Back to skill

Security audit

Ticket Monitor Ichinosuke

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its installer can modify the shared Python environment with unpinned packages, so it should be reviewed before installation.

Install only if you are comfortable with a Discord webhook receiving public ticket details and with local state being stored. Prefer installing dependencies in an isolated virtual environment or locked container image, remove --break-system-packages, pin dependency versions, and add cron only if you intentionally want recurring checks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/install.sh:4
Finding

Unpinned Dependencies Installed into the System Python Environment

Content
View full analysis

Vulnerability Details

File Location: scripts/install.sh:4-5
Vulnerability Type: Unpinned third-party dependencies and unsafe system-level package installation
Risk Level: Medium

Vulnerable Code

bash
echo "Installing ticket-monitor-ichinosuke dependencies..."
pip install requests beautifulsoup4 python-dotenv --break-system-packages || pip install requests beautifulsoup4 python-dotenv

Technical Analysis

The installer downloads requests, beautifulsoup4, and python-dotenv without pinning reviewed versions or verifying package hashes. Consequently, the code installed during future deployments can differ from the code that was assessed.

The first installation attempt also uses --break-system-packages, bypassing Python's externally managed environment protection. This can modify the host or container's shared Python environment and overwrite dependencies used by OpenClaw or other applications. The fallback command remains unpinned and may still install globally, depending on the runtime configuration and account permissions.

No malicious or misspelled package name was identified in the audited project. The risk instead arises from uncontrolled future dependency resolution, package-index compromise, compromised upstream releases, and shared-environment modification.

Attack Path

  1. An attacker compromises an upstream package release, maintainer account, distribution artifact, or package-index delivery path for one of the declared dependencies.
  2. A user or automated installer executes bash scripts/install.sh.
  3. pip resolves and downloads the latest available package version because no exact version or hash is specified.
  4. Malicious installation or package code executes with the privileges of the account running the installer.
  5. Because the command targets the shared Python environment and explicitly permits breaking system package protections, the compromised package may affect the Skill, OpenClaw, or other Pyth ...[truncated 745 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency lock file containing exact versions and cryptographic hashes.
  2. Install with hash enforcement, for example:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Use a dedicated virtual environment rather than the system interpreter:
    bash
    python3 -m venv .venv
    .venv/bin/python -m pip install --require-hashes -r requirements.txt
    
  4. Remove --break-system-packages and fail safely if an isolated environment is unavailable.
  5. Prefer dependency installation during an immutable container-image build rather than modifying a running OpenClaw container.
  6. Run installation as an unprivileged account and ensure the environment cannot modify unrelated OpenClaw or system files.
  7. Add automated dependency vulnerability and provenance checks to the release process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (15)

Tainted flow: 'DISCORD_WEBHOOK_URL' from os.getenv (line 12, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/ticket_monitor.py (reported line 91)May include surrounding context.

python
data = {
        "content": f"🔔 **春風亭一之輔 公演情報(東京)**\n\n{ticket['full_text']}\n\n**詳細・チケット:** {ticket['url']}"
    }
    response = requests.post(DISCORD_WEBHOOK_URL, json=data)
    response.raise_for_status()

def main():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ticket_monitor.py (reported line 8)May include surrounding context.

python
from bs4 import BeautifulSoup
from dotenv import load_dotenv

# dotenv を使ってスクリプト実行ディレクトリ周辺の .env も読み込む
env_path = os.path.join(os.path.dirname(__file__), '../.env')
load_dotenv(dotenv_path=env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ticket_monitor.py (reported line 9)May include surrounding context.

python
from dotenv import load_dotenv

# dotenv を使ってスクリプト実行ディレクトリ周辺の .env も読み込む
env_path = os.path.join(os.path.dirname(__file__), '../.env')
load_dotenv(dotenv_path=env_path)

DISCORD_WEBHOOK_URL = os.getenv("DISCORD_WEBHOOK_URL")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares installation and behavior that imply access to environment variables, local files, and outbound network communication, but it does not define any explicit tool scope or permission boundaries. This can let an agent invoke the skill with broader-than-necessary capabilities, increasing the chance of unintended file access, secret exposure, or arbitrary network use if the implementation is modified or abused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation phrases are broad and can cause the agent to run the skill whenever a user asks generally about checking ticket information, without strong trigger boundaries or confirmation. In an agent environment, ambiguous activation can lead to unintended web requests, Discord notifications, and state changes such as updating the seen-tickets file.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/skill_ticket_notification/deploy_guide.md (reported line 53)May include surrounding context.

VPS側の cron を使って、Dockerコマンドを定期的に叩くように設定します。

bash
# crontab -e で設定
0 9 * * * docker exec <container_id> python3 /app/skills/ticket-monitor/scripts/ticket_monitor.py

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill plan and user-facing descriptions are written only in Japanese, including the title, operational summary, and proposed SKILL.md description content. There is no indication that users may choose another language or that the skill is intentionally limited to Japanese-language users for a documented regional or compliance reason.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The inline comment states the Tokyo-performance filter exists to satisfy a user request for '東京公演チケット', implying the script is monitoring Tokyo tickets for the requested subject. However, the code is hardwired to 春風亭一之輔's official site and Discord message content, creating a direct mismatch between the documented intent and the actual monitored source/artist.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ticket_monitor.py (reported line 91)May include surrounding context.

python
data = {
        "content": f"🔔 **春風亭一之輔 公演情報(東京)**\n\n{ticket['full_text']}\n\n**詳細・チケット:** {ticket['url']}"
    }
    response = requests.post(DISCORD_WEBHOOK_URL, json=data)
    response.raise_for_status()

def main():

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing description and invocation guidance are presented exclusively in Japanese, with no indication that users may choose another language or that the locale restriction is intentional. This can conflict with organizational language/locale policies when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all operational instructions in Japanese and includes a Japanese invocation example at L47, but it does not indicate that the skill is Japan-specific or offer any user language/locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file's natural-language instructions are entirely in Japanese, which may impose a language constraint on users without any opt-in or explanation. Under the language/locale policy rule, this is a potential violation unless the skill explicitly offers language choice or documents a justified region-specific scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file instructs the user to configure a Discord webhook, which causes notifications to be sent to a third-party service. The walkthrough does not include any warning about privacy, data disclosure, or the need to ensure the webhook destination is appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file includes natural-language comments and notification/status text in Japanese, and the notification content sent to users is fixed to that language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs a network call to an external Discord webhook and transmits scraped ticket content and URLs, but there is no confirmation prompt, explanatory comment/docstring near the function, or explicit user-facing disclosure about the outbound transmission itself. The existing print at L085 only reports missing configuration and does not warn that data will be sent to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.