Back to skill

Security audit

Free Ride - Unlimited free AI

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its purpose, but it handles an API key and changes OpenClaw behavior while using unsafe secret-check instructions, a persistent watcher, and an unpinned remote installer.

Install only if you are comfortable with it editing your OpenClaw model configuration and using your OpenRouter API key. Do not run the documented echo command for the key; use a non-printing presence check instead. Avoid the nohup watcher unless you deliberately want continuous background health checks and automatic config rotation, and prefer a pinned installer version over @latest.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:28
Finding

API Key Disclosure Through a Secret-Printing Prerequisite Command

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
skill.json:46
Finding

Mutable Remote Package Is Downloaded and Executed During Installation

Content
View full analysis
=2.31.0", ] ``` No malicious dependency was identified in the reviewed project, but the installation flow lacks version and integrity controls. ### Attack Path 1. A user follows the documented installation command or a platform executes the `skill.json` installation string. 2. `npx` resolves `clawhub@latest` from the configured npm registry. 3. The resolved package is downloaded and executed. 4. If that mutable release or its dependency chain has been compromised, its installation or runtime code executes as the user. 5. The malicious package can access files, environment variables, network resources, and user-owned configuration available to the installation process. 6. It can then modify the installed Skill or establish additional behavior outside the r ...[truncated 719 chars]
Remediation
View remediation
install free-ride ``` 2. Where supported, verify the package integrity digest before execution. 3. Commit lockfiles for installation tooling and Python dependencies. 4. Pin Python dependencies to reviewed versions rather than relying only on a lower bound. 5. Run installation in a minimally privileged environment without unrelated secrets. 6. Document the exact installer version and integrity value associated with each Skill release. 7. Require a new security review whenever the installer or dependency versions change. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
main.py:349
Finding

Optional Authentication-Profile Write Exceeds the Declared Configuration Boundary

Content
View full analysis
dict: """Set up OpenRouter auth profile if not exists.""" if "auth" not in config: config["auth"] = {} if "profiles" not in config["auth"]: config["auth"]["profiles"] = {} if "openrouter:default" not in config["auth"]["profiles"]: config["auth"]["profiles"]["openrouter:default"] = { "provider": "openrouter", "mode": "api_key" } print("Added OpenRouter auth profile.") return config ``` The optional write is invoked during configuration updates: ```python if setup_auth: config = setup_openrouter_auth(config) ``` However, `SKILL.md:12` declares only: ```yaml writes: - ~/.openclaw/openclaw.json (keys: agents.defaults.model, agents.defaults.models only) ``` The same restricted boundary is represented in `skill.json:39-42`: ```json "configKeys": [ "agents.defaults.model", "agents.defaults.models" ] ``` ### Technical Analysis The `auto --setup-auth` and `switch --setup-auth` options can create `auth.profiles.openrouter:default`, even though the Skill declares that it writes only `agents.defaults.model` and `agents.defaults.models`. The implementation does not insert an API key into the new profile, and the behavior is gated behind an explicit command-line option. It is therefore not evidence of malicious credential theft. Nevertheless, the undeclared write violates the stated least-privilege boundary and can cause permission-review systems or users to approve the Skill based on incomplete metadata. The entire configuration is subsequently serialized back to `~/.openclaw/openclaw.json`, making accurate declaration of all modified keys important. ### Attack Path 1. A user or agent invokes `freeride auto -- ...[truncated 1019 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The published description frames the skill as a simple model configuration helper, but the documented behavior includes a persistent watcher/daemon, health probing, rotation logic, and state/history persistence. This mismatch is dangerous because users and orchestration layers may grant or invoke the skill under the assumption of one-shot config edits, while it can establish ongoing autonomous behavior with continued network and file activity.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
90% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · watcher.py (reported line 39)May include surrounding context.

python
def _atomic_write(path: Path, content: str):
    """Write atomically via tmp + rename so a crash mid-write can't corrupt state."""
    path.parent.mkdir(parents=True, exist_ok=True)
    tmp = path.with_suffix(path.suffix + ".tmp")
    tmp.write_text(content)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 5)May include surrounding context.

md
### Stop paying for AI. Start riding free.

[![ClawHub Downloads](https://api.clawhub-badge.xyz/badge/free-ride/downloads.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Current Installs](https://api.clawhub-badge.xyz/badge/free-ride/installs-current.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Stars](https://api.clawhub-badge.xyz/badge/free-ride/stars.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Version](https://api.clawhub-badge.xyz/badge/free-ride/version.svg)](https://clawhub.ai/skills/free-ride)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 6)May include surrounding context.

md
### Stop paying for AI. Start riding free.

[![ClawHub Downloads](https://api.clawhub-badge.xyz/badge/free-ride/downloads.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Current Installs](https://api.clawhub-badge.xyz/badge/free-ride/installs-current.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Stars](https://api.clawhub-badge.xyz/badge/free-ride/stars.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Version](https://api.clawhub-badge.xyz/badge/free-ride/version.svg)](https://clawhub.ai/skills/free-ride)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 7)May include surrounding context.

md
### Stop paying for AI. Start riding free.

