Back to skill

Security audit

fboc

Security checks for vulnerabilities and agentic risk

Overview

This is a real Facebook Page management skill, but it needs Review because it exposes Page tokens and can change live Facebook content with weak safeguards.

Install only if you are comfortable giving this skill a Facebook Page token that can publish, schedule, hide, or delete content. Use a test Page first, avoid pasting tokens into command lines or chats, rotate any token used with this version, and do not run the test or cron examples against a production Page without manual review.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
commands/post.js:19
Finding

Facebook Access Tokens Are Disclosed in Debug Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
commands/fb-post-setup.js:27
Finding

Setup Commands Expose Access Tokens Through Process Arguments and Console Output

Content
View full analysis
', 'Your Facebook Page ID') .argument('', 'Your Facebook Page Access Token') .argument('[page_name]', 'Optional: Your Page name') ``` ```js if (!pageId || !accessToken) { console.error('❌ Missing required arguments.'); console.error(''); console.error('Usage:'); console.error(' openclaw fb-post-setup [page_name]'); console.error(''); console.error('Example:'); console.error(' openclaw fb-post-setup "123456789" "EAAB...token..." "My Business Page"'); console.error(''); console.error('Get help:'); console.error(' openclaw fb-post-setup-help'); process.exit(1); } console.log('Configuration:'); console.log(` Page ID: ${pageId}`); console.log(` Access Token: ${accessToken.substring(0, 15)}...${accessToken.substring(accessToken.length - 5)}`); console.log(` Page Name: ${pageName || '(will fetch from API)'}`); ``` ### Technical Analysis The setup interface requires the Facebook token as a positional command-line argument. Command-line secrets can be exposed through: - Shell history files. - Process inspection utilities while the command is running. - OpenClaw command transcripts. - Terminal recording and audit systems. - Wrapper scripts and command telemetry. - Error reports that retain the original invocation. The command then prints the first 15 and final 5 characters of the token. Although this is not the complete credential, it is unnecessary sensitive-data disclosure and can assist token identification or correlation. ### Attack Path 1. A user follows the docum ...[truncated 742 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
commands/fb-post-setup.js:108
Finding

Facebook Access Tokens Are Stored in Plaintext Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
commands/fb-post-setup.js:70
Finding

Bearer Tokens Are Transmitted in Graph API URL Query Strings

Content
View full analysis
{ ``` Other representative occurrences include: ```js path: `/${page_id}/feed?limit=${limit}&filter=scheduled&access_token=${access_token}` ``` ```js path: `/${postId}?access_token=${access_token}` ``` ### Technical Analysis The requests use HTTPS and are sent to Facebook's official `graph.facebook.com` endpoint, so the behavior is necessary for the declared functionality and is not evidence of malicious exfiltration. However, bearer tokens are repeatedly embedded in URL query strings. URLs and request paths are more likely than headers to be retained by debugging tools, HTTP instrumentation, proxies, exception telemetry, and application logs. The actual full-path disclosure in `commands/post.js` demonstrates that this risk is realized elsewhere in the project. ### Attack Path 1. A command constructs a Graph API URL containing `access_token`. 2. A debugging layer, proxy, request logger, application exception, or terminal trace records the request path. 3. An attacker or unauthorized operator reads the retained request metadata. 4. The attacker extracts the token from the query string. 5. The attacker replays the credential against Facebook's Graph API. ### Impact Assessment The token can provide access to Page data and Page-management operations according to its granted scopes. Potential consequences include unauthorized content publication, scheduling, hiding, deletion, and engagement-data access. The exposure boundary includes every component that records complete request URLs or paths. ...[truncated 3 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
commands/fb-post-test.js:126
Finding

Connection Test Creates a Real Post and Can Leave It Published After Cleanup Failure

