Back to skill

Security audit

Gajago Sns

Security checks for vulnerabilities and agentic risk

Overview

This skill is broadly aligned with SNS content generation, but it exposes a Gemini API key and uses under-scoped local commands, background services, external downloads, and third-party sharing that users should review before installing.

Install only after the Gemini key is revoked and removed, paths and outputs are made user-configurable, external sharing through Telegram is opt-in, downloads are either bundled or integrity-checked, and the video scripts are changed to honor user-supplied inputs instead of hardcoded local files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:55
Finding

Hardcoded Gemini API Credential Exposed in Skill Documentation

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi uv run ~/.openclaw/workspace/skills/nano-banana-pro/scripts/generate_image.py \ --prompt "..." \ --filename "..." \ --resolution 2K ``` 5. Provision the value through a secret manager or protected deployment configuration. 6. Restrict the replacement key to only the required APIs, applications, environments, and quotas. 7. Add automated secret scanning to pre-commit and CI checks. 8. Replace documentation values with non-secret placeholders such as `${GEMINI_API_KEY}`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
autoresearch-gajago-sns/dashboard.html:168
Finding

Stored DOM-Based Cross-Site Scripting in Research Dashboard

Content
View full analysis
` ${e.id} ${e.score}/${e.max_score} ${e.pass_rate.toFixed(1)}% ${e.status} ${e.description} `).join(''); // Eval breakdown const evalDiv = document.getElementById('evalBreakdown'); evalDiv.innerHTML = data.eval_breakdown.map(ev => { const pct = ev.total > 0 ? (ev.pass_count / ev.total * 100) : 0; return `
${ev.name}
${pct.toFixed(0)}%
`; }).join(''); ``` The data is loaded from an adjacent JSON file: ```javascript async function fetchData() { try { const r = await fetch('results.json?t=' + Date.now()); return await r.json(); } catch(e) { return INLINE_DATA; } } ``` ### Technical Analysis The dashboard retrieves `results.json` and directly interpolates its properties into HTML strings assigned to `innerHTML`. No escaping, sanitization, schema validation, or allowlisting is performed. Attacker-controlled values such as `description`, `status`, or `name` can therefore terminate their intended HTML context and inject active markup. Event-handler payloads are a practical execution mechanism because scripts inserted directly through `innerHTML` may not execute consistently, while injected elements with event handlers can execute when loaded or interacted with. The `status` field is used in both visible content and a CSS class attribute, creating an additional attribute ...[truncated 1688 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
autoresearch-gajago-sns/dashboard.html:7
Finding

Externally Hosted JavaScript Loaded Without Subresource Integrity

Content
View full analysis
``` ### Technical Analysis The dashboard loads Chart.js from a third-party CDN and executes it with the same browser privileges as the dashboard's own JavaScript. The URL pins version `4.4.1`, which reduces accidental version drift, but the element does not provide a Subresource Integrity hash. Without SRI, the browser verifies only that the resource was delivered over HTTPS; it does not verify that the response matches a specific reviewed file. If the CDN, package publication account, upstream artifact, or relevant delivery infrastructure were compromised, modified JavaScript could be served and executed when the dashboard loads. No evidence was found that the referenced Chart.js version is malicious or currently compromised. This finding concerns the absence of integrity enforcement for executable third-party content. ### Attack Path 1. An attacker compromises the CDN response path, the hosted package artifact, or another relevant upstream supply-chain component. 2. The external Chart.js URL begins returning modified JavaScript. 3. A user opens the dashboard while connected to the network. 4. The browser downloads and executes the modified script because no integrity hash is supplied. 5. The payload executes in the dashboard origin and can interact with the page and same-origin resources available to that browser context. ### Impact Assessment A successful upstream compromise could provide arbitrary JavaScript execution in the dashboard's browser context. Potential effects include falsifying audit results, reading accessible same-origin data, issuing requests available to the user, or redirecting the page. This issue does not grant operating-system pr ...[truncated 161 chars]
Remediation
View remediation
``` 3. Verify the hash independently against the exact reviewed file rather than copying an untrusted value. 4. Use a restrictive Content Security Policy that permits scripts only from approved locations and disallows unsafe inline execution after moving inline code to a separate file. 5. Monitor dependency advisories and periodically review pinned third-party assets. 6. Ensure offline or integrity-check failures stop script execution rather than silently switching to an unverified source. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a command-driven automation skill that ingests user inputs and produces multiple SNS assets: platform-specific copy, images, and a 20-second video. The supplied code only covers one narrow part of that promise: assembling a 20-second video. Even that behavior is not dynamic—it uses hardcoded photo paths, hardcoded scene text, fixed dimensions, fixed timing, and fixed output naming. There is no command handling, no parsing of /가자고, no intake of text/keywords/images from a user, and no generation of Instagram/Facebook/Band copy. The code also does not output standalone images for SNS use. Therefore the implementation materially under-delivers and behaves as a specific local video production script rather than the broader interactive SNS content auto-generation skill described.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declaration describes an interactive automation flow that, when triggered by /가자고, takes user-provided text/keywords/images and produces platform-specific SNS copy, images, and a 20-second video. The supplied code does only one narrow task: it renders a pre-scripted 20-second promotional slideshow video from five hardcoded inbound photos and five hardcoded scene captions, then combines it with a fixed local audio file via ffmpeg. There is no command handling, no parsing of user input, no text/copy generation for Instagram/Facebook/Band, and no generalized image generation pipeline. While video creation is part of the declared functionality, the implemented behavior is materially narrower and misses the core interactive multi-output SNS generation described.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains what appears to be a live Gemini API key embedded directly in the skill instructions. Hardcoded secrets are highly dangerous because anyone with access to the skill can reuse the credential, incur charges, access associated services, or pivot into broader compromise of connected systems.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly instructs shell execution, process launching, file writes, network access, and local script execution, but does not declare any tool scope or allowed-tools restrictions. This creates an over-privileged and under-specified skill boundary, making accidental or unauthorized command execution more likely if the agent runs it in a permissive environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill automatically creates and stores generated media files in fixed local paths without warning about persistence, naming, or storage location. This can expose sensitive or private user-provided images and generated content to other local users, backups, or later unintended reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill says generated images and copy will be sent via Telegram, but does not warn users that their supplied text and media may be transmitted to a third-party messaging platform. In a content workflow that may include photos and institution-related material, this creates a meaningful data-sharing and privacy risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs downloading third-party media from an external site at runtime, introducing unnecessary network dependency and supply-chain risk into a workflow that processes local content. If the remote resource changes, is replaced, or is maliciously served, the skill could ingest untrusted content without user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description and trigger specify only the Korean command '/가자고' and present the skill as operating in Korean without offering any language or locale alternative. This is a natural-language policy concern because the skill appears to require a specific language for activation rather than documenting an optional or justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="ko", which sets a specific language/locale for the interface. Under the policy, forcing a specific language without user opt-in or a clearly documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file prescribes Korean-specific fonts, Korean greetings, Korean text formatting, and channel copy rules as mandatory output behavior. While the organization is Korean, the skill does not explicitly state that Korean-only behavior is intentional, justified, or optional for users who may need another language.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

