Back to skill

Security audit

Synology Surveillance

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it handles surveillance-system credentials and camera controls in ways users should review carefully before installing.

Install only if you are comfortable giving an agent credentialed access to your Synology cameras. Use a dedicated least-privilege Surveillance Station account, avoid admin credentials, keep 2FA enabled where possible, require HTTPS, do not store the password in TOOLS.md, and be aware that snapshot, record, PTZ, and preset commands can capture images or change live camera behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/syno-surveillance.sh:4
Finding

Insecure Credential Transport and Predictable Session Cookie Storage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill recommends disabling 2FA for the API user without any warning or compensating controls. In a surveillance context, weakening authentication for camera access materially increases the risk of unauthorized viewing, recording control, event monitoring, or broader compromise of the NAS account if credentials are stolen.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples explicitly show HTTP usage and include credentials in URL query strings. This is dangerous because credentials may be exposed over the network in cleartext when HTTP is used, and query-string secrets are commonly captured in shell history, logs, proxies, monitoring systems, and browser or server access logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script sends credentials in a URL query string to the Synology login endpoint, which can expose the username and password via process listings, shell history, intermediary logs, reverse proxies, or server access logs. In addition, BASE_URL="http${SYNO_HTTPS:+s}://..." enables HTTPS whenever SYNOLOGY_HTTPS is set to any non-empty value, which contradicts the help text and can lead to unsafe operator assumptions about transport security configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README describes the skill entirely in German ('OpenClaw Skill für Synology Surveillance Station - Steuere Kameras über die Web API') with no indication that users can choose another language or that the skill is intentionally limited to German-speaking users. This can violate language/locale policy when a skill imposes a language without explicit opt-in or documented justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents shell-based execution (./scripts/..., curl) but does not declare any explicit tool scope such as allowed tools or permissions. This creates an authorization and review gap: users or orchestration systems cannot clearly constrain what execution capabilities the skill expects, which increases the chance of unintended shell access or overbroad execution in an agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to place host, username, and password directly into TOOLS.md, but gives no guidance on secrets handling, storage restrictions, or redaction. This encourages credential sprawl in plaintext documentation files that may be synced, committed, logged, or exposed to other tools and agents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation shows credential submission via a GET request and later explicitly states that 2FA must be disabled for the API user, but it does not clearly warn about the security consequences. Using GET can expose credentials in logs, browser history, and intermediary systems when misused, and recommending 2FA disablement reduces account protection for a system that controls surveillance cameras and recordings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The snapshot operation creates a JPEG file on local storage containing surveillance imagery, which can be privacy-sensitive user data. Although the code prints the filename after success, there is no prior warning or documented disclosure that invoking this command stores camera images on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The record command starts or stops recording, and the script also supports PTZ movement and preset changes, all of which can affect surveillance behavior or captured evidence. The help text describes the commands functionally but does not warn that they trigger live changes on the surveillance system or request confirmation before doing so.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file forces German-language instructions throughout without indicating that the skill is intentionally German-only or offering another language option. Under the stated policy, fixed language constraints should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Comments, help text, and user-facing messages are written in German, which imposes a specific language on users without any opt-in or documented locale constraint. This matches the policy category for language or locale restrictions expressed in natural language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.