Back to skill

Security audit

Copilot For Revit Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly meant to control Revit, but it gives an agent broad project-modifying authority through an unverified local bridge and plaintext network configuration with weak user-control boundaries.

Review before installing. Use only with trusted bridge code pinned to a known commit, restrict the Revit service to localhost, VPN, or another authenticated channel, enable command confirmation for writes and deletes, and test on backup or non-production Revit models first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/revit_call.py:30
Finding

Unpinned Third-Party Dependencies and Mutable Bridge Code Are Executed

Content
View full analysis

Vulnerability Details

File Location: scripts/revit_call.py:30-49; related installation guidance at SKILL.md:51,78
Vulnerability Type: Supply-chain exposure through unpinned dependencies and externally maintained executable code
Risk Level: High

Vulnerable Code

python
# Build the uv command
cmd_parts = [
    "uv", "run",
    "--with", "httpx",
    "--with", "click",
    "python", "-m", "openclaw_bridge.cli"
]

# Add the subcommand
cmd_parts.extend(command.split())

# Add arguments for a tools call
if "tools call" in command and args:
    cmd_parts.extend(["--args", json.dumps(args)])

try:
    result = subprocess.run(
        cmd_parts,
        cwd=BRIDGE_DIR,
        capture_output=True,
        text=True,
        timeout=60,
        env={**subprocess.os.environ, "REVIT_MCP_URL": REVIT_MCP_URL}
    )

The associated setup instructions execute an externally cloned repository without identifying a reviewed commit:

markdown
2. **Linux side** has installed openclaw-bridge (`git clone https://github.com/ryanchan720/openclaw-bridge`)
bash
uv run python -m openclaw_bridge.cli health

Technical Analysis

The wrapper executes the openclaw_bridge.cli module from the directory selected by OPENCLAW_BRIDGE_DIR. The documented installation process obtains that code from a mutable Git repository without pinning a commit, tag digest, or signed release.

The invocation also asks uv to provide httpx and click without version constraints or integrity hashes. Dependency resolution can therefore change after the Skill has been reviewed. A malicious or compromised upstream package release, package index, bridge repository, or update could introduce code that is executed automatically when the wrapper runs.

This is a supply-chain trust-boundary issue rather than evidence that the currently reviewed source is malicious. The reviewed project contains ...[truncated 1350 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin openclaw-bridge to a reviewed commit hash or a cryptographically signed, immutable release.
  2. Pin exact versions of httpx, click, and all transitive dependencies in a committed lockfile.
  3. Require package hashes and use a trusted, controlled package index where possible.
  4. Install dependencies into a dedicated virtual environment during a controlled installation phase instead of resolving them during each command invocation.
  5. Verify the bridge directory against an expected commit or artifact digest before execution.
  6. Run the bridge under a dedicated low-privilege account or sandbox with only the filesystem and network access required for Revit operations.
  7. Avoid forwarding the entire parent environment. Construct a minimal environment containing only required variables.
  8. Add dependency vulnerability scanning and reproducible-build checks to release validation.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/revit_call.py:15
Finding

Project-Modifying Revit Operations Are Configured Over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/revit_call.py:15-16,46-52; insecure remote endpoint example at SKILL.md:60-73 and README.md:30-34
Vulnerability Type: Unencrypted network transport for a state-changing remote control service
Risk Level: High

Vulnerable Code

python
# Configuration is read from the environment
REVIT_MCP_URL = os.environ.get("REVIT_MCP_URL", "http://localhost:18181")
BRIDGE_DIR = Path(os.environ.get("OPENCLAW_BRIDGE_DIR", Path.home() / "repos" / "openclaw-bridge"))
python
result = subprocess.run(
    cmd_parts,
    cwd=BRIDGE_DIR,
    capture_output=True,
    text=True,
    timeout=60,
    env={**subprocess.os.environ, "REVIT_MCP_URL": REVIT_MCP_URL}
)

The documentation recommends plaintext HTTP for a remote Windows host:

bash
export REVIT_MCP_URL="http://192.168.1.100:18181"
export OPENCLAW_BRIDGE_DIR="$HOME/repos/openclaw-bridge"

It also suggests a direct plaintext connectivity test:

bash
curl $REVIT_MCP_URL/sse

Technical Analysis

The Skill is explicitly capable of invoking Revit commands that modify project state, including changing parameters and deleting elements. Nevertheless, the default endpoint and documented remote deployment example use http://.

