Back to skill

Security audit

Content Pipeline Provisioner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent content automation tool, but it asks for broad posting authority, persistent scheduled jobs, and sensitive credentials with weak scoping and secret-handling guidance.

Review this carefully before installing. Use separate scoped credentials per service and per brand, lock down or avoid ~/.openclaw/.env, do not store customer newsletter API keys as plain database text, verify the Larry dependency source and version, and keep all crons in test mode until you have reviewed exactly what each channel will publish.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
references/setup-checklist.md:7
Finding

Unpinned Third-Party Dependency Receives Access to Publishing Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:119
Finding

Centralized Plaintext Secret File Is Read with Excessive Credential Scope

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/supabase-schema.md:8
Finding

Customer Newsletter API Keys Are Modeled as Plaintext Database Fields

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description emphasizes convenience and self-hosting but does not prominently warn that it can schedule recurring automated posts, send newsletters, publish blog content, and message Telegram using the user's linked accounts. That missing disclosure increases the risk that a user invokes the skill without understanding it will create persistent, externally visible automation with reputational and operational consequences.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The access secret is a companion credential that can enable authenticated API use when paired with the token/key material. Because this skill orchestrates social posting at scale, leakage increases the blast radius from a single host compromise or accidental commit to full misuse of the posting integration.

Content

Scanner excerpt · references/setup-checklist.md (reported line 34)May include surrounding context.

md
## 2. Twitter/X API (direct posting — optional if using Postiz only)
1. Apply at developer.twitter.com
2. Basic tier required for posting ($100/mo) — OR use Postiz OAuth only (free, no direct API needed)
3. If using direct API: save API key, secret, access token, access secret to ~/.openclaw/.env

## 3. MailerLite (newsletter)
1. Create account at mailerlite.com (free up to 1,000 subscribers)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The access secret is a companion credential that can enable authenticated API use when paired with the token/key material. Because this skill orchestrates social posting at scale, leakage increases the blast radius from a single host compromise or accidental commit to full misuse of the posting integration.

Content

Scanner excerpt · references/setup-checklist.md (reported line 34)May include surrounding context.

md
## 2. Twitter/X API (direct posting — optional if using Postiz only)
1. Apply at developer.twitter.com
2. Basic tier required for posting ($100/mo) — OR use Postiz OAuth only (free, no direct API needed)
3. If using direct API: save API key, secret, access token, access secret to ~/.openclaw/.env

## 3. MailerLite (newsletter)
1. Create account at mailerlite.com (free up to 1,000 subscribers)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The access secret is a companion credential that can enable authenticated API use when paired with the token/key material. Because this skill orchestrates social posting at scale, leakage increases the blast radius from a single host compromise or accidental commit to full misuse of the posting integration.

Content

Scanner excerpt · references/setup-checklist.md (reported line 34)May include surrounding context.

md
## 2. Twitter/X API (direct posting — optional if using Postiz only)
1. Apply at developer.twitter.com
2. Basic tier required for posting ($100/mo) — OR use Postiz OAuth only (free, no direct API needed)
3. If using direct API: save API key, secret, access token, access secret to ~/.openclaw/.env

## 3. MailerLite (newsletter)
1. Create account at mailerlite.com (free up to 1,000 subscribers)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The checklist instructs users to store the Telegram bot token and chat ID in ~/.openclaw/.env without warning about sensitivity. A leaked bot token allows others to send messages as the bot, read/update bot interactions depending on configuration, and abuse the automation channel used for briefings.

Content

Scanner excerpt · references/setup-checklist.md (reported line 47)May include surrounding context.

md
1. Message @BotFather on Telegram → /newbot → follow prompts
2. Save the bot token
3. Get your chat ID: message your bot, then fetch https://api.telegram.org/bot{TOKEN}/getUpdates
4. Save TELEGRAM_BOT_TOKEN + TELEGRAM_CHAT_ID to ~/.openclaw/.env

## 5. OpenAI API (image generation for TikTok slides)
1. Get API key at platform.openai.com

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The OpenAI API key is directed into a plaintext .env file with no handling guidance. Exposure would let an attacker consume the account's quota, incur charges, and potentially access or generate content through the user's automation workflow.

Content

Scanner excerpt · references/setup-checklist.md (reported line 51)May include surrounding context.

md
## 5. OpenAI API (image generation for TikTok slides)
1. Get API key at platform.openai.com
2. Save OPENAI_API_KEY to ~/.openclaw/.env
3. Note: gpt-image-1.5 costs ~$0.04/image. ~30 images/month = ~$1.20/month per pipeline

## 6. Supabase + Netlify (blog publishing)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This instruction stores a Supabase service-role key and Netlify deploy hook in ~/.openclaw/.env. A Supabase service-role key is highly privileged and can bypass normal client restrictions, while a leaked Netlify deploy hook can trigger unauthorized site deployments; together they create a strong path to database abuse and malicious content publication.

Content

Scanner excerpt · references/setup-checklist.md (reported line 59)May include surrounding context.

md
2. Create blog_articles table — schema at references/blog-schema.md
3. Get service role key: Supabase → Settings → API → service_role key
4. Create Netlify site (or connect existing) and get deploy hook URL
5. Save SUPABASE_URL + SUPABASE_SERVICE_KEY + NETLIFY_DEPLOY_HOOK to ~/.openclaw/.env
6. Note: Blog publishing requires your site to be connected to Supabase — see references/blog-schema.md

## 7. Verify everything

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup-checklist.md (reported line 64)May include surrounding context.

md
## 7. Verify everything
Run: `node scripts/verify-setup.js` (coming soon — manual check for now)
Confirm each credential is in ~/.openclaw/.env or the relevant config file.

