Back to skill

Security audit

Openclaw Flowsery

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent and service-focused, but it gives an agent documented paths to read personal analytics data and irreversibly delete payment and goal history using only instruction-level safeguards.

Install only if you trust Flowsery with the configured workspace token and want an agent to access sensitive analytics data. Prefer the included OpenClaw plugin for normal use because it omits writes and visitor profiles; be especially cautious with the markdown skill's direct API guidance for visitor profiles, payment recording, and DELETE operations, and require a human review of exact website, filters, date range, and record count before any deletion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (45)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Payment deletion is particularly dangerous because it permanently removes revenue history and affects reporting, auditability, and user profiles. The skill text warns about this, but natural-language safeguards are weaker than enforcement, so an agent or wrapper that skips confirmations could still perform destructive actions with significant business impact.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
This skill is read-only by default, but the API also exposes **write** and **irreversible delete** operations and returns **personal data**. Before acting, observe these rules:

- **Destructive operations require confirmation.** `DELETE /goals` and `DELETE /payments` permanently erase historical business data and cannot be undone. Never run them as a side effect of an analytics request. Always restate exactly what will be deleted (website, filters, date range, and how many records if known) and get explicit user confirmation first. Never run a DELETE without a date range or other narrowing filter unless the user has explicitly confirmed a full-history wipe.
- **Treat a request to "clean up", "fix", or "remove" data as deletion, not querying**: confirm intent before translating it into a DELETE call.
- **Visitor profiles and payments are PII.** Profiles can contain email, name, geolocation, full page history, and revenue. Only retrieve an individual visitor profile when the user explicitly asks about a specific person/visitor, and confirm they are authorized to view it. Present the minimum detail needed to answer; do not dump full identity, contact, and activity timelines unless asked.
- **Minimize personal data on writes.** When recording payments/goals, send only the fields required for the task. Do not add `email`, `name`, or `customerId` unless the user explicitly provides them and they are needed for attribution.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Payment deletion is particularly dangerous because it permanently removes revenue history and affects reporting, auditability, and user profiles. The skill text warns about this, but natural-language safeguards are weaker than enforcement, so an agent or wrapper that skips confirmations could still perform destructive actions with significant business impact.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
This skill is read-only by default, but the API also exposes **write** and **irreversible delete** operations and returns **personal data**. Before acting, observe these rules:

- **Destructive operations require confirmation.** `DELETE /goals` and `DELETE /payments` permanently erase historical business data and cannot be undone. Never run them as a side effect of an analytics request. Always restate exactly what will be deleted (website, filters, date range, and how many records if known) and get explicit user confirmation first. Never run a DELETE without a date range or other narrowing filter unless the user has explicitly confirmed a full-history wipe.
- **Treat a request to "clean up", "fix", or "remove" data as deletion, not querying**: confirm intent before translating it into a DELETE call.
- **Visitor profiles and payments are PII.** Profiles can contain email, name, geolocation, full page history, and revenue. Only retrieve an individual visitor profile when the user explicitly asks about a specific person/visitor, and confirm they are authorized to view it. Present the minimum detail needed to answer; do not dump full identity, contact, and activity timelines unless asked.
- **Minimize personal data on writes.** When recording payments/goals, send only the fields required for the task. Do not add `email`, `name`, or `customerId` unless the user explicitly provides them and they are needed for attribution.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The statement that goal events can be 'undone' with DELETE /goals normalizes use of an irreversible destructive endpoint as a routine reversal mechanism. That can encourage agents to select deletion automatically after accidental duplicate writes, risking broader historical data loss if parameters are wrong or under-scoped.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
- `visitorUid` (recommended): the `_fs_vid` cookie value of a visitor the tracking script has already seen, so the completion attaches to that visitor's sessions and source. Omit it to record an anonymous completion.
- `metadata` (optional): up to 10 string key-value pairs; more than 10 returns `400`

Each call appends one completion, so repeating it counts the goal twice. Use `POST /payments` for revenue, which records a `payment` goal on its own. Undo with `DELETE /goals`.

### 10. Record a payment

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
- `transactionId` must be unique. A repeated id is rejected, not deduplicated.
- A new payment also records a `payment` goal completion (`free_trial` when `amount` is 0). `isRenewal: true` counts the revenue but skips that goal.
- `isRefund: true` with an existing `transactionId` marks that payment refunded by `amount` instead of creating a new record. Prefer this over `DELETE /payments` when the charge should stay in history.
- Attribution looks up a known visitor by `visitorUid`, then `customerId` or `email`. With no match the revenue is still recorded, but its source, country and device show as Unknown.

### 11. Delete goal events (irreversible, confirm first)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The skill openly advertises destructive endpoints among normal agent tasks, which increases the chance an autonomous system may invoke them if user intent is ambiguous or if prompt injection attempts to coerce deletion. Because these deletes are irreversible and can affect historical analytics integrity, their presence is a genuine high-risk capability even absent malicious intent by the author.