Plain HTTP does not provide transport confidentiality, endpoint authentication, or message integrity. The reviewed wrapper performs no scheme validation and passes the endpoint directly to the external bridge. No application-layer authentication, request signing, certificate validation, or replay protection is implemented in the reviewed project.

When the endpoint is loopback-only, exposure is more limited. However, the documentation explicitly recommends a private-network IP address, creating a network path across which requests and responses may be observed or modified. The absence of authentication in this project does not prove that the external bri ...[truncated 1624 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS for every non-loopback endpoint and reject remote http:// URLs during configuration validation.
  2. Use certificates issued by a trusted internal CA and preserve certificate and hostname verification.
  3. Prefer mutual TLS so both the bridge client and Revit service authenticate each other.
  4. If native HTTPS is unavailable, place the service behind a mutually authenticated VPN or SSH tunnel and bind the Revit service to loopback.
  5. Add application-layer authorization using short-lived credentials and narrowly scoped permissions.
  6. Sign requests or use a protocol that provides message integrity and replay protection.
  7. Restrict port 18181 through host firewalls and network access-control lists to approved clients only.
  8. Separate read-only tools from mutating tools and require explicit user confirmation for parameter changes, deletion, and other destructive operations.
  9. Log authenticated tool invocations and retain audit records containing the actor, tool name, target project, result, and timestamp.
  10. Update all examples and defaults so they do not encourage plaintext remote connections.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The usage example shows bulk modification of model data (changing all door heights) and reports the update as completed, but the markdown does not warn that the skill can alter project data or advise users to verify changes before use. For markdown files, this counts as missing disclosure about behavior that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill can access environment variables, make network requests, and invoke shell-based bridge commands, but its declared scope only lists network-access and does not clearly constrain command execution. In this context, the skill is explicitly capable of issuing state-changing Revit operations through a local bridge, so under-declared capabilities increase the chance of silent or overly broad execution beyond what operators expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is designed to auto-activate on general Revit-related intent, which can cause it to engage on ordinary design discussions rather than explicit operational requests. Because this skill can execute modifying commands against an active Revit project, broad activation raises the risk of unintended tool invocation and accidental project changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes very common BIM/domain terms such as walls, doors, windows, rooms, and also auto-activates on dynamically fetched tool names. This makes activation highly permissive and partially attacker-influenced via external tool enumeration, increasing the chance that unrelated conversation or manipulated tool metadata leads to execution of powerful Revit commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file-level natural-language documentation is written only in Chinese, which imposes a specific language on users without any opt-in or explanation of a region-specific requirement. The policy explicitly calls for flagging language or locale constraints when no user choice or justified limitation is provided.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

The code launches an external process via subprocess.run using command components partly influenced by user-controlled input through the tool name and arguments path, and it executes from a configurable working directory. Although shell injection is mitigated by passing a list and not using shell=True, invoking a Python module from an attacker-controlled directory can execute unintended code from a malicious openclaw_bridge package or project files.

Content

Scanner excerpt · scripts/revit_call.py (reported line 46)May include surrounding context.

python
cmd_parts.extend(["--args", json.dumps(args)])
    
    try:
        result = subprocess.run(
            cmd_parts,
            cwd=BRIDGE_DIR,
            capture_output=True,

Tainted flow: 'BRIDGE_DIR' from os.environ.get (line 16, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
96% confidence
Finding

OPENCLAW_BRIDGE_DIR is read from the environment and used as cwd for python -m openclaw_bridge.cli. If an attacker can influence that environment variable, they can point execution at a directory containing a malicious openclaw_bridge package or Python project metadata, leading to arbitrary code execution in the context of this skill. In an agent skill that automatically operates Revit, this becomes more dangerous because the code is designed to trigger local automation actions on the user's workstation.

Content

Scanner excerpt · scripts/revit_call.py (reported line 46)May include surrounding context.

python
cmd_parts.extend(["--args", json.dumps(args)])
    
    try:
        result = subprocess.run(
            cmd_parts,
            cwd=BRIDGE_DIR,
            capture_output=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The skill description and examples are presented entirely in Chinese, implying a fixed interaction language, but the file does not state that this is a region-specific skill or offer users any language/locale choice. This can be a natural-language policy issue when a specific language is effectively required without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.