Back to skill

Security audit

A2A Vault

Security checks for vulnerabilities and agentic risk

Overview

This secrets-management skill is purpose-aligned, but it installs an unpinned external plugin that would handle highly sensitive credentials and gives limited safety guidance around importing, deleting, and injecting secrets.

Install only if you trust A2A Corp and the @a2a/openclaw-plugin package source. Before use, verify the package version, review what .env keys will be imported, confirm vault/environment/key names before deleting or promoting secrets, and inject secrets only into tools you trust not to log or forward them unexpectedly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Third-Party Plugin Introduces Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-17
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

yaml
"install":
  [
    {
      "id": "plugin",
      "kind": "node",
      "package": "@a2a/openclaw-plugin",
      "label": "Install A2A Corp plugin",
    },
  ],

Technical Analysis

The skill instructs the platform to install the external Node.js package @a2a/openclaw-plugin without specifying an exact version or package integrity hash. The package implementation is not included in the audited project, so its lifecycle scripts, network destinations, encryption implementation, and handling of retrieved credentials cannot be independently reviewed.

An unpinned package reference can resolve to a newer release after the skill has been audited. If the package publisher account, registry distribution channel, or a future release is compromised, the installed code could differ materially from the version originally expected. This is particularly sensitive because the documented plugin operations include reading, storing, retrieving, and injecting secrets.

The audit did not establish that the named package is currently malicious. The confirmed weakness is the absence of dependency version and integrity controls in a security-sensitive installation path.

Attack Path

  1. An attacker compromises the package publisher, publication credentials, registry path, or a future package release.
  2. The attacker publishes a modified version of @a2a/openclaw-plugin.
  3. A user installs or reinstalls the skill after the malicious release becomes the version selected by the package resolver.
  4. The platform downloads and executes the unreviewed package, including any applicable installation lifecycle code.
  5. When the documented PassBox operations are used, the compromised plugin may gain access to local environment secrets, retrieved vault values, authentic ...[truncated 783 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @a2a/openclaw-plugin to an exact, reviewed version rather than allowing implicit resolution to the latest compatible release.
  2. Enforce a cryptographic integrity value or lockfile so installation fails if the downloaded artifact differs from the audited package.
  3. Include the plugin source in the review scope or link the dependency to an immutable source revision and reproducible build.
  4. Audit package installation scripts and disable Node.js lifecycle scripts where they are unnecessary.
  5. Restrict the plugin through sandboxing, outbound-network allowlists, filesystem controls, and least-privilege access to vaults and local files.
  6. Require explicit user confirmation before reading or importing .env files, retrieving complete environments, or injecting credentials into another tool.
  7. Document and verify the plugin's remote endpoints, encryption protocol, key custody, secret retention, and logging behavior.
  8. Use automated dependency monitoring and require security review before upgrading the pinned package.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
| `passbox_list_environments` | List environments (dev, staging, prod) |
| `passbox_get_environment` | Get all secrets in an environment |

### .env Integration

| Tool | Description |
|------|-------------|

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
| `passbox_list_environments` | List environments (dev, staging, prod) |
| `passbox_get_environment` | Get all secrets in an environment |

### .env Integration

| Tool | Description |
|------|-------------|

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
| `passbox_list_environments` | List environments (dev, staging, prod) |
| `passbox_get_environment` | Get all secrets in an environment |

### .env Integration

| Tool | Description |
|------|-------------|

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
| `passbox_list_environments` | List environments (dev, staging, prod) |
| `passbox_get_environment` | Get all secrets in an environment |

### .env Integration

| Tool | Description |
|------|-------------|

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
| `passbox_list_environments` | List environments (dev, staging, prod) |
| `passbox_get_environment` | Get all secrets in an environment |

### .env Integration

| Tool | Description |
|------|-------------|

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents secret deletion as a routine operation but provides no warning about irreversibility, confirmation steps, or safeguards. In a secrets-management context, accidental deletion can cause service outages or loss of credentials, especially if users assume recovery is available.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The .env import workflow encourages reading and uploading local secrets without any privacy or data-handling warning. Even if the product uses client-side encryption, users may unintentionally import unnecessary, sensitive, or environment-mismatched credentials into a shared vault.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic credential injection into another tool is described as convenient but lacks an explicit warning that the receiving tool, its logs, prompts, subprocesses, or third-party APIs may expose the resolved secret. In a tool-chaining environment, downstream exposure is a real risk even if the vault itself is well designed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.