Content

Scanner excerpt · SKILL.md (reported line 387)May include surrounding context.

md
- `POST /goals`: track a goal event
- `POST /payments`: record a payment
- `PATCH /issues/{id}`: change an issue's status (reversible)
- `DELETE /goals`: delete goal events (irreversible)
- `DELETE /payments`: delete payment records (irreversible)

**Always confirm with the user before running DELETE operations.**

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

Permanent payment-record deletion is a high-risk capability because it can erase revenue evidence, alter reports, and impede audits or dispute resolution. The context makes this more dangerous because the same skill also handles sensitive revenue and visitor data, so a mistaken or manipulated call can have both operational and compliance consequences.

Content

Scanner excerpt · SKILL.md (reported line 388)May include surrounding context.

md
- `POST /payments`: record a payment
- `PATCH /issues/{id}`: change an issue's status (reversible)
- `DELETE /goals`: delete goal events (irreversible)
- `DELETE /payments`: delete payment records (irreversible)

**Always confirm with the user before running DELETE operations.**

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · openclaw-plugin/README.md (reported line 57)May include surrounding context.

md
## What is deliberately missing

No writes. The API can create goal and payment records and can permanently
delete them, and `DELETE /goals` with no date range wipes history that does not
come back. None of that belongs behind a tool an agent can reach while
answering "how did traffic do last week". Use the
[skill](https://github.com/Flowsery/flowsery-openclaw), which spells out the

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The skill documents a destructive payment-deletion capability that can permanently erase revenue history if an agent invokes it with broad or weakly validated filters. In an agent context, this is dangerous because a prompt-influenced or mistaken action could cause irreversible financial-data loss across large date ranges or entire visitor histories.

Content

Scanner excerpt · references/api-reference.md (reported line 502)May include surrounding context.

md
- `transactionId` must be unique. A repeated id is rejected, not deduplicated.
- A new payment also records a `payment` goal completion (`free_trial` when `amount` is 0). `isRenewal: true` counts the revenue but skips that goal.
- `isRefund: true` with an existing `transactionId` marks that payment refunded by `amount` instead of creating a new record. A `transactionId` that belongs to another website answers `400`. Prefer this over `DELETE /payments` when the charge should stay in history.
- Attribution looks up a known visitor by `visitorUid`, then `customerId` or `email`. With no match the revenue is still recorded but its source, country and device show as Unknown.

**Note:** Stripe, LemonSqueezy, and Polar payments are tracked automatically when connected; only use this for other providers.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The documented DELETE /goals endpoint permanently removes historical goal completions and warns that broad filters can delete data across all history. This creates a real tool-parameter abuse risk for an agent, since ambiguous user requests or prompt manipulation could trigger irreversible analytics corruption without sufficient scoping.

Content

Scanner excerpt · references/api-reference.md (reported line 507)May include surrounding context.

md
**Note:** Stripe, LemonSqueezy, and Polar payments are tracked automatically when connected; only use this for other providers.

### DELETE /goals

Delete custom goal events by filter.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This second DELETE /payments reference reinforces that deletions are irreversible and may affect all matching records across history when no date range is supplied. In agent-operated environments, such endpoints are especially dangerous because the tool may be invoked from vague cleanup requests, producing large-scale data destruction without malicious code in the skill itself.

Content

Scanner excerpt · references/api-reference.md (reported line 533)May include surrounding context.

md
**WARNING:** Without a date range, matching records are deleted across the entire history.

### DELETE /payments

Delete payment records by filter.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

1. List accessible websites

bash
curl -s -H "Authorization: Bearer $FLOWSERY_API_KEY" \
  https://analytics.flowsery.com/analytics/api/v1/websites

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 344)May include surrounding context.

md
`code` is present only on the errors below; read `message` for the rest.

| Status | `code`                     | Meaning                                                                                              |
| ------ | -------------------------- | ---------------------------------------------------------------------------------------------------- |
| 400    |                            | Invalid input, no website selected with a workspace token, or a delete with no filter                |
| 401    |                            | Missing, invalid or revoked API key                                                                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
### Common agent tasks

| User says                          | What to do                                                                                  |
| ---------------------------------- | ------------------------------------------------------------------------------------------- |
| "How's my traffic?"                | Call `overview` with last 30 days                                                           |
| "What are my top pages?"           | Call `pages` with date range; `breakdown?dimension=entry_page` for landing pages            |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
export const API_BASE_URL = "https://analytics.flowsery.com/analytics/api/v1";
const TOKEN_PREFIX = "flow_ws_";
export function readConfig(api) {
    const root = api.config;

Static analysis

No suspicious patterns detected.