2단계: Gemini API로 카피 생성

bash
# 웹앱 API 호출
curl -s -X POST http://localhost:3000/api/copy \
  -H "Content-Type: application/json" \
  -d '{
    "text": "[입력내용]",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · autoresearch-gajago-sns/gajago-sns-v2.md (reported line 36)May include surrounding context.

2단계: Gemini API로 카피 생성

bash
# 웹앱 API 호출
curl -s -X POST http://localhost:3000/api/copy \
  -H "Content-Type: application/json" \
  -d '{
    "text": "[입력내용]",

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to start a local webapp process (npm run dev) if it is not already running, which expands behavior beyond simple content generation into process management and long-lived service execution. This increases risk because a chat-triggered skill can unexpectedly launch software, alter local system state, and expose a local service without explicit user consent or safety checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill transmits generated outputs via Telegram and references sharing via deployed web URLs, but it does not warn users that their input content and derived media may leave the local environment. This is dangerous because users may submit sensitive images or institutional text assuming local-only processing, resulting in unintended disclosure to external services or recipients.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill embeds a Gemini API key directly in the document and execution examples, exposing a live credential in plaintext. Hardcoded secrets are dangerous because anyone with access to the skill can reuse the credential, incur costs, access associated services, or pivot into other connected resources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill downloads background music from an external URL at runtime, adding unnecessary network access and external content retrieval to the workflow. This creates supply-chain and privacy risk, since the agent may contact third-party infrastructure without warning and import untrusted media into later processing steps.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/make_video.py (reported line 165)May include surrounding context.

python
"-movflags", "+faststart",
    output
]
r = subprocess.run(cmd, capture_output=True, text=True)
if r.returncode == 0:
    size = os.path.getsize(output)/1024/1024
    print(f"\n✅ 완성! {output} ({size:.1f} MB)")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/make_video_template.py (reported line 163)May include surrounding context.

python
"-movflags", "+faststart",
    output
]
r = subprocess.run(cmd, capture_output=True, text=True)
if r.returncode == 0:
    size = os.path.getsize(output)/1024/1024
    print(f"\n✅ 완성! {output} ({size:.1f} MB)")

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

Lines L129-L134 and L136-L140 state that outputs must rely only on the provided input and avoid introducing outside material. Lines L146-L149 then explicitly direct the skill to download and incorporate external audio content, which conflicts with the stated intent of using only current input-derived material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill includes an external download command but gives no user warning that running the workflow may access the network. Even when the downloaded file is just audio, undisclosed outbound access weakens trust boundaries and may violate user expectations or organizational controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file is in scope for SQP-3, and the text prescribes fixed output styles tied to Korean social platforms and Korean linguistic conventions such as using Korean greetings and formatting. There is no indication that users can choose another language/locale or that the restriction is explicitly justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Lines L129-L145 state that only information from the input text should be used and that non-input wording should not be added. However, the skill simultaneously mandates fixed greetings, branding phrases, badge text structures, hashtags/style conventions, and channel-specific overlay text patterns, which introduces content beyond the source text and conflicts with the strict wording of the rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON contains multiple natural-language strings in Korean, such as experiment descriptions and evaluation category names, but does not document that the skill is intentionally Korean-only or offers any language/locale opt-in. Under the language/locale policy, forcing a specific language without user choice or clear justification can be a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code performs substantial file creation in /tmp and the outbound media directory, but the output only shows progress and completion messages rather than clearly disclosing that files will be written and where they will be stored. For a code file, file-write behavior should have some explicit user disclosure unless it is clearly documented as the skill's expected purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Launching an external process is a safety-relevant operation for code files, and here the script runs ffmpeg without a prior warning, confirmation, or explanatory comment that an external binary will be executed. The nearby status message mentions encoding, but it does not clearly disclose subprocess execution or dependency on ffmpeg.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.