Back to skill

Security audit

openclaw-engine-mcp-setup

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for setting up a finance MCP server, but it embeds a live-looking shared credential and asks users to persistently trust a third-party service without enough safeguards.

Review before installing. Only use this skill if you trust the operator of the MCP endpoint and are comfortable sending financial strategy inputs to it. Replace the embedded credential with individually provisioned credentials, store secrets securely, and make sure you know how to disable the server entry and revoke access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Hard-Coded Shared MCP Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-32
Vulnerability Type: Hard-coded credentials in configuration documentation
Risk Level: Medium

Vulnerable Code

json
"mcp": {
  "servers": {
    "engine_mcp_server": {
      "url": "https://mcp.hzyotoy.com/engine/mcp",
      "headers": {
        "Authorization": "Aksk Mu4OfFXJSPyWXGv3",
        "appid": "mcpclient001"
      }
    }
  }
}

The same credential-bearing configuration is duplicated at lines 52-66.

Technical Analysis

The Skill embeds a reusable authorization value and application identifier directly in its configuration instructions. Any person who can access the Skill can extract these values and submit requests to the configured MCP endpoint under the shared client identity.

Static shared credentials provide poor isolation and attribution. Rotation requires modifying every deployed configuration, while revoking the credential can disrupt all users who copied the example. The credential's exact server-side permissions cannot be established from the audited file, so access beyond the privileges granted to this identity is not asserted.

Attack Path

  1. An attacker obtains a copy of SKILL.md.
  2. The attacker extracts the Authorization and appid header values.
  3. The attacker sends requests directly to https://mcp.hzyotoy.com/engine/mcp with those headers.
  4. If the server still accepts the credential, requests are processed under the shared client identity.
  5. The attacker can consume or misuse whatever MCP functionality, quota, and data access that identity is authorized to use.

Impact Assessment

Successful exploitation could permit unauthorized use of the MCP service within the exposed credential's existing privilege scope. Potential effects include quota consumption, service abuse, weak request attribution, exposure of resources accessible to the shared identity, and operational disr ...[truncated 175 chars]

Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed authorization credential.
  2. Remove all live credentials from SKILL.md and its configuration examples.
  3. Replace secret values with explicit placeholders, such as ${ENGINE_MCP_TOKEN} and ${ENGINE_MCP_APP_ID}.
  4. Require each installation or user to obtain an individual credential through a trusted provisioning process.
  5. Store secrets in a protected secret manager, operating-system credential store, or environment variable rather than source-controlled files.
  6. Use short-lived, narrowly scoped tokens with server-side expiration and revocation support.
  7. Apply rate limits, audit logging, and per-client attribution at the MCP service.
  8. Review service logs for unauthorized use of the exposed identity.
  9. Add automated secret scanning to the publication or review workflow to prevent recurrence.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:52
Finding

Persistent Third-Party MCP Integration Lacks Trust and Data-Handling Safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 52-76
Vulnerability Type: Unsafe external service configuration and trust-boundary expansion
Risk Level: Medium

Vulnerable Code

json
{
  "commands": {
    "mcp": true
  },
  "mcp": {
    "servers": {
      "engine_mcp_server": {
        "url": "https://mcp.hzyotoy.com/engine/mcp",
        "headers": {
          "Authorization": "Aksk Mu4OfFXJSPyWXGv3",
          "appid": "mcpclient001"
        }
      }
    }
  }
}

The subsequent validation instructions direct the user to confirm that the server is registered and invoke an MCP tool:

text
1. Check whether commands.mcp is true in the main configuration file
2. Check whether mcp.servers contains engine_mcp_server
3. Try invoking an MCP tool to confirm that the configuration is effective

Technical Analysis

The Skill directs users to enable MCP globally, persistently register a fixed third-party endpoint, restart OpenClaw, and invoke tools exposed through that endpoint. This expands the agent's trust boundary from local configuration to a remotely operated service.

The audited instructions do not provide a method to verify endpoint ownership, describe transmitted information and retention practices, constrain which remote tools may be used, require informed approval before sensitive calls, or provide credential revocation and server-removal procedures. TLS protects transport when correctly validated, but it does not establish that the service operator is trustworthy or that returned tool results are accurate.

Later examples in the file submit financial strategy expressions, contract codes, date ranges, capital assumptions, and execution metadata to the remote tool. Consequently, following the instructions may disclose strategy-related information to the endpoint operator. A compromised or untrusted endpoint could also provide inaccurate or manipulated tool ...[truncated 1310 chars]

Remediation
View remediation

Remediation Suggestions

  1. Document the service operator, official endpoint, intended functionality, and data-retention policy.
  2. Provide a trusted method for users to verify the endpoint before registration.
  3. Require explicit, informed user approval before adding the persistent MCP server.
  4. Require separate approval before transmitting confidential strategies or other sensitive financial data.
  5. Clearly enumerate the fields sent to the service and warn users not to submit proprietary information unless authorized.
  6. Restrict access to the minimum set of required tools and data fields.
  7. Use individual, least-privilege credentials rather than a shared identity.
  8. Validate tool responses and present remote financial results as untrusted data rather than authoritative instructions.
  9. Add clear procedures for disabling MCP, removing the server entry, and revoking credentials.
  10. Consider a user-configurable endpoint instead of silently prescribing a fixed third-party service, while applying an explicit allowlist where appropriate.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill embeds a concrete Authorization credential directly in documentation and configuration examples, which can lead users or agents to deploy a real secret into configs, logs, prompts, or version control. Because this skill’s purpose is only to enable MCP and add a server config, hardcoding a live-looking credential is unnecessary and materially increases the risk of credential leakage and unauthorized access to the remote MCP service.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The markdown explicitly publishes and encourages reuse of concrete authorization credentials without any warning about secret handling. This promotes insecure operational behavior: users may copy the credential into plaintext configs, share it in tickets, or commit it to repositories, causing credential compromise and downstream abuse of the MCP endpoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file largely presents content in Chinese but embeds an English invocation description ('Invoke when user wants...') as the activation guidance. This creates a language policy concern because it imposes mixed-language behavior without documenting language preference, opt-in, or locale scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.