Back to skill

Security audit

MiniMax MCP Call

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended for MiniMax web search and image analysis, but it uses risky installation and runtime patterns that can expose more local secrets and execute more third-party code than users may expect.

Review this skill before installing. It may be acceptable if you trust MiniMax, the uv installer source, and the minimax-coding-plan-mcp package, but avoid placing unrelated secrets in ~/.openclaw/.env, prefer safer verified installation of uv, and pin or review the MCP package before allowing it to run locally.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:20
Finding

Mutable remote installer scripts are executed directly by command interpreters

Content
View full analysis

Vulnerability Details

File Location: README.md:20-25; duplicated for Unix-like systems in SKILL.md:25-28
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code

README.md:20-25:

bash
# macOS / Linux
curl -LsSf https://astral.sh/uv/install.sh | sh

# Windows
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

SKILL.md:25-28:

bash
1. Install uv:
```bash
curl -LsSf https://astral.sh/uv/install.sh | sh
text

### Technical Analysis

Both installation methods retrieve mutable content from an external URL and pass it directly to a command interpreter. The downloaded payload is not pinned to a reviewed version and is not verified using a cryptographic digest or publisher signature before execution.

The PowerShell command additionally uses `-ExecutionPolicy ByPass`, removing a local policy barrier for the downloaded script. Although `astral.sh` is presented as the official source for `uv`, direct interpreter piping leaves execution dependent on the continuing integrity of the remote publication infrastructure, DNS resolution, TLS trust chain, and upstream account security. The effective code can change after this Skill package has been reviewed.

This behavior is used to install a declared prerequisite, but it is not the least-risk installation method and exceeds what is necessary because verified, versioned installation mechanisms can be used instead.

### Attack Path

1. An attacker compromises the remote installer publication process, hosting account, domain, or another relevant distribution dependency.
2. The attacker replaces the installer response with commands of their choice.
3. A user follows the documented setup command.
4. `sh` or PowerShell immediately interprets the response without presenting it for review or checking a pinned digest.
5. The attacker's commands execute with all
...[truncated 622 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove all curl | sh and irm | iex installation instructions.
  • Direct users to a trusted operating-system package manager with an explicitly pinned package version where possible.
  • Otherwise, download a versioned release artifact to disk without executing it.
  • Verify the artifact against a hardcoded SHA-256 digest or a trusted publisher signature obtained through an independently authenticated channel.
  • Present the verified script for inspection before execution.
  • Do not use PowerShell execution-policy bypasses in installation instructions.
  • Document that installation must occur without administrative privileges unless a specific platform package manager requires elevation.

T08 · Insecure Dependencies

Error
Location
scripts/mcp_client.mjs:18
Finding

Unpinned third-party MCP package is executed at runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/mcp_client.mjs:18-25
Vulnerability Type: Unpinned executable dependency and supply-chain exposure
Risk Level: High

Vulnerable Code

js
function initMcpServer() {
  return new Promise((resolve, reject) => {
    mcpProcess = spawn("uvx", ["minimax-coding-plan-mcp", "-y"], {
      env: {
        ...process.env,
        MINIMAX_API_KEY: API_KEY,
        MINIMAX_API_HOST: API_HOST,
      },
      stdio: ["pipe", "pipe", "pipe"],

Technical Analysis

The client launches minimax-coding-plan-mcp by package name without pinning an exact reviewed version or integrity digest. The dependency is not included in the audited project, and no lockfile or hash is provided. Consequently, the implementation executed by uvx may differ from the version intended by the Skill author or the version available during this audit.

Because the package is launched as a local child process rather than isolated as a remote service, its code receives the invoking user's local execution privileges. It also receives an environment containing the MiniMax credential and all other inherited environment variables.

This dependency is related to the declared MCP functionality, but resolving and executing an unpinned release is not necessary. An exact reviewed release can be pinned and integrity-verified.

Attack Path

  1. An attacker compromises the upstream package publisher, package repository, release process, or a dependency of the MCP package.
