Back to skill

Security audit

Fox Veille

Security checks for vulnerabilities and agentic risk

Overview

This RSS digest skill is mostly coherent, but it needs Review because optional LLM and output features handle credentials with weak scoping and its feed fetching can reach poorly constrained network targets.

Review the configuration before enabling scoring, outputs, or cron. Keep LLM API keys in a dedicated secret file, use only trusted HTTPS LLM endpoints, avoid storing SMTP passwords in the general config when possible, verify file permissions on ~/.openclaw/config/veille/config.json, and only add RSS sources you trust to make network requests from your machine.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scorer.py:58
Finding

Arbitrary Credential File Exfiltration Through a Configurable LLM Endpoint

Content
View full analysis
str: """Read API key from the file specified in config. Security: warns if the key file has overly permissive filesystem permissions (world-readable). Recommended: chmod 600. """ key_file = Path(llm_cfg.get("api_key_file", "")).expanduser() if not key_file.exists(): raise FileNotFoundError(f"API key file not found: {key_file}") # Permission check (Unix only, skip silently on Windows) try: mode = key_file.stat().st_mode & 0o777 if mode & 0o044: # readable by group or others print(f"[scorer] WARNING: {key_file} has permissive mode {oct(mode)} " f"- recommend chmod 600", file=sys.stderr) except (OSError, AttributeError): pass # Windows or unsupported FS print(f"[scorer] reading API key from {key_file}", file=sys.stderr) return key_file.read_text(encoding="utf-8").strip() ``` ```python def _call_llm(prompt: str, llm_cfg: dict) -> list: """Call OpenAI-compatible API and return parsed scores list.""" api_key = _read_api_key(llm_cfg) base_url = llm_cfg.get("base_url", "https://api.openai.com/v1").rstrip("/") if not base_url.startswith("https://"): print(f"[scorer] WARNING: base_url is not HTTPS ({base_url}) — " f"API key will be sent in cleartext", file=sys.stderr) model = llm_cfg.get("model", "gpt-4o-mini") payload = json.dumps({ "model": model, "max_tokens": 2048, "messages": [{"role": "user", "content": prompt}], }).encode() req = urllib.request.Request( f"{base_url}/chat/completions", data=payload, headers={ "Authorization": f"Bearer {api_key}", "Content-Type": "a ...[truncated 2011 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/veille.py:203
Finding

Feed Fetching Is Vulnerable to Redirect- and DNS-Based SSRF

Content
View full analysis
bool: """Reject non-HTTP schemes and private/localhost targets.""" try: parsed = urlparse(url) except Exception: return False if parsed.scheme not in ("http", "https"): return False host = (parsed.hostname or "").lower() if host in ("localhost", ""): return False if any(host.startswith(p) for p in _PRIVATE_IP_PREFIXES): return False # Reject 172.16.0.0/12 if host.startswith("172."): parts = host.split(".") if len(parts) >= 2 and parts[1].isdigit() and 16 <= int(parts[1]) <= 31: return False return True ``` ```python def fetch_feed(source_name: str, url: str, hours: int, max_articles: int) -> list: """ Fetche et parse un flux RSS 2.0 ou Atom. Retourne une liste de dicts articles. """ if not _validate_feed_url(url): print(f"[WARN] {source_name}: blocked URL (non-HTTP or private target): {url}", file=sys.stderr) return [] req = urllib.request.Request(url, headers={"User-Agent": USER_AGENT}) try: def _do(): with urllib.request.urlopen(req, timeout=15) as resp: return resp.read() raw = with_retry(_do) ``` ### Technical Analysis The validator checks only the textual hostname supplied in the original URL. It does not resolve the hostname and verify that all resulting addresses are globally routable. Consequently, a normal-looking public hostname may resolve to loopback, private, link-local, reserved, or cloud metadata addresses. DNS rebinding may also cause the addre ...[truncated 1797 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init.py:85
Finding

Initialization Fetch Bypasses All Feed URL Security Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.py:80
Finding

Credential-Bearing Configuration Files Are Written Without Enforced Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (62)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 217)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 218)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 219)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 253)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 256)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 257)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 217)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 217)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 256)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 218)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

### Cross-config read (dispatch only)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 219)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

### Cross-config read (dispatch only)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 218)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

