Back to skill

Security audit

Clawhub Publish

Security checks for vulnerabilities and agentic risk

Overview

This Vercel deployment skill includes useful deployment steps, but it also gives broad production and security-control-changing instructions that need careful review before use.

Review this skill carefully before installing. It should not be allowed to auto-run production deploys or remove Vercel access protections unless you explicitly request that exact action, verify the target project, and understand that protected content may become public. Prefer Vercel's normal login/CLI flows or a dedicated secrets manager instead of pasting tokens into chat.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:27
Finding

Vercel Access Token Requested Through Conversation Content

Content
View full analysis
"Open vercel.com/account/tokens → Create Token → copy it and send it here. You only need to do this once." 2. Once received, verify: ```bash export VERCEL_TOKEN= vercel whoami ``` 3. Store securely — do NOT write the token to `~/.zshrc` or any file. Keep it in env for this session only, or ask the user to add it to their secrets manager. ``` ### Technical Analysis The skill explicitly instructs the user to send a Vercel access token through the conversation. Access tokens are bearer credentials: possession is generally sufficient to exercise the permissions granted to the token. Although the skill subsequently recommends keeping the token in an environment variable, that does not address the initial disclosure. Before being exported, the token has already entered the conversation and may consequently be retained in chat history, agent traces, application logs, monitoring systems, or other infrastructure that processes prompts. This design contradicts the principle that secrets should only be entered through dedicated secret-input channels. The absence of hardcoding does not make the workflow secure because the credential is still transmitted as plaintext conversation content. ### Attack Path 1. A headless agent activates the skill for a Vercel-related task. 2. The skill asks the user to create a Vercel token and send it through the conversation. 3. The user submits the bearer token as ordinary message content. 4. The token becomes available to systems or personnel with access to conversation records, logs, traces, or prompt-processing infrastructure. 5. An unauthorized party retrieves the token and uses it with the Vercel CLI or API. 6. The party performs any proj ...[truncated 635 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.md:100
Finding

Local Credential Extraction Used to Disable Multiple Deployment Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata describes broad auto-activation for any Vercel-related task, which can cause it to engage in situations where the user did not intend deployment or production changes. Overbroad activation raises the risk of unauthorized or premature operational actions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Triggers like 'landing page', 'update site', or any mention of Vercel are ambiguous and likely to match ordinary discussion. In the context of a skill that edits files and deploys to production, ambiguous activation materially increases the chance of unintended changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as a deployment helper, but it includes instructions to disable SSO, password protection, and trusted IP restrictions on a Vercel project. That expands its scope from deployment into security-control removal, which can expose protected sites publicly and materially weaken the user's security posture.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions to null out 'ssoProtection', 'passwordProtection', and 'trustedIps' remove access controls without any explicit warning about the security consequences. This can turn a restricted site into a publicly accessible one and bypass intended administrative safeguards.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill reads a local Vercel CLI auth token from the user's filesystem and reuses it in direct API calls. Accessing stored credentials outside the minimum needed deployment flow increases the chance of secret misuse and enables unauthorized administrative actions beyond the stated purpose.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 33)May include surrounding context.

→ In OpenClaw or any headless agent:

  1. Tell the user:

    "Open vercel.com/account/tokens → Create Token → copy it and send it here. You only need to do this once."

  2. Once received, verify:
bash
export VERCEL_TOKEN=<token>

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says tokens should remain only in session memory and not be written to files, but later instructs reading a token from a local auth file. This inconsistency normalizes accessing persisted secrets despite earlier guidance, which can mislead users about credential handling and weaken trust boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs direct file modification as the default behavior without a corresponding warning that this changes project contents. In an auto-activating skill, silent write behavior can lead to unintended local changes, broken content, or deployment of unreviewed edits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The deploy workflow targets production using 'vercel deploy --yes --prod' and post-deploy live-site verification, but it lacks a clear warning that it will modify a public production system. Automatic or insufficiently gated production deployment can cause service disruption, content errors, or accidental exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This command transmits a bearer token to the Vercel API to perform a privileged project update. Although contacting the vendor API is expected in a deploy-related skill, here the request is used for security-setting changes rather than core deployment, making the transmission more sensitive and risky.

Content

Scanner excerpt · skill.md (reported line 115)May include surrounding context.

md
TOKEN=$(python3 -c "import json; print(json.load(open('$HOME/Library/Application Support/com.vercel.cli/auth.json'))['token'])")

# For personal accounts:
curl -s -X PATCH "https://api.vercel.com/v9/projects/$PROJECT_ID" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"ssoProtection":null,"passwordProtection":null,"trustedIps":null}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This command transmits a bearer token to the Vercel API to perform a privileged project update. Although contacting the vendor API is expected in a deploy-related skill, here the request is used for security-setting changes rather than core deployment, making the transmission more sensitive and risky.

Content

Scanner excerpt · skill.md (reported line 115)May include surrounding context.

md
TOKEN=$(python3 -c "import json; print(json.load(open('$HOME/Library/Application Support/com.vercel.cli/auth.json'))['token'])")

# For personal accounts:
curl -s -X PATCH "https://api.vercel.com/v9/projects/$PROJECT_ID" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"ssoProtection":null,"passwordProtection":null,"trustedIps":null}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 121)May include surrounding context.

md
-d '{"ssoProtection":null,"passwordProtection":null,"trustedIps":null}'

# For team accounts — add teamId:
curl -s -X PATCH "https://api.vercel.com/v9/projects/$PROJECT_ID?teamId=YOUR_TEAM_ID" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"ssoProtection":null,"passwordProtection":null,"trustedIps":null}'

Static analysis

No suspicious patterns detected.