Back to skill

Security audit

Tautullu

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Tautulli/Plex monitoring skill; it accesses sensitive viewing data by design, so users should protect the API key and outputs.

Install only for a Tautulli instance you are authorized to monitor. Prefer HTTPS for TAUTULLI_URL, avoid sharing command output because it may reveal viewing habits and usernames, keep the API key restricted, and rotate it if it has been exposed in logs or over plaintext HTTP.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/activity.sh:4
Finding

Tautulli API Key Exposed in Request URLs and Potentially Plaintext HTTP Traffic

Content
View full analysis
``` ``` `README.md:28-38`: ```markdown Set environment variables in your OpenClaw config (`~/.openclaw/openclaw.json`): ```json { "env": { "vars": { "TAUTULLI_URL": "http://192.168.1.100:8181", "TAUTULLI_API_KEY": "your-api-key-here" } } } ``` ``` ### Technical Analysis All six scripts place `TAUTULLI_API_KEY` directly in the request query string. Query-string credentials can be exposed through process inspection while `curl` is running, rever ...[truncated 2387 chars]
Remediation
View remediation
&2 exit 1 ;; esac ``` 2. **Avoid query-string credentials where supported** - If the deployed Tautulli API version supports authentication through a request header or POST body, use that mechanism instead of `apikey` in the URL. - If query-string authentication is unavoidable, clearly document that complete URLs must not be logged and that the key may be visible in process arguments. 3. **Harden `curl` invocation** - Use options that report HTTP failures and constrain permitted protocols, such as: ```bash curl --silent --show-error --fail --proto '=https' \ "$TAUTULLI_URL/api/v2?apikey=$TAUTULLI_API_KEY&cmd=get_activity" ``` - Where loopback HTTP must remain supported, select protocol restrictions based on a separately validated URL rather than allowing arbitrary schemes. 4. **Reduce credential exposure** - Redact the `apikey` parameter from reverse-proxy, Tautulli, monitoring, and diagnostic logs. - Prevent untrusted users from reading application configuration containing `TAUTULLI_API_KEY`. - Use a restricted API credential if Tautulli supports permission scoping. - Rotate the key immediately if it may already have appeared in logs or traversed an untrusted plaintext network. 5. **Improve documentation** - State that viewing activity and history are sensitive information. - Recommend trusted certificates and HTTPS for all non-loopback deployments. - Explain the residual logging risk if Tautulli requires query-string API authentication. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly promotes checking who is watching, viewing watch history, and user watch-time statistics, which involves potentially sensitive behavioral data. Without any privacy notice, access-control guidance, or consent considerations, the documentation normalizes surveillance-style use and may lead operators to expose or misuse personal viewing activity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes shell scripts but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent may execute shell-capable behavior without clear least-privilege constraints, increasing the risk of unintended command execution or broader access than the user expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill exposes Tautulli activity, watch history, user stats, and server information, all of which can reveal sensitive behavioral and account data about Plex users. Omitting a warning about this sensitivity increases the chance that users invoke the skill without understanding that it may disclose private viewing activity or metadata to the agent or downstream logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends the Tautulli API key and viewing-history query as URL query parameters in an outbound HTTP request. If TAUTULLI_URL is configured with plain HTTP, or if request URLs are logged by proxies, shells, process monitors, or server logs, the API key and potentially sensitive activity data can be exposed without any warning to the user; the skill context increases concern because it handles personal media-viewing history.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script performs an HTTP request and includes the sensitive TAUTULLI_API_KEY directly in the request URL, but there is no confirmation prompt, visible disclosure, or explanatory comment warning the user that credentials will be transmitted. For a code file, network transmission of sensitive data should have some form of user disclosure unless it is clearly documented as the skill's stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script reads the sensitive environment variable TAUTULLI_API_KEY and transmits it via a curl request, but there is no confirmation prompt, warning, or explanatory comment indicating that credentials and request data will be sent over the network. This is a safety-relevant operation for a code file under the missing user warnings rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L04 makes a network request to an external service and includes a sensitive credential in the request URL, but the script provides no confirmation prompt, warning, or explanatory comment about this behavior. For code files, outbound transmission of system data or credentials without any disclosure matches the missing user warnings criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L4 performs a network call and includes the TAUTULLI_API_KEY credential in the request, but the script provides no confirmation prompt, logging, comment, or other user-facing disclosure about transmitting credentials and retrieving account data. For a code file, this matches the missing-warning criterion for network/data access and sensitive environment variable usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.