  2. A malicious or compromised release becomes the version resolved for minimax-coding-plan-mcp.
  3. The user invokes mcp_search.sh, which starts mcp_client.mjs.
  4. The client asks uvx to resolve and execute the unpinned package.
  5. The compromised package runs locally with the user's permissions and receives the child-process environment.
  6. It can access local resources or transmit available credentials before retu ...[truncated 576 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin minimax-coding-plan-mcp to an exact reviewed version rather than resolving it by an unversioned package name.
  • Maintain a lockfile containing cryptographic hashes for the package and its transitive dependencies.
  • Restrict package resolution to an explicitly trusted package index.
  • Prefer installing the reviewed dependency during a controlled setup phase rather than dynamically obtaining executable code whenever the Skill runs.
  • Consider vendoring the reviewed MCP server artifact if its licensing and update process permit this.
  • Add a documented dependency-update process requiring source review, integrity verification, and security testing.
  • Combine dependency pinning with a minimal child-process environment so a compromised component cannot automatically access unrelated credentials.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mcp_search.sh:4
Finding

Shared environment file is unsafely parsed and all inherited secrets are forwarded to the MCP child process

Content
View full analysis

Vulnerability Details

File Location: scripts/mcp_search.sh:4-7 and scripts/mcp_client.mjs:19-24
Vulnerability Type: Overbroad credential exposure and unsafe environment-file parsing
Risk Level: High

Vulnerable Code

scripts/mcp_search.sh:4-7:

bash
# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

scripts/mcp_client.mjs:19-24:

js
    mcpProcess = spawn("uvx", ["minimax-coding-plan-mcp", "-y"], {
      env: {
        ...process.env,
        MINIMAX_API_KEY: API_KEY,
        MINIMAX_API_HOST: API_HOST,
      },

Technical Analysis

The shell wrapper reads the shared ~/.openclaw/.env file and exports every whitespace-delimited assignment it contains. The Skill only requires MINIMAX_API_KEY and MINIMAX_API_HOST, so importing unrelated variables exceeds the minimum privileges necessary for its declared functionality.

Using export $(cat ... | xargs) is not a valid or robust dotenv parser. xargs transforms quoting, whitespace, and special-character handling, so values containing spaces or shell-sensitive characters may be corrupted or divided into unintended words. The file path is also unquoted in the cat command, although ordinary $HOME paths generally do not contain whitespace.

The Node.js client then spreads the complete process.env into the environment of the unpinned MCP process. As a result, unrelated credentials from the shared OpenClaw environment file and the parent process become readable by third-party package code. Only the MiniMax API key, API host, and a small set of runtime variables are needed.

Attack Path

  1. The user's ~/.openclaw/.env contains the MiniMax key and unrelated credentials used by other Skills or services.
  2. The wrapper imports every parsed entry into its process environment.
  3. The Node.js process inherits those variables.
  4. The client ...[truncated 1216 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove export $(cat "$HOME/.openclaw/.env" | xargs).
  • Use a strict dotenv parser and read only MINIMAX_API_KEY and MINIMAX_API_HOST.
  • Prefer a Skill-specific credential file or operating-system credential store rather than a shared environment file containing secrets for unrelated components.
  • Create credential files with mode 600 before writing secrets. Add the restrictive permission instruction to SKILL.md, where it is currently omitted.
  • Construct an explicit child environment containing only required runtime entries, such as a controlled PATH, locale variables if needed, MINIMAX_API_KEY, and MINIMAX_API_HOST.
  • Do not use { ...process.env } when spawning third-party executable code.
  • Validate MINIMAX_API_HOST against an expected HTTPS origin or an explicit administrator-controlled allowlist.
  • Avoid appending duplicate credential entries with repeated echo >>; provide an idempotent configuration mechanism that safely updates only the intended keys.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (19)

Chaining Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

Piping network-fetched content directly into sh is a classic command-chaining anti-pattern that turns a remote content source into immediate code execution. This is especially dangerous in setup documentation because users often run it with minimal scrutiny, and any compromise of the source or a malicious redirect could fully compromise the local environment. The skill context increases danger because this is framed as a prerequisite for using the tool.

Content

