not require restrictive file permissions, describe encryption or keychain storage, warn against version-control inclusion, or provide token-rotation procedures. A plaintext secret file with permissive permissions can be read by other local users or processes operating under an account with access to the file. The project does not contain code that directly reads or exfiltrates these secrets, and storing application credentials is necessary for the declared integration. The security issue is the documented storage and transmission mechanism, which does not enforce least exposure. ### Attack Path #### Command-line exposure 1. The user launches `tescmd` with `--openclaw-token` or `--client-secret`. 2. The secret becomes part of the process argument vector and may also be retained in shell history. 3. A local process, user, monitoring agent, support bundle, or log collector ob ...[truncated 1352 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The guide recommends piping a remotely fetched script directly into sh, which removes the user's opportunity to inspect what will run and executes network-delivered code immediately. If the download source, DNS, TLS termination, or upstream distribution is compromised, this becomes instant arbitrary code execution on the host, especially dangerous in a setup flow that later handles Tesla and Gateway credentials.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

If not installed:

If not logged in:

bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
If missing, install it:
- macOS: `xcode-select --install`
- Linux: `sudo apt install git` or `sudo dnf install git`

#### Required: GitHub CLI (gh)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
If missing, install it:
- macOS: `xcode-select --install`
- Linux: `sudo apt install git` or `sudo dnf install git`

#### Required: GitHub CLI (gh)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

If not logged in:

bash
sudo tailscale up

Tell the user: "Please complete the Tailscale login in your browser if prompted."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup text states that the Gateway-issued authentication token is saved to ~/.config/tescmd/bridge.json, but it does not warn the user that this is a persistent credential that can be reused by anyone with local file access. In a vehicle-control integration, theft of that token could let an attacker reconnect a rogue node to the Gateway and access telemetry or command paths until the token is revoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides example environment variables for TESLA_CLIENT_SECRET and OPENCLAW_GATEWAY_TOKEN without any handling guidance, which normalizes placing long-lived secrets in a plaintext .env file. Those credentials can be exposed through shell history, backups, support bundles, source-control accidents, or weak permissions, and in this context they may enable vehicle API access and Gateway authentication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.