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest advertises very broad trigger phrases such as 'run my content engine', 'start posting for [product]', and 'go live [slug]', which can overlap with ordinary user requests and cause the skill to activate in situations where the user did not intend to authorize automated publishing. In this skill's context, accidental invocation is especially dangerous because downstream actions include provisioning cron jobs and eventually publishing to external social, newsletter, blog, and Telegram accounts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

Creating a new system folder from a template establishes persistent infrastructure for future automated operations, not just a transient response to the current request. That persistence becomes more dangerous here because the created directory is later used for cron-driven posting and publication workflows, amplifying the effect of any mistaken setup or abusive invocation.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

slug = productName.toLowerCase().replace(/[^a-z0-9]/g, '-').replace(/-+/g, '-') Example: "Echo Reviews" → "echo-reviews"

Step 3 — Create system folder

text
LARRY_ROOT = ~/[workspace]/99-External-Systems/skills/larry
SYSTEMS_DIR = {LARRY_ROOT}/tiktok-marketing/systems

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill persists user-provided brand data by writing config files and updating systems.json, creating durable state that can continue influencing future automated behavior beyond the current session. In this context, persistence is security-relevant because it is coupled to recurring automation and can silently survive later user context changes or misunderstandings.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
- Copy template: `cp -r {TEMPLATE_DIR} {NEW_DIR}`
- Write `{NEW_DIR}/config.json` using answers from Step 1. See `references/config-schema.md`.
- Write `{NEW_DIR}/voice.md` from brand voice + product description. See `references/voice-guide-template.md`.
- Add entry to `{LARRY_ROOT}/tiktok-marketing/systems.json`

### Step 3b — Generate Twitter config
Write `{LARRY_ROOT}/social/twitter/config.json` using the buyer's brand details.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions direct the agent to read sensitive secrets from ~/.openclaw/.env, including API keys and messaging tokens, but provide no privacy/security warning or minimization guidance. Even if the intended use is legitimate, instructing a skill to access a consolidated secret store raises the chance of over-collection, accidental disclosure, or use of credentials without fully informed consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/blog-schema.md (reported line 8)May include surrounding context.

Supabase Table: blog_articles

sql
create table blog_articles (
  id uuid default gen_random_uuid() primary key,
  created_at timestamptz default now(),
  title text not null,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation tells users to place a Supabase service-role key in a local .env file but does not clearly warn that this credential is highly privileged and bypasses normal row-level security controls. In a self-serve automation skill that provisions publishing infrastructure, this increases the chance users mishandle the secret, commit it, expose it to logs, or reuse it in unsafe contexts, leading to full database compromise.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/blog-schema.md (reported line 41)May include surrounding context.

text
SUPABASE_URL=https://your-project.supabase.co
SUPABASE_SERVICE_KEY=your-service-role-key
NETLIFY_DEPLOY_HOOK=https://api.netlify.com/build_hooks/your-hook-id
  • SUPABASE_URL: Project Settings → API → Project URL

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-checklist.md (reported line 24)May include surrounding context.

md
---

## 1. Postiz (TikTok + Twitter scheduling)
1. Create account at postiz.com (free plan works for 1 channel, paid for multiple)
2. Connect your TikTok account: Postiz dashboard → Channels → Add Channel → TikTok
3. Connect your Twitter/X account: Postiz dashboard → Channels → Add Channel → Twitter
4. Get your API key: Postiz dashboard → Settings → API → Copy API key

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The checklist instructs users to place multiple sensitive credentials, including service-role and deploy-hook secrets, into local config files without any warning about least privilege, filesystem protections, git exclusion, or rotation. In a skill whose purpose is to automate posting and publishing across several services, compromise of these secrets could enable account takeover of automation channels and unauthorized publishing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/setup-checklist.md (reported line 46)May include surrounding context.

md
## 4. Telegram (briefings)
1. Message @BotFather on Telegram → /newbot → follow prompts
2. Save the bot token
3. Get your chat ID: message your bot, then fetch https://api.telegram.org/bot{TOKEN}/getUpdates
4. Save TELEGRAM_BOT_TOKEN + TELEGRAM_CHAT_ID to ~/.openclaw/.env

## 5. OpenAI API (image generation for TikTok slides)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This documentation explicitly instructs operators to use a Supabase service role key and indicates storage of customer-provided newsletter API keys in the same system. A service role key bypasses RLS and provides broad database access, so weak handling, unclear storage protections, or operator misuse could expose all client records and downstream third-party credentials; in a content automation skill that provisions posting infrastructure, those credentials are especially sensitive because they can be used to send mail or act on customer accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file describes generating example tweets that will 'seed the Twitter autoposter,' which implies downstream automated publishing behavior. The template and instructions do not include any warning about review, approval, or the risks of unintended public posting, which is a user-impacting behavior covered by missing-warning criteria for markdown files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documentation states that publishing will POST to a Netlify deploy hook and trigger a rebuild, but it does not clearly frame this as an externally triggered side effect users should explicitly expect before enabling automation. In an automated content pipeline, unexpected rebuilds can cause unplanned deployments, cost, or availability disruption if the hook is triggered too often or misused.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.