Back to skill

Security audit

Grill Gate

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed gatekeeper plugin, but its main security promise can be bypassed or forged, so it needs human review before installation.

Review this before installing as a security control. It may be useful as a lightweight reminder or workflow guard, but do not rely on it as an unforgeable enforcement layer unless token issuance, token storage permissions, one-time consumption, task binding, and bypass exemptions are redesigned. Install only where blocking selected exec and sessions_spawn calls is acceptable, and pin or audit dependencies for security-sensitive use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
src/index.ts:90
Finding

Forgeable and Replayable Grill Authorization Tokens

Content
View full analysis
f.endsWith(".token") ); const now = Date.now() / 1000; for (const file of files) { const filePath = join(config.tokenDir, file); try { const content = readFileSync(filePath, "utf-8"); const data = JSON.parse(content); if (now - (data.issued_at || 0) < config.tokenTtlSeconds) { return true; // Valid token found } // Expired — clean up unlinkSync(filePath); } catch { try { unlinkSync(filePath); } catch {} } } return false; } catch { return false; } } ``` The result is used as the authorization boundary for restricted tool calls: ```ts if (isBlockedCommand(command, config)) { if (!hasValidToken(config)) { return { block: true, blockReason: "🛑 Grill Gate: Blocked command detected without grill token. " + "You must complete a grill-with-docs session first, then issue a " + "grill token via: python3 scripts/auto_dispatch.py --issue-grill-token ''", }; } } ``` ### Technical Analysis The gate treats any file ending in `.token` as a valid authorization token when its JSON content has an `issued_at` value satisfying: ```ts now - issued_at < tokenTtlSeconds ``` No cryptographic signature, message authentication code, unpredictable secret, trusted issuer identifier, strict schema, or task binding is validated. Consequently, any process or agent able to write into the configured token directory can create its own authorization token without completing ...[truncated 2126 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior materially differs from the stated purpose: enforcement only applies to selected blocked commands, can be bypassed through exemption keywords, and relies on filesystem token/config handling that is not clearly disclosed. This creates a false sense of security, so operators may believe all research/development exec or spawn activity is blocked when important paths remain allowed or can be disabled by crafted inputs.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The plugin explicitly defines exemption phrases such as "ASAP", "skip grill", "just do it", and similar urgent-language shortcuts that disable the gate. Because trigger detection checks exemptions first, an agent or user can trivially append one of these phrases to bypass the intended runtime control, defeating the protection the plugin claims is 'unforgeable'.

Content

No source excerpt is available for this finding.

Ssd 2

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The containsTrigger() logic returns false as soon as any exemption substring appears in the task text, so tasks containing both sensitive trigger terms and bypass phrases are allowed through. In this plugin's context, that is especially dangerous because it is marketed as the final enforcement layer; a simple wording trick can nullify the control and permit research/development task spawning without a grill token.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==5.0.6 — 3 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro); CVE-2026-69152 (brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-1)

High
Category
Supply Chain
Confidence
88% confidence
Finding

brace-expansion 5.0.6 has multiple DoS advisories involving exponential or unbounded expansion. Although this is a transitive dependency, agent tooling often processes attacker-influenced patterns, paths, or globs, making resource exhaustion realistic if hostile input reaches expansion logic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.2 — 6 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +3 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

fast-uri 3.1.2 is affected by host confusion and SSRF-related parsing issues. In a package like openclaw that clearly performs network requests and protocol handling, incorrect URI normalization could allow policy bypasses, misrouting, or unintended access to internal endpoints.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'gaxios' resembles popular package 'axios'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: hono==4.12.18 — 16 advisory(ies): CVE-2026-47676 (Hono: app.mount() strips mount prefix using undecoded path, causing incorrect ro); CVE-2026-47675 (Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie); CVE-2026-71848 (Hono: Algorithmic Complexity DoS in Language Middleware) +13 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

hono 4.12.18 carries many advisories spanning routing, cookie handling, and denial-of-service classes. Because this skill depends on a broad agent framework that may expose HTTP/MCP interfaces, the accumulation of web-facing issues materially increases attack surface even if not all vulnerable code paths are used.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.2.0 — 3 advisory(ies): CVE-2026-54272 (ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSR); CVE-2026-69198 (ip-address: a CIDR suffix on the parsed address suppresses special-use classific); CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco)

