Back to skill

Security audit

rankrat

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it runs mutable external installer and Docker images while handling broad website-account credentials and default write access.

Install only if you are comfortable granting this server broad access to your SEO, analytics, Tag Manager, Bing, and Cloudflare accounts. Prefer read-only mode for agents, bind HTTP to loopback or require the bearer token, and avoid the mutable installer/images unless you can pin and verify the exact release or digest you intend to run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/setup.md (reported line 291)May include surrounding context.

md
--pids-limit 16 --memory 64m --cpus 0.25 \
  --mount type=volume,src=rankrat-lighthouse-runtime,dst=/run/lighthouse \
  --entrypoint /bin/sh psyb0t/rankrat-lighthouse \
  -c 'chmod 1777 /run/lighthouse && touch /run/lighthouse/.initialized && chown -R 10001:10001 /run/lighthouse && chmod 0750 /run/lighthouse'
docker run --rm -d --name rankrat-lighthouse-worker --init --read-only \
  --user 10001:10001 --cap-drop=ALL --security-opt no-new-privileges:true \
  --pids-limit 256 --memory 2g --cpus 2 --shm-size 1g \

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documented docker run example executes psyb0t/rankrat without a version tag or digest, so users will pull whatever image currently backs latest. That creates a supply-chain risk: a future compromised, malicious, or simply breaking image could be fetched and run with network access plus mounted config, OAuth, state, and secret directories.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This HTTP deployment example also runs psyb0t/rankrat without a fixed tag or digest. Because this mode exposes a network service and mounts credential-related directories, an unexpected image update could introduce remote attack surface changes or credential-handling regressions that operators did not review.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup.md (reported line 124)May include surrounding context.

md
full Rankrat grant under `oauth/`. PageSpeed's separate API key is prompted at
the same time because that API does not use OAuth.

After storage, setup runs account readiness. It does not create site properties,
submit sitemaps/URLs, or send IndexNow notifications. Secret values are never
printed or written into `.env`.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The documentation instructs users to download and execute a remote installer script from GitHub. Even though it recommends reading the file first, this still creates a software supply-chain risk: if the upstream repository, branch, network path, or downloaded artifact is tampered with, users may execute attacker-controlled code locally or with elevated privileges.

Content

Scanner excerpt · references/setup.md (reported line 200)May include surrounding context.

(no root) or system-wide:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/rankrat/main/install.sh -o rankrat-install.sh
less rankrat-install.sh
bash rankrat-install.sh                # per-user   -> ~/.local/bin/rankrat
sudo bash rankrat-install.sh --system  # system-wide -> /usr/local/bin/rankrat

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The guide explicitly recommends sudo bash rankrat-install.sh --system, which executes a downloaded shell script as root. If the installer is malicious or compromised, the impact becomes full system compromise rather than user-level compromise.

Content

Scanner excerpt · references/setup.md (reported line 203)May include surrounding context.

curl -fsSL https://raw.githubusercontent.com/psyb0t/rankrat/main/install.sh -o rankrat-install.sh less rankrat-install.sh bash rankrat-install.sh # per-user -> ~/.local/bin/rankrat sudo bash rankrat-install.sh --system # system-wide -> /usr/local/bin/rankrat

text

The single public launcher is named `rankrat`; it is not duplicated into agent

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · references/setup.md (reported line 275)May include surrounding context.

md
The commands above use the writable default. Before mounting config writable,
verify that the resolved directory is owner-only, `boundaries.json` is not a
symlink, both are owned by the current UID, and the file is not group- or
world-writable. The public `rankrat` launcher performs those checks. The OpenClaw
launcher additionally rejects symlinked path components. For a read-only
caller, set `RANKRAT_READ_ONLY=true` and make only `/run/config` read-only.
Never make the provider-secret mount writable during normal service operation.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 291)May include surrounding context.

md
--pids-limit 16 --memory 64m --cpus 0.25 \
  --mount type=volume,src=rankrat-lighthouse-runtime,dst=/run/lighthouse \
  --entrypoint /bin/sh psyb0t/rankrat-lighthouse \
  -c 'chmod 1777 /run/lighthouse && touch /run/lighthouse/.initialized && chown -R 10001:10001 /run/lighthouse && chmod 0750 /run/lighthouse'
docker run --rm -d --name rankrat-lighthouse-worker --init --read-only \
  --user 10001:10001 --cap-drop=ALL --security-opt no-new-privileges:true \
  --pids-limit 256 --memory 2g --cpus 2 --shm-size 1g \

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 291)May include surrounding context.

md
--pids-limit 16 --memory 64m --cpus 0.25 \
  --mount type=volume,src=rankrat-lighthouse-runtime,dst=/run/lighthouse \
  --entrypoint /bin/sh psyb0t/rankrat-lighthouse \
  -c 'chmod 1777 /run/lighthouse && touch /run/lighthouse/.initialized && chown -R 10001:10001 /run/lighthouse && chmod 0750 /run/lighthouse'
docker run --rm -d --name rankrat-lighthouse-worker --init --read-only \
  --user 10001:10001 --cap-drop=ALL --security-opt no-new-privileges:true \
  --pids-limit 256 --memory 2g --cpus 2 --shm-size 1g \

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/setup.md (reported line 286)May include surrounding context.

bash
docker volume create rankrat-lighthouse-runtime
docker run --rm --network none --user 0:0 --read-only \
  --cap-drop=ALL --cap-add=CHOWN --cap-add=FOWNER \
  --security-opt no-new-privileges:true \
  --pids-limit 16 --memory 64m --cpus 0.25 \
  --mount type=volume,src=rankrat-lighthouse-runtime,dst=/run/lighthouse \

Static analysis

No suspicious patterns detected.