Content
View full analysis
{ let postData = ''; postRes.on('data', chunk => postData += chunk); postRes.on('end', () => { try { const postResult = JSON.parse(postData); if (postResult.id) { console.log(' ✅ Can create posts'); console.log(` 📝 Test post created: ${postResult.id}`); // Delete the test post const deleteOptions = { hostname: 'graph.facebook.com', path: `/${postResult.id}?access_token=${access_token}`, method: 'DELETE' }; const deleteReq = https.request(deleteOptions, (deleteRes) => { let deleteData = ''; deleteRes.on('data', chunk => deleteData += chunk); deleteRes.on('end', () => { try { const deleteResult = JSON.parse(deleteData); if (deleteResult.success) { console.log(' ✅ Can delete posts'); console.log(' 🗑️ Test post deleted'); } else { console.log(' ⚠️ Could not delete test post (may need additional permissions)'); } } catch (err) { console.error(' ⚠️ Error parsing delete response'); console.log(''); console.log('✅ Post capability verified (delete test skipped)'); ...[truncated 2024 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (71)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The command prints part of the Facebook access token and reveals its total length to standard output. Even partial credential disclosure is sensitive because terminal output may be captured in logs, shell history workflows, screenshots, CI output, or shared support sessions, increasing the risk of token compromise or aiding reconstruction/identification of the secret.

Content

Scanner excerpt · commands/config-show.js (reported line 30)May include surrounding context.

js
if (config.page_name) {
    console.log(`📄 Page Name: ${config.page_name}`);
  }
  console.log(`🔑 Access Token: ${config.access_token.substring(0, 15)}...${config.access_token.length} chars`);
  console.log(`📅 Created: ${new Date(config.created_at).toLocaleString()}`);
  console.log('\n💡 Commands:');
  console.log('   fb-post "<message>"              - Post text');

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The user access token is embedded directly in the request URL query string when requesting the page token. Putting credentials in URLs is risky because query strings are more likely to be captured in logs, proxies, monitoring systems, browser/history equivalents, or error messages, causing unintended token disclosure.

Content

Scanner excerpt · commands/delete-post.js (reported line 94)May include surrounding context.

js
console.log('🔄 Fetching Page Access Token...');

  try {
    // Step 1: Get Page Access Token using User Token
    const pageTokenResponse = await makeHttpsRequest(
      'GET',
      `/${page_id}?fields=access_token&access_token=${userToken}`,

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The script prints part of the access token to stdout, exposing a credential fragment in terminal scrollback, logs, CI output, or session recordings. Even partial token disclosure is unnecessary and increases the chance of credential leakage, especially when combined with other metadata or if token formats are predictable.

Content

Scanner excerpt · commands/fb-post-setup.js (reported line 54)May include surrounding context.

js
console.log('Configuration:');
    console.log(`  Page ID: ${pageId}`);
    console.log(`  Access Token: ${accessToken.substring(0, 15)}...${accessToken.substring(accessToken.length - 5)}`);
    console.log(`  Page Name: ${pageName || '(will fetch from API)'}`);
    console.log('');

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/help.js (reported line 69)May include surrounding context.

js
💡 Tips:
--------
- Access tokens may expire. Re-run setup if you get authentication errors.
- Use fb-post-test to verify your credentials before posting.
- Scheduled posts use server time (UTC).

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The code places the user access token directly into the URL query string when calling the Facebook Graph API. Tokens in URLs are dangerous because they can be captured in logs, proxies, browser/history equivalents, monitoring systems, error traces, or upstream infrastructure, resulting in credential disclosure and unauthorized Page actions.

Content

Scanner excerpt · commands/hide-post.js (reported line 94)May include surrounding context.

js
console.log('🔄 Fetching Page Access Token...');

  try {
    // Step 1: Get Page Access Token using User Token
    const pageTokenResponse = await makeHttpsRequest(
      'GET',
      `/${page_id}?fields=access_token&access_token=${userToken}`,

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The code sends the Facebook access token in the URL query string and explicitly requests the page's access_token field. Query-string credentials are more likely to be exposed through logs, error messages, proxies, browser/history capture, or downstream monitoring, and requesting token material when it is not needed increases credential exposure. In a CLI skill that stores and uses persistent page tokens, this raises the risk of token leakage and subsequent unauthorized access to the Facebook page.