Scanner excerpt · README.md (reported line 22)May include surrounding context.

bash
# macOS / Linux
curl -LsSf https://astral.sh/uv/install.sh | sh

# Windows
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The explicit '| sh' construct creates a direct command chain from network input to code execution, removing any opportunity for validation before execution. In a skill context, this is more dangerous because users may treat setup instructions as trusted and run them verbatim, enabling supply-chain compromise or malicious content delivery.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

  1. Install uv:
bash
curl -LsSf https://astral.sh/uv/install.sh | sh
  1. Configure API key:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

md
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

md
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

md
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/mcp_search.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/mcp_search.sh (reported line 6)May include surrounding context.

sh
#!/bin/bash
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
73% confidence
Finding

Using export $(cat $HOME/.openclaw/.env | xargs) unsafely ingests and exports all entries from the file, not just the intended API key. This can misparse values containing spaces or shell-significant characters, accidentally expose unrelated secrets to the child Node process, and create reliability and secret-scope issues beyond the skill's stated web-search purpose.

Content

Scanner excerpt · scripts/mcp_search.sh (reported line 5)May include surrounding context.

sh
# Easy wrapper for MiniMax MCP web search

# Load env from ~/.openclaw/.env
if [ -f "$HOME/.openclaw/.env" ]; then
    export $(cat $HOME/.openclaw/.env | xargs)
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

Add to ~/.openclaw/.env

echo 'MINIMAX_API_KEY=your-coding-plan-key' >> ~/.openclaw/.env echo 'MINIMAX_API_HOST=https://api.minimaxi.com' >> ~/.openclaw/.env chmod 600 ~/.openclaw/.env

text

## Usage

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script launches an external package via uvx, which executes code outside this repository and expands the trust boundary from a simple client wrapper to whatever the resolved MCP package does at runtime. That is risky because the spawned package can perform arbitrary subprocess, filesystem, or network actions under the user's privileges, and the skill description understates that behavior as only web search/image analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The subprocess is spawned with ...process.env, forwarding the full parent environment to an external tool. This can expose unrelated secrets, tokens, proxy settings, and credentials to the child process or any dependency it loads, which is especially dangerous because the child is a network-capable externally sourced package.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The tool forwards user-provided search queries and image URLs to an external MCP service without any explicit runtime disclosure or consent mechanism. In a skill designed for web search and image understanding, outbound transmission is expected, but it still creates privacy and data-handling risk if users provide sensitive prompts, internal URLs, or confidential image locations.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The README instructs users to fetch and execute a remote install script directly with curl ... | sh, which bypasses meaningful review of the downloaded code. If the remote host, network path, or installation script is compromised, arbitrary code will run on the user's machine. Because this is an installation step in a developer tool skill, the likelihood of users copying it verbatim is high.

Content

Scanner excerpt · README.md (reported line 22)May include surrounding context.

bash
# macOS / Linux
curl -LsSf https://astral.sh/uv/install.sh | sh

# Windows
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

External Script Fetching

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The skill instructs users to fetch and execute a remote install script in one step via curl piped to sh. If the remote server, DNS, TLS trust chain, or delivery path is compromised, arbitrary code will run immediately on the user's system with the user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

  1. Install uv:
bash
curl -LsSf https://astral.sh/uv/install.sh | sh
  1. Configure API key:

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes a MiniMax MCP tool for web search and image understanding, but this wrapper additionally reads environment variables from a specific local file in the user's home directory. While obtaining an API key is necessary, hard-coding access to ~/.openclaw/.env is a broader local-file access capability that is not stated in the skill purpose and is not required if credentials are already provided by the runtime.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/mcp_client.mjs:19