Back to skill

Security audit

Ephemo: Instant Agentic Hosting

Security checks for vulnerabilities and agentic risk

Overview

This hosting skill matches its stated purpose, but it can automatically publish local directories through mutable npm code with too little confirmation or upload scoping.

Install only if you are comfortable with an agent uploading selected files to a public Ephemo URL. Before use, confirm the exact directory, remove secrets and dotfiles, avoid broad project roots, prefer a clean build output folder, and be aware that cached Ephemo credentials can make deployments permanent.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:32
Finding

Unpinned Runtime Retrieval and Execution of a Mutable npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:17
Finding

Public Directory Upload Lacks Mandatory Secret Screening and Explicit Publication Approval

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill promotes instant publishing but does not present an upfront warning that local files will be made publicly accessible on the internet. Because the skill targets arbitrary directories and automation, the missing disclosure materially increases the risk of accidental data exposure, especially if users assume 'share' means a private or temporary local action.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill says to trigger 'universally' for very broad phrases like 'share this', 'publish this', or 'make a website'. In a hosting skill that uploads local directories to a public URL, overbroad activation can cause unintended publication of sensitive files or execution in contexts where the user did not clearly consent to public exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 15)May include surrounding context.

md
## How to Contribute

1. **Fork the repo** and create your branch from `main`.
2. **Modify the Skill:** Make your changes strictly within the `ephemo-agent-skill/` directory.
3. **Test it:** If you have OpenClaw installed, point your local workspace to your forked skill to verify the agent follows the new instructions.
4. **Pull Request:** Submit a clear PR description detailing what has improved in the agent's behavior.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill explicitly supports automated operation and describes persistent credential state via ~/.ephemo_credentials. In context, this creates session persistence that can silently convert anonymous temporary publishing into authenticated permanent publishing, increasing the risk of unintended durable exposure if the agent reuses cached credentials.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
**Skill version: 2.0.0**

Create a live URL from any directory containing static web files. Operations can be fully automated edge-to-edge.

## When to Use

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
- Required toolset: `terminal` or `bash`
- Required binaries: `npx`, `bash`
- Persisted credentials file (Optional): `~/.ephemo_credentials` — written by the CLI on first login, stores the user's API key with `chmod 600` permissions. Users can inspect or delete this file at any time.

**[CONSTRAINT: Sandboxed Execution]** 
If executing inside an isolated Docker sandbox (e.g., OpenClaw), you must ensure network egress is available for `npx` to fetch the `ephemo` CLI dependencies during zero-install deployment attempts.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill repeatedly instructs the agent to execute npx ephemo without pinning an exact package version. That causes runtime code to be fetched from the npm registry at execution time, creating a supply-chain risk where a newly published or compromised package version could run arbitrary code in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This command uses unpinned npx ephemo for update operations, so the agent may download and execute whatever version is current at the time. In an automated deployment skill, that enables registry compromise or malicious package takeover to become arbitrary code execution with access to local files being published.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Listing sites via npx ephemo list still performs code execution from an unpinned registry package. Even though the business action is lower risk than deploy, the installation path can still execute arbitrary code and access persisted credentials such as ~/.ephemo_credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The delete operation uses an unpinned npx ephemo package, exposing the agent to arbitrary code execution before a destructive command runs. Combining dynamic package fetch with deletion increases the blast radius because a compromised package could both exfiltrate credentials and delete or alter hosted assets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The delete operation is documented as immediately taking a site offline, but the skill does not require any user confirmation or safety check before destructive execution. In an agent setting, ambiguous instructions or mistaken slug selection could lead to irreversible service disruption.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The login flow relies on an unpinned npx ephemo login, which can execute unreviewed registry code during authentication. That is especially sensitive because the flow results in API key handling and persistence to a local credential file, making credential theft a realistic outcome of a supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill's general guidance to verify success after using npx ephemo still depends on the same unpinned execution model. In context, this is dangerous because the skill is user-invocable and intended for broad use, multiplying opportunities for registry-delivered malicious code to run.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.