Back to skill

Security audit

Conference Intern

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent event-registration purpose, but it delegates sensitive account actions and personal-data submission too broadly and contains implementation flaws that could expose a user to unintended registrations or phishing pages.

Review carefully before installing. Use only with conferences and event sources you trust, avoid enabling persisted Luma login unless you are comfortable storing session cookies locally, and manually review events and consent terms before registration. The package should ideally fix URL hostname validation, remove automatic legal/privacy consent, harden sensitive file permissions, and avoid interpolating config into executable Python before broad use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.sh:202
Finding

Weak Luma Domain Validation Allows Automatic Submission to Phishing Hosts

Content
View full analysis
/dev/null || echo "[]" } ``` Discovery does not perform compensating URL validation: ```bash # Set rsvp_status to "ok" for all events (skip slow per-URL HEAD validation) # Dead links are caught at registration time when the page fails to load log_info "Skipping URL validation (handled at registration time)..." ``` ### Technical Analysis The code treats a URL as a trusted Luma URL whenever its complete string contains `lu.ma` or `luma.com`. This does not validate the parsed hostname. Attacker-controlled URLs such as the following pass the test: ```text https://lu.ma.attacker.example/register https://attacker.example/path/luma.com https://fake-luma.com/register ``` The accepted URL is subsequently opened by `cli_register_event`. The registration agent receives the user's name, email, and saved custom answers and is instructed to fill and submit the displayed form. Consequently, this validation defect crosses a sensitive trust boundary. The README states that RSV ...[truncated 1384 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/curate.sh:125
Finding

Conference Configuration Is Interpolated into Executable Python Source

Content
View full analysis
`. 3. The script reads the crafted value into `CONF_NAME`. 4. The value is inserted into the `python3 -c` source string. 5. The injected single quote terminates the intended assignment. 6. Python parses and executes the attacker's appended statements with the privileges of the OpenClaw process. ### Impact Assessment Successful exploitation allows arbitrary Python execution as the local account running the Skill. This can provide access to: - Conference con ...[truncated 452 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
templates/register-single-prompt.md:29
Finding

Registration Agent Automatically Accepts Legal and Privacy Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
templates/setup-prompt.md:42
Finding

Authentication Cookies and Registration Profile Data Are Persisted Without Permission Hardening

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims automated registration and directs use of browser automation and agent-driven page interaction, yet the declared metadata does not clearly scope or disclose those powers. This can mislead reviewers or users about the degree of automation and action-taking, increasing the risk of unintended registrations or broader browser use.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims automated registration and directs use of browser automation and agent-driven page interaction, yet the declared metadata does not clearly scope or disclose those powers. This can mislead reviewers or users about the degree of automation and action-taking, increasing the risk of unintended registrations or broader browser use.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill claims automated registration and directs use of browser automation and agent-driven page interaction, yet the declared metadata does not clearly scope or disclose those powers. This can mislead reviewers or users about the degree of automation and action-taking, increasing the risk of unintended registrations or broader browser use.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims automated registration and directs use of browser automation and agent-driven page interaction, yet the declared metadata does not clearly scope or disclose those powers. This can mislead reviewers or users about the degree of automation and action-taking, increasing the risk of unintended registrations or broader browser use.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims automated registration and directs use of browser automation and agent-driven page interaction, yet the declared metadata does not clearly scope or disclose those powers. This can mislead reviewers or users about the degree of automation and action-taking, increasing the risk of unintended registrations or broader browser use.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to run shell scripts for all major actions, but the manifest does not declare an explicit tool scope or permissions boundary for shell use. This creates an authorization gap: users and enforcement layers may not clearly understand that arbitrary local commands and file operations are part of the skill's behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises auto-registration and browser-driven RSVP actions without an upfront, prominent warning that it will actively submit forms on the user's behalf. In this context, silent action-taking is risky because it can create unwanted registrations, disclose personal information to event organizers, or trigger platform abuse controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill stores persisted Luma session cookies and personal registration answers, but the description does not prominently warn users about retention of authentication material and personal data. If these files are exposed, reused, or committed accidentally, an attacker could hijack sessions or access sensitive registration details.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes discovering, curating, and registering for conference side events via Luma and Google Sheets, but this helper additionally pulls personally identifying registration data from process environment variables. Accessing ambient environment state is a broader capability than the stated data sources and can expose unrelated secrets or create hidden dependencies not declared in the skill purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script embeds the user's name and email into a free-form message sent to an agent without any explicit user-facing notice, consent checkpoint, or data minimization boundary. Because agent prompts may be logged, inspected, or mishandled by downstream components, this creates unnecessary privacy and data-handling risk even though the data is relevant to the registration task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends full event data, conference preferences, blocked organizers, and summary statistics to an external agent through openclaw agent --message without any user-facing consent or warning at the point of transmission. Even if the data is not highly sensitive in every case, preferences and organizer blocklists can reveal strategic interests or internal screening criteria, and the batch payload may include third-party data that users do not expect to be forwarded to another service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to write both result and knowledge files without any explicit user-facing warning or consent for file modification. Silent writes are risky because they can overwrite expected data, persist tainted information, and make the agent perform side effects beyond simple browsing/extraction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt expands scope beyond event discovery by instructing the agent to modify a secondary knowledge file. That creates an unnecessary write side effect and increases the attack surface, since a page-controlled or malformed extraction workflow could poison persistent guidance used by future runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is designed to perform registrations on the user's behalf and explicitly instructs the agent to submit event RSVP forms, but it does not require an explicit per-action confirmation or present a clear warning that it will take external account-affecting actions. In this context, that creates a real risk of unintended registrations, especially because event signups can trigger emails, share identity data with third parties, and create commitments under the user's authenticated session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt instructs the agent to load authenticated Luma session cookies from a local file, enabling it to act as the user without an explicit disclosure or consent gate. Using stored login state is sensitive because it allows account-scoped actions and can surprise users who did not expect the skill to leverage existing authentication material automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill reads name and email from local configuration and submits them to third-party event forms, but it does not warn the user that personal data will be transmitted externally. This is dangerous because the transfer is automated, may involve multiple unrelated event organizers, and could expose the user's identity and contact information more broadly than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup collects and stores personal data (name, email) and an authentication artifact (luma-session.json) without any warning about sensitivity, retention, local file permissions, or the risks of cookie theft. If those files are exposed through logs, backups, repo commits, or other local compromise, an attacker could abuse the user’s identity or authenticated Luma session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes event discovery, curation, and registration via Luma and Google Sheets. This setup prompt additionally instructs the agent to create persistent scheduled automation using openclaw cron edit, which is an operational capability beyond the core user-facing purpose and introduces ongoing autonomous execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The prompt says 'Do NOT write Python scripts' and frames the workflow as browser-only extraction, but later explicitly instructs writing the result file via exec with a heredoc. While not necessarily Python, this contradicts the earlier browser-tools-only constraint by introducing shell execution as part of the required workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Line L24 instructs the agent to mark events as needs-input in curated.md, and later lines update statuses for success or failure. These are file-write operations, but the prompt does not explicitly warn that local tracking files will be changed as part of execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown skill directs the agent to write output to {RESULT_FILE}, which is a file write operation affecting user/system data. The instructions provide no warning that the skill will create or overwrite a file, and there is no visible disclosure about this behavior in the description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The prompt creates a recurring background task but does not clearly warn the user that monitoring will continue automatically after setup. This can lead to unexpected background activity, repeated network access, unintended registrations if later automation expands, and confusion about how to stop the task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.