Back to skill

Security audit

Facebook Fanpage Inbox for Meta Business Suite

Security checks for vulnerabilities and agentic risk

Overview

This skill fits its Facebook inbox purpose, but it needs review because it can read customer messages, send replies, modify inbox metadata, store sensitive conversation links, download customer media, and close unrelated browser tabs.

Review before installing. Use it only for business pages you are authorized to manage, keep config.json and any saved conversation URLs out of shared folders and repositories, and require explicit approval before sending replies, changing labels or notes, deleting notes, or downloading customer images. The tab cleanup instructions should be changed to close only tabs the skill opened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:98
Finding

Unscoped Browser Tab Destruction in Shared OpenClaw Profile

Content
View full analysis
" ``` ``` ### Technical Analysis The cleanup procedure instructs the agent to enumerate all tabs associated with the `openclaw` browser profile and close every tab other than a newly created blank tab. It does not restrict cleanup to the Facebook tab created by this skill. The browser profile is a shared resource that may contain tabs opened by users, other skills, or concurrent agent workflows. The skill already receives a unique `targetId` when it opens the Meta Business Suite page, so enumerating and closing unrelated targets is unnecessary and violates least-resource principles. This behavior does not grant operating-system privileges or access to additional accounts. However, it allows the skill to destructively modify browser state outside the legitimate scope of its Facebook inbox task. ### Attack Path 1. A user or another agent workflow opens one or more unrelated tabs in the `openclaw` browser profile. 2. The Facebook inbox skill is invoked to inspect or manage messages. 3. The skill opens its Meta Business Suite tab and performs the requested operation. 4. During cleanup, it opens a new `about:blank` tab. 5. It enumerates every tab in the shared profile. 6. Following the documented procedure, it closes all targets except the newest blank tab. 7. Unrelated tabs are destroyed, potentially interrupting other workflows and discarding unsaved browser state. No at ...[truncated 784 chars]
Remediation
View remediation
" ``` The skill should preserve every pre-existing tab and every tab whose ownership cannot be established. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose says the skill checks Facebook inbox messages and can be used to reply to customers via Meta Business Suite browser automation. However, the supplied code only performs setup/configuration: it collects Facebook inbox URLs and aliases from the user and stores them in a local JSON config file. There is no browser automation, no network access, no login/session handling, no reading of messages, and no reply functionality. While multi-page support with custom aliases is consistent with the description, the primary claimed functionality is not present in this code chunk, so this is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
node scripts/setup.js

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises very broad natural-language triggers such as 'Check Facebook inbox' and 'Reply to [customer name] on Facebook' without stating confirmation requirements, account/page scoping, or other activation guards. In an agentic environment, overly generic triggers can cause the skill to be invoked unintentionally for ambiguous requests, leading to access or actions on sensitive customer conversations that the user did not explicitly intend.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill instructs users to persist Meta Business inbox URLs in a local config.json file, which creates durable local storage of session-adjacent resource identifiers and page-specific access metadata. Although the URL shown does not itself contain a session token, persistent local storage of these identifiers can aid unauthorized access attempts, leak organizational account structure, and expose sensitive communication context if the workstation or repository is compromised.

Content

Scanner excerpt · README.md (reported line 53)May include surrounding context.

Manual Configuration

If you prefer to configure manually, create config.json:

json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explains local configuration and later states that conversation URLs can be stored and reused, but it does not clearly warn users that config.json and saved direct conversation URLs contain sensitive page identifiers and customer communication metadata. If stored insecurely or shared accidentally, these artifacts could expose inbox structure, page mappings, and direct links to customer threads, increasing privacy and operational risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says to use the skill when asked to 'check Facebook messages, reply to FB customers, or manage Facebook page inbox.' While Facebook-specific, 'reply to FB customers' and 'manage Facebook page inbox' are still broad operational triggers and the file does not provide negative examples or explicit boundaries for when the skill should not activate. This can increase the chance of unintended invocation for loosely related requests.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guidance to retain direct conversation URLs and customer-related note content for later reuse encourages persistence of sensitive customer-linked metadata outside the live inbox workflow. This increases the chance of inadvertent disclosure in logs, memory, files, or future prompts, especially because URLs and notes can encode identifiers and private business context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs downloading customer-shared images to the local filesystem with curl, which expands from browser-based inbox handling into writing untrusted external content onto the host. This creates risk of unnecessary local data retention, accidental exposure of sensitive customer media, and unsafe handling of attacker-controlled files/URLs outside the browser sandbox.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The curl-based image download guidance fetches external content and writes it locally without warning the user about network access, file creation, or privacy implications. Because the content originates from customers, this increases risk of storing sensitive media locally and handling attacker-controlled resources without adequate controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill contains step-by-step instructions to send messages on the user’s behalf without requiring an explicit confirmation checkpoint immediately before transmission. In an automation context, this can lead to unintended outbound communications, reputational harm, and unauthorized actions if the user’s request is ambiguous or misinterpreted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script programmatically extracts Facebook inbox chat metadata and message previews from the DOM, which are user communications and therefore sensitive data. In the context of a browser automation skill, this collection may be functionally intended, but without clear consent boundaries, minimization, or disclosure controls, it creates a privacy and data-exposure risk if invoked unexpectedly, logged, or forwarded to other components.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This script is designed to systematically harvest conversation text and image links from the Facebook page inbox, including customer messages, and return them in structured form. In the context of browser automation, that creates a real data-exfiltration surface: private customer communications can be extracted wholesale and propagated outside Meta Business Suite without meaningful technical safeguards, consent checks, or least-privilege controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script extracts message content and associated image metadata from a live Facebook inbox and returns it programmatically, which is sensitive third-party communication data. Even if this is the intended feature of the skill, collecting and exposing customer messages without clear user consent, scope limitation, or minimization creates a privacy and data-handling vulnerability if the output is misused, logged, or sent to an unintended recipient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The image-scraping logic gathers large fbcdn-hosted images from the Messenger UI and returns direct image URLs, which may expose customer-submitted media beyond the narrow task of checking messages. Media can contain highly sensitive personal or business information, and returning raw URLs increases the chance of downstream leakage through logs, prompts, or other tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The reporting format hard-codes Chinese status markers '[未讀/已讀]'. This imposes a language choice on output without opt-in, even though the rest of the file is mixed-language and no region-specific justification is provided. That can violate language or locale policy requiring user choice or documented constraints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill recommends storing direct conversation URLs in files or memory for later reuse, which introduces retention of customer-linked conversation identifiers beyond the immediate task. Those saved URLs can expose page IDs and thread identifiers and increase the chance of leakage, unauthorized reuse, or cross-task disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.