Back to skill

Security audit

Mission Control Builder

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent dashboard tutorial, but it includes an unauthenticated API route that can expose local OpenClaw memory excerpts.

Install only if you plan to run it as a strictly local personal dashboard. Before using the memory sync feature, add authentication, bind the server to localhost, make the memory directory explicitly configurable, and return metadata or selected records instead of bulk memory excerpts. Pin npm package versions if you want reproducible setup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:346
Finding

Unauthenticated Disclosure of OpenClaw Memory Contents

Content
View full analysis
f.endsWith('.md'))) { const content = await fs.readFile(path.join(memoryDir, file), 'utf-8'); memories.push({ id: file, title: file.replace('.md', ''), content: content.slice(0, 500) + '...', createdAt: new Date().toISOString(), }); } return NextResponse.json(memories); } catch (error) { return NextResponse.json([]); } } ``` ### Technical Analysis The generated `/api/sync` GET handler accesses every Markdown file in the OpenClaw memory directory under the server account's home directory. It then returns filenames and the first 500 characters of each file in an HTTP response. The route contains no authentication or authorization check. Although reading OpenClaw memories is necessary for the declared memory-browser feature, exposing those memories to every caller capable of reaching the endpoint exceeds minimum safe privilege. The later documentation acknowledges that authentication is absent and recommends running locally or behind a VPN, but this warning does not protect the generated implementation. The fixed directory and `.md` filter reduce arbitrary-file-read risk, but they do not prevent disclosure of sensitive information legitimately stored in OpenClaw memory files. The application also returns all available memory excerpts rather than requiring the user to select individual records. ### Attack Path 1. A user implements and starts the dashboard as instructed. 2. The application becomes reachable by an ...[truncated 1235 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:55
Finding

Mutable and Unpinned npm Supply-Chain Execution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation implies an OpenClaw integration, but the implementation actually scrapes raw markdown files from a hardcoded home-directory path. That mismatch is dangerous because users may believe they are using a bounded application interface when the code is actually performing direct filesystem reads of potentially sensitive local data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs exposing OpenClaw memory content through an API route without a clear warning that personal memory files will be read and served. In context, this is especially risky because the same document states that no authentication is included, turning sensitive local notes into potentially accessible HTTP responses.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The sync route reads directly from $HOME/clawd/memory and exposes file contents over an API endpoint, granting local-file access broader than the dashboard description suggests. This can unintentionally surface sensitive personal memory data to any user or process that can reach the web app, especially since the skill explicitly includes no authentication.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 434)May include surrounding context.

md
// src/app/api/github-trends/route.ts
export async function GET() {
  const response = await fetch(
    "https://api.github.com/search/repositories?q=stars:>1000&sort=stars&per_page=10"
  );
  const data = await response.json();
  return NextResponse.json(data.items);

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The architecture section presents the implementation as using local JSON files and OpenClaw memory, which implies a local dashboard data flow. Later, the GitHub Trends route introduces outbound network access to api.github.com, which is a meaningful behavior not reflected in the stated architecture or implementation description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown instructs adding a route that fetches data from api.github.com, which causes outbound network traffic from the user's environment. The file does not clearly disclose near this step that enabling this feature sends requests to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.