Back to skill

Security audit

FiberAgent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed shopping cashback integration that calls FiberAgent APIs and returns tracked affiliate links, with no evidence of hidden persistence, exfiltration, or destructive behavior.

Before installing, be comfortable with a third-party shopping service receiving product queries, agent IDs, and wallet addresses, and with purchases through returned links being affiliate-tracked for crypto rewards and reputation. Prefer the reviewed local/ClawHub install path over the future unpinned npm command unless the package version and provenance are verified.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:14
Finding

Unpinned Third-Party Package Installation Instruction

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
index.js:21
Finding

Unvalidated Parameters Interpolated into API Request URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 9)May include surrounding context.

Option 1: Local (Instant)

bash
mkdir -p ~/.openclaw/workspace/skills
cp -r fiberagent ~/.openclaw/workspace/skills/
openclaw restart  # or restart OpenClaw gateway

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly describes returning tracked affiliate URLs and registering agents with wallet addresses through an external API, but it does not disclose tracking behavior, third-party data sharing, or consent expectations. In an agent context, this can cause users or operators to unknowingly send identifiers and shopping activity to a remote service, creating privacy, profiling, and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to send product queries to an external API but does not clearly warn that user shopping interests and search terms will be transmitted off-platform. This creates a privacy and transparency issue because users may disclose sensitive purchasing intent or preferences without informed consent, and the third party can log or profile that data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes affiliate links, wallet-linked earnings, and on-chain reputation but does not clearly warn users that clicks and purchases may be attributed to the agent wallet and tracked for compensation and reputation building. This is dangerous because it obscures a material financial incentive and creates undisclosed tracking of user purchase activity tied to a blockchain identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language task example encourages sending free-form intent and budget context to an external endpoint without warning that this user context leaves the local environment. Such context can contain sensitive personal or financial information, enabling unnecessary data exposure, third-party profiling, or retention beyond user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends user-linked identifiers and a wallet address to an external third-party service (fiberagent.shop) through search, stats, and registration requests without any visible consent, disclosure, minimization, or validation controls in the code. In an agent/tooling context, this is risky because users may not realize their agent ID and wallet address are being transmitted off-platform, enabling privacy leakage, profiling, and unintended exposure of sensitive financial identifiers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.