High
Category
Supply Chain
Confidence
89% confidence
Finding

ip-address 10.2.0 has SSRF-relevant parsing and classification flaws, including IPv4-mapped/NAT64 and leading-zero ambiguities. In an agent ecosystem that may validate destinations before making outbound requests, these bugs can let attackers smuggle internal or forbidden targets past network policy checks.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: protobufjs==8.4.0 — 5 advisory(ies): CVE-2026-54270 (protobufjs: Memory amplification from preserved unknown fields in binary decode); CVE-2026-54269 (protobufjs : Schema-derived names can shadow runtime-significant properties); CVE-2026-59877 (protobufjs: Denial of Service via infinite loop in .proto option parsing) +2 more

High
Category
Supply Chain
Confidence
84% confidence
Finding

protobufjs 8.4.0 is associated with parsing and memory amplification issues. If the framework consumes untrusted protobuf schemas or binary payloads, attackers may trigger excessive memory use or parser instability, which is especially relevant for long-running agent services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented trigger list is broad enough to match many ordinary task descriptions, causing the enforcement logic to activate on benign requests and making security decisions depend on vague keyword presence rather than explicit task classification. In a runtime enforcement plugin, ambiguous activation boundaries can be abused or can create inconsistent blocking behavior that users learn to work around, weakening the control overall.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The exemption phrases are effectively bypass strings: common language such as "ASAP," "skip grill," or "just do it" can suppress the gate despite the task otherwise matching guarded research/development behavior. Because this plugin is presented as a hard runtime control, ambiguous exemptions directly undermine the trust boundary and create an easy path for accidental or intentional bypass.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

Configuration

Create ~/.openclaw/grill-gate.json (all fields optional):

json
{

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

Configuration

Create ~/.openclaw/grill-gate.json (all fields optional):

json
{

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The header documents a language setting limited to "zh"|"en" with a default of auto-detect. This imposes language handling behavior without any user-choice flow or justification for restricting operation to those locales, which matches the locale-policy concern for natural-language policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The only built-in presets are zh and en, and the matching logic depends on those language-specific trigger phrases. Because the skill does not present this as an explicit user opt-in or a clearly justified regional limitation, it constitutes a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: openclaw==2026.6.1 — 1 advisory(ies): CVE-2026-62208 (OpenClaw MCP SSE redirects could forward Authorization headers)

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins openclaw 2026.6.1, and the cited advisory indicates MCP SSE redirects may forward Authorization headers. In an agent/plugin context that likely handles tokens and remote endpoints, this can leak bearer credentials to an unintended host if redirects are followed across origins.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @hono/node-server==1.19.14 — 1 advisory(ies): GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode)

Low
Category
Supply Chain
Confidence
85% confidence
Finding

@hono/node-server 1.19.14 is flagged for a Windows-specific path traversal issue in serve-static via encoded paths. If this dependency is used to expose files in a local or remote service, an attacker may retrieve unintended files on Windows hosts.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==2.2.2 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
78% confidence
Finding

body-parser 2.2.2 is reported vulnerable to denial of service when invalid limit handling degrades unexpectedly. In environments where this stack accepts HTTP input, malformed requests could consume resources or destabilize request handling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.15.2 — 2 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
80% confidence
Finding

qs 6.15.2 is flagged for DoS and array-limit bypass behaviors during querystring parsing. If any web endpoint in the framework parses attacker-controlled query strings, malformed parameters could bypass assumptions or degrade performance.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The package uses a caret range for the devDependency @types/node, which permits automatic adoption of newer minor/patch releases. While common in JavaScript projects, this weakens build reproducibility and can expose the project to supply-chain risk if an upstream release is compromised or introduces breaking behavior.

Content

Scanner excerpt · package.json (reported line 6)May include surrounding context.

json
"version": "1.0.0",
  "type": "module",
  "devDependencies": {
    "@types/node": "^25.9.1",
    "typescript": "^6.0.3"
  },
  "dependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The package uses a caret range for the devDependency typescript, allowing newer compatible versions to be resolved automatically. This creates a low-severity supply-chain and reproducibility risk because builds may change over time or consume a malicious/defective upstream release.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"type": "module",
  "devDependencies": {
    "@types/node": "^25.9.1",
    "typescript": "^6.0.3"
  },
  "dependencies": {
    "openclaw": "^2026.5.22"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The runtime dependency openclaw is specified with a caret range, so installation may pull newer releases without explicit review. Because this skill is a runtime enforcement plugin that mediates exec/spawn blocking, compromise or unexpected changes in the core runtime dependency are more security-relevant than ordinary library drift and could weaken or bypass the intended guardrail.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"typescript": "^6.0.3"
  },
  "dependencies": {
    "openclaw": "^2026.5.22"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language description states language: "zh"|"en" with a default of auto-detect, and the implementation hardcodes only Chinese and English trigger/exemption presets. This can constitute a language/locale policy issue because the skill behavior is constrained to specific languages without presenting a user choice in the skill interface or documenting a justified regional limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.