### Cross-config read (dispatch only)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 219)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

### Cross-config read (dispatch only)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 257)May include surrounding context.

md
| Path | Purpose | Cleared by uninstall |
|------|---------|----------------------|
| `~/.openclaw/config/veille/config.json` | Sources + settings + outputs | Manual (`rm -rf ~/.openclaw/config/veille`) |
| `~/.openclaw/data/veille/seen_urls.json` | URL dedup store (14d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |
| `~/.openclaw/data/veille/topic_seen.json` | Topic fingerprints (5d TTL) | Manual (`rm -rf ~/.openclaw/data/veille`) |

### Cross-config read (dispatch only)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 253)May include surrounding context.

bash
# Remove skill
clawhub remove veille   # or rm -rf ~/.openclaw/workspace/skills/veille

# Remove config + data (optional)
rm -rf ~/.openclaw/config/veille

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a full RSS aggregation and digest-dispatch skill with content processing and delivery features. The supplied code chunk does not implement any of those behaviors. It only provides a generic retry helper for transient network failures. While retry logic could be a supporting component inside such a system, this chunk by itself has a materially different primary purpose from the declared skill behavior, so this is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as a full RSS ingestion and processing system with deduplication, LLM scoring, and multi-channel dispatch. The supplied code chunk does not implement that pipeline. Instead, it is an init/validation utility: it checks for a config file, ensures a data directory exists, and fetches only the first configured source as a connectivity/parsing test. While the network fetch is loosely related to RSS handling, the primary purpose of this code is environment verification, not article aggregation and distribution. Therefore the code chunk materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents the skill as an operational RSS aggregation and dispatch engine. However, this code chunk is specifically a setup/admin utility, not the aggregator runtime. Its primary behavior is local configuration management: creating ~/.openclaw config/data directories, copying/writing config.json, toggling sources, editing categories and outputs, generating cron.json, reading OpenClaw config for Telegram token presence, and deleting persisted files with --cleanup. Those are materially different capabilities from fetching RSS feeds, deduplicating content, scoring with an LLM, and dispatching digests. While these setup tasks support the declared skill, the supplied chunk itself does not implement the declared primary purpose and adds undeclared cleanup/config-management behavior, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad end-to-end RSS aggregation and digest distribution skill. The supplied code chunk is much narrower: it performs topic-based deduplication of article titles, ranks sources by authority, checks duplicates against a historical local JSON store, and exposes a debug CLI. It does not fetch RSS feeds, invoke any LLM, send output anywhere, or use mail/Nextcloud integrations. While topic deduplication is one component of the declared purpose, the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 22)May include surrounding context.

text
   Reset if needed:
   ```bash
   rm ~/.openclaw/data/veille/seen_urls.json
  1. Feed URLs changed: Some sources change their RSS URL periodically.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 112)May include surrounding context.

text
   Reset if needed:
   ```bash
   rm ~/.openclaw/data/veille/seen_urls.json
  1. Feed URLs changed: Some sources change their RSS URL periodically.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 192)May include surrounding context.

Reset all stores:

bash
rm -f ~/.openclaw/data/veille/seen_urls.json
rm -f ~/.openclaw/data/veille/topic_seen.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/troubleshooting.md (reported line 193)May include surrounding context.

Reset all stores:

bash
rm -f ~/.openclaw/data/veille/seen_urls.json
rm -f ~/.openclaw/data/veille/topic_seen.json

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/dispatch.py (reported line 76)May include surrounding context.

python
_BLOCKED_PATH_PATTERNS = [
    ".ssh", ".gnupg", ".config/systemd", "crontab",
    "/etc/", ".bashrc", ".profile", ".bash_profile", ".zshrc",
    ".env",
]

_DEFAULT_ALLOWED_DIR = pathlib.Path.home() / ".openclaw"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/scorer.py (reported line 62)May include surrounding context.

python
"""Read API key from the file specified in config.

    Security: warns if the key file has overly permissive filesystem
    permissions (world-readable). Recommended: chmod 600.
    """
    key_file = Path(llm_cfg.get("api_key_file", "")).expanduser()
    if not key_file.exists():

Static analysis

Detected: suspicious.destructive_delete_command, suspicious.dynamic_code_execution

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
README.md:217

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/dispatch.py:89