Back to skill

Security audit

render

Security checks for vulnerabilities and agentic risk

Overview

This Render deployment skill is purpose-aligned and explicitly requires user confirmation before live, billable, or destructive Render actions.

Install this only if you want Codex/OpenClaw to help manage Render deployments. Review every proposed live action carefully, especially service creation, redeploys, env-var replacement, destruction, plan changes, and anything that may incur cost or persist in your Render workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- Validate before push: `render blueprints validate render.yaml` or the Validate Blueprint API.
- Do not `git commit` / `git push` unless the user asked to deploy or confirmed the Blueprint file.
- New Key Value instances: `ipAllowList: []` unless the user asked for public access.
- Do not set continuous auto-deploy unless the user wants every push to go live.
- Sanitize user-supplied names before writing YAML.

## References

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
- Validate before push: `render blueprints validate render.yaml` or the Validate Blueprint API.
- Do not `git commit` / `git push` unless the user asked to deploy or confirmed the Blueprint file.
- New Key Value instances: `ipAllowList: []` unless the user asked for public access.
- Do not set continuous auto-deploy unless the user wants every push to go live.
- Sanitize user-supplied names before writing YAML.

## References

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
- Push to the linked branch when the user already enabled auto-deploy and wants this commit live.
- MCP: `trigger_deploy` (after yes).
- REST: `POST https://api.render.com/v1/services/{serviceId}/deploys` with `Authorization: Bearer $RENDER_API_KEY`. Optional body: `{ "clearCache": "do_not_clear" }` or `"clear"`.
- Deploy hook: `curl -X POST "$RENDER_DEPLOY_HOOK_URL"` only if the user provided the hook and confirmed this redeploy. Do not log the URL.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
MCP cannot create: workers, private services, Workflows, image-backed services. Use Blueprint or Dashboard for those.

Set the workspace first (`list_workspaces` / `get_selected_workspace`, or ask the user to pick one). Do not create in the first workspace returned without confirmation.

---

Static analysis

No suspicious patterns detected.