Back to skill

Security audit

anycrawl

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward web scraping, crawling, and search API wrapper, with expected third-party network use and no hidden local persistence or destructive behavior.

Before installing, understand that URLs, search queries, extraction prompts/schemas, optional proxy settings, and crawl targets are sent to SkillBoss and may involve downstream scraping providers. Avoid submitting secrets, internal-only URLs, regulated data, or credential-bearing proxy URLs unless that is approved for your environment. Prefer OpenClaw config or a secret manager over editing shell profiles if you do not want the API key persisted there.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

AnyCrawl Skill

Web scraping, crawling, and search via SkillBoss API Hub — powered by high-performance multi-threaded crawling backends (Firecrawl, Jina AI, Apify, ScrapingDog, and more).

Setup

Method 1: Environment variable (Recommended)

bash
export SKILLBOSS_API_KEY="your-api-key"

Make it permanent by adding to ~/.bashrc or ~/.zshrc:

bash
echo 'export SKILLBOSS_API_KEY="your-api-key"' >> ~/.bashrc
source ~/.bashrc

Get your API key at: https://skillboss.co

Method 2: OpenClaw gateway config

bash
openclaw config.patch --set SKILLBOSS_API_KEY="your-api-key"

requires.env

text
SKILLBOSS_API_KEY

Functions

1. anycrawl_scrape

Scrape a single URL and convert to LLM-ready structured data via SkillBoss API Hub (type: "scraping").

Parameters:

  • url (string, required): URL to scrape
  • engine (string, optional): Scraping engine - "cheerio" (default), "playwright", "puppeteer"
  • formats (a

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends user-provided URLs, search queries, crawl targets, and potentially scraped page contents to the third-party SkillBoss API Hub, but the description does not clearly warn users about that external data transmission. This can cause unintentional disclosure of sensitive prompts, internal URLs, or proprietary page content when users assume processing is local.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 2)May include surrounding context.

js
// AnyCrawl Skill - powered by SkillBoss API Hub
// Scrape, Crawl, and Search web content via https://api.skillboss.co/v1/pilot

const API_KEY = process.env.SKILLBOSS_API_KEY;
const API_BASE = "https://api.skillboss.co/v1";

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · index.js (reported line 5)May include surrounding context.

js
// AnyCrawl Skill - powered by SkillBoss API Hub
// Scrape, Crawl, and Search web content via https://api.skillboss.co/v1/pilot

const API_KEY = process.env.SKILLBOSS_API_KEY;
const API_BASE = "https://api.skillboss.co/v1";

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.js:4