Content

Scanner excerpt · commands/post-test.js (reported line 70)May include surrounding context.

js
}

  try {
    // Test 1: Verify access token and page access
    const pageInfo = await makeHttpsRequest(
      'GET',
      `/${page_id}?fields=id,name,access_token&access_token=${access_token}`,

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The code logs part of the page access token in the request path preview. Even partial credential disclosure is risky because logs are often broadly accessible, retained long-term, and aggregated externally; combined with other leaked context, this can aid token compromise and confirms the presence of a live secret.

Content

Scanner excerpt · commands/post.js (reported line 116)May include surrounding context.

js
const pageAccessToken = pageTokenResponse.access_token;
    console.log('✅ Page Access Token retrieved successfully.');

    // Step 2: Post using the Page Access Token
    console.log(`📝 Posting message: "${message}"`);
    console.log(`🔗 Request path: /${page_id}/feed?access_token=${pageAccessToken.substring(0, 20)}...`);
    console.log(`📦 Request body: { message: "${message}" }`);

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The manifest states that configuration is stored in a file containing page_id, access_token, and page_name, implying persistent storage of a sensitive access token. Storing long-lived API tokens in a local config file can lead to credential exposure through weak file permissions, backups, shell history during setup, or accidental sharing.

Content

Scanner excerpt · manifest.json (reported line 148)May include surrounding context.

json
"description": "Configuration file containing page_id, access_token, and page_name"
  },
  "security_notes": [
    "Never share your access token",
    "Page tokens last 60 days",
    "Regenerate if compromised",
    "Use Page tokens, not User tokens"

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
95% confidence
Finding

The package defines a postinstall hook that automatically launches PowerShell with ExecutionPolicy Bypass on Windows, causing code to run during installation without explicit user review. Even though this file does not itself show a network download, install-time script execution materially increases risk because it can execute arbitrary local bootstrap logic and is especially dangerous in an agent-skill/package ecosystem where installation may be automated.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
{
  "name": "facebook-advanced",
  "version": "1.0.0",
  "description": "Facebook Page management CLI for OpenClaw",
  "main": "bin/facebook-advanced",
  "dependencies": {
    "commander": "^12.0.0",
    "node-fetch": "^2.7.0"
  },
  "scripts": {
    "test": "echo \"Error: no test specified\" && exit 1",
    "postinstall": "if (process.platform === 'win32') { powershell.exe -ExecutionPolicy Bypass -File ./bin/setup.ps1 }"
  },
  "bin": {
    "facebook-advanced": "./bin/facebook-advanced"
  },
  "keywords": [
    "facebook",
    "graph-api",
    "pages",
    "posts",
    "comments",
    "openclaw"
  ],
  "author": "",
  "license": "MIT"
}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/fb-post-setup-help.js (reported line 139)May include surrounding context.

js
## Quick Start

### 1. Configure your access token

**Option A: Using facebook-config.json (Recommended)**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/fb-post-setup.js (reported line 90)May include surrounding context.

js
## Quick Start

### 1. Configure your access token

**Option A: Using facebook-config.json (Recommended)**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/fb-post-test.js (reported line 67)May include surrounding context.

js
## Quick Start

### 1. Configure your access token

**Option A: Using facebook-config.json (Recommended)**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/post-test.js (reported line 103)May include surrounding context.

js
## Quick Start

### 1. Configure your access token

**Option A: Using facebook-config.json (Recommended)**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/post-test.js (reported line 106)May include surrounding context.

js
## Quick Start

### 1. Configure your access token

**Option A: Using facebook-config.json (Recommended)**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · readme.md (reported line 7)May include surrounding context.

md
## Quick Start

### 1. Configure your access token

**Option A: Using facebook-config.json (Recommended)**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 176)May include surrounding context.

md
## Quick Start

### 1. Configure your access token

**Option A: Using facebook-config.json (Recommended)**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/delete-post.js (reported line 91)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/delete-post.js (reported line 103)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/delete-post.js (reported line 107)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/delete-post.js (reported line 157)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/delete-post.js (reported line 164)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/fb-post-setup-help.js (reported line 35)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/fb-post-setup-help.js (reported line 39)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/fb-post-setup.js (reported line 29)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · commands/help.js (reported line 53)May include surrounding context.

js
This skill is installed as an npm package. After cloning or installing:

```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"

# Make the script executable (if needed)

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:63

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skill.md:106