Back to skill

Security audit

toui URL shortener

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its URL-shortening purpose, but its curl fallback uses an unsafe command template that could mishandle crafted URLs or titles.

Review this skill before installing if you expect agents to use the REST fallback. Prefer the MCP tool path, and only use a minimally scoped TOUI_API_KEY. Do not let an agent build the curl command by pasting raw URLs or titles into the shown shell snippet; values should be validated and JSON-escaped or sent through a structured API.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:51
Finding

Shell Command Injection Through Unsafe URL and Title Interpolation

Content
View full analysis
","title":"optional"}' ``` ### Technical Analysis The documented REST workflow instructs the agent to place a user-provided URL and optional title directly inside a single-quoted shell argument. No structured JSON serialization or shell-safe parameter handling is specified. If an agent constructs this command through textual substitution, a single quote in either user-controlled value can terminate the shell argument. Subsequent shell metacharacters can then be interpreted as commands. Independently, embedded quotation marks, backslashes, or control characters can corrupt the JSON request. For example, a malicious value conceptually shaped as: ```text https://example.invalid/' ; attacker_command ; # ``` could transform the intended `curl` invocation into multiple shell commands if inserted directly into the documented template. The precise payload depends on how the invoking agent performs substitution and whether it validates the URL before command execution. ### Attack Path 1. An attacker asks the agent to shorten a crafted URL or supplies a crafted optional title. 2. The input contains a single quote that closes the `-d` argument, followed by shell syntax and an injected command. 3. The agent follows the Skill's REST instructions and substitutes the untrusted value directly into the command template. 4. The command is passed to a shell. 5. The shell executes the injected command with the same operating-system privileges and environment access as the agent process. This path is applicable when the REST fallback is used and the template is assembled through direct textual ...[truncated 819 chars]
Remediation
View remediation
' TITLE='' jq -n \ --arg url "$URL" \ --arg title "$TITLE" \ '{url: $url, title: $title}' | curl --fail-with-body \ --request POST \ 'https://toui.io/api/v1/shorten' \ --header "Authorization: Bearer $TOUI_API_KEY" \ --header 'Content-Type: application/json' \ --data-binary @- ``` Additional hardening measures: 1. Prefer the structured `shorten_url` MCP tool over shell execution whenever it is available. 2. Validate that the submitted value uses an explicitly permitted scheme, such as `https` or `http`, before sending it. 3. Pass command arguments through a process API without invoking a shell where supported. 4. Never build JSON by concatenating or substituting raw user input. 5. Keep `TOUI_API_KEY` scoped to the minimum required API permissions and prevent it from being logged. 6. Document that URLs and titles are untrusted data and must not be evaluated as shell syntax. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
description: toui API key (shorten scope) needed only for the direct REST path (curl). Create one at https://toui.io/admin. Not required if you connected via "openclaw mcp add toui" (OAuth).
    requires:
      anyBins:
        - curl
    emoji: "🔗"
    homepage: https://toui.io
    os:

Static analysis

No suspicious patterns detected.