[![ClawHub Downloads](https://api.clawhub-badge.xyz/badge/free-ride/downloads.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Current Installs](https://api.clawhub-badge.xyz/badge/free-ride/installs-current.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Stars](https://api.clawhub-badge.xyz/badge/free-ride/stars.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Version](https://api.clawhub-badge.xyz/badge/free-ride/version.svg)](https://clawhub.ai/skills/free-ride)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 8)May include surrounding context.

md
### Stop paying for AI. Start riding free.

[![ClawHub Downloads](https://api.clawhub-badge.xyz/badge/free-ride/downloads.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Current Installs](https://api.clawhub-badge.xyz/badge/free-ride/installs-current.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Stars](https://api.clawhub-badge.xyz/badge/free-ride/stars.svg)](https://clawhub.ai/skills/free-ride)
[![ClawHub Version](https://api.clawhub-badge.xyz/badge/free-ride/version.svg)](https://clawhub.ai/skills/free-ride)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes a one-command setup that automatically edits ~/.openclaw/openclaw.json and reconfigures model/fallback behavior, but the up-front messaging emphasizes convenience rather than clearly warning that a persistent user configuration file will be modified. This can lead users to run the command without understanding that local agent behavior and routing policy are being changed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The installation command uses npx clawhub@latest, which fetches and executes the latest package version at install time without pinning to a reviewed release. This creates a supply-chain execution risk: if the package, dependency chain, or publishing account is compromised, users may run attacker-controlled code immediately during setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The watcher instructions encourage users to run a persistent background daemon that probes remote models every minute and automatically rotates config, but do not foreground the privacy, resource, and operational implications of continuous network activity and ongoing config mutation. Users may unknowingly leave a long-running process active across logouts that makes repeated outbound requests and changes model selection over time.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The README explicitly instructs users to start freeride-watcher under nohup so it persists after logout, creating a background process that continues making network probes and rotating configuration outside the user's active session. Persistence itself is not inherently malicious here, but without strong warnings and lifecycle guidance it increases the chance of unnoticed ongoing activity, stale processes, and unintended behavior changes.

Content

Scanner excerpt · README.md (reported line 199)May include surrounding context.

md
freeride-watcher

# Background, persistent across logout
nohup freeride-watcher > ~/.openclaw/freeride-watcher.log 2>&1 &

# One-off check (no loop)
freeride-watcher --once

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares sensitive capabilities (environment secret access, network access, and file writes) but does not define an explicit tool/permission scope. That makes its effective authority broader and less auditable, increasing the chance an agent invokes it with more privileges than intended or that future changes expand behavior without a corresponding policy review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance uses broad trigger phrases like 'free AI', 'model switching', 'rate limits', and 'reduce AI costs', which can overlap with many ordinary support requests. Over-broad routing can cause the skill to be invoked unexpectedly, exposing API-key-dependent network operations and config mutations in situations where the user may only be asking for advice rather than requesting changes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill explicitly recommends launching a persistent background process via nohup, which creates session persistence outside the immediate user interaction. Persistent daemons increase risk because they continue making network probes and configuration changes after the original task ends, and they may be forgotten, harder to audit, or abused if their behavior changes.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
freeride-watcher

# Persistent background
nohup freeride-watcher > ~/.openclaw/freeride-watcher.log 2>&1 &

# One-shot check (no loop)
freeride-watcher --once

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code persistently modifies the user's OpenClaw configuration by calling save_openclaw_config(config) after changing primary and fallback models. Although some status messages are printed, there is no confirmation prompt or explicit warning before the write occurs, and the operation changes application behavior in a user-impacting way.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The install command invokes npx clawhub@latest, which fetches and executes remote package code at install time without pinning to an exact trusted version. This creates a supply-chain execution path where a compromised upstream release or dependency could run arbitrary code on the user's machine during installation, and the risk is amplified because this skill also handles API secrets and edits local configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill writes a cache file under ~/.openclaw/.freeride-cache.json, which is a file-system side effect. The function itself has only an internal docstring and no user-facing disclosure at the point of write, so users invoking commands indirectly triggering caching may not be warned that local files are being created or updated.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as requests>=2.31.0, which allows any future version and does not guarantee a tested or reviewed release. This weakens supply-chain control and reproducibility, and can unintentionally introduce vulnerable or incompatible versions during installation.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Because requests is not pinned, it is not possible to determine from this manifest whether the installed version is affected by known advisories. In a skill that may make network calls to OpenRouter or related services, using an unknown requests version can expose the agent to client-side request handling issues, credential leakage, or TLS/redirect-related vulnerabilities if a vulnerable release is resolved.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description says the skill provides "Unlimited free AI access for OpenClaw via OpenRouter's free models with automatic fallback switching," but it does not specify concrete activation conditions, command scope, or exclusion cases, which can make invocation overly broad in systems that use manifest text for discovery or routing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.