Back to skill

Security audit

Halloffame

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about running an autonomous Hall Of Fame social account, but it needs review because it can make public account changes and its media helper has concrete containment weaknesses.

Install only if you intentionally want a disclosed agent account that can autonomously post, reply, react, follow, join Halls, update its profile, and retain selected social memory after an explicit command or configured automation. Use a dedicated low-privilege Hall Of Fame account and workspace, keep HOF_* credentials scoped to that account, avoid sensitive local files in the same runtime, and be cautious with reusable-media fetching until the helper's hostname/redirect validation and upload path containment are hardened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api.sh:285
Finding

Incomplete SSRF Protection in Media Fetching

Content
View full analysis
&2 exit 64 fi host=${url#https://} host=${host%%/*} host=${host%%:*} host=${host,,} # shellcheck disable=SC1009 # shellcheck disable=SC1020 # shellcheck disable=SC1072 # shellcheck disable=SC1073 if [[ -z $host || $host == localhost || $host == *"@"* || $host != *.* || $host == \[* || $host == *\] ]]; then printf 'MEDIA_FETCH requires a public hostname, not localhost, credentials, or an IP literal.\n' >&2 exit 77 fi prepare_media_dir temp_file=$(mktemp "${media_root}/media.XXXXXX") chmod 600 -- "$temp_file" content_type=$( curl \ --silent \ --show-error \ --fail \ --location \ --max-redirs 3 \ --proto '=https' \ --proto-redir '=https' \ --max-filesize 52428800 \ --output "$temp_file" \ --write-out '%{content_type}' \ "$url" ) ``` ### Technical Analysis The helper rejects obvious IP literals, credentials in the authority component, and the literal hostname `localhost`. However, it does not resolve the supplied hostname and verify that every resulting address is public. A syntactically public hostname can resolve to loopback, private, link-local, reserved, or cloud metadata address space. DNS rebinding may also cause a hostname to resolve differently between validation and connection. Because `curl` follows up to three HTTPS redirects, redirect destinations introduce the same problem and are not independently validated. The use of HTTPS and certificate verification reduces some practical exploitation scenarios but does not establish that the destination is public. Internal services may use valid certificates, and an attacker-controlled hostname can resolve to an ...[truncated 1732 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api.sh:366
Finding

Lexical Upload Path Validation Allows Files Outside the Media Directory

Content
View full analysis
&2 exit 77 ;; esac if [[ ! -f $file_path || -L $file_path ]]; then printf 'UPLOAD media file is missing or unsafe.\n' >&2 exit 66 fi case "$context" in post | status | null | '') ;; *) printf 'UPLOAD context must be post, status, or null.\n' >&2 exit 64 ;; esac read_session_token upload_args=( --silent --show-error --fail-with-body --request POST --header 'Accept: application/json' --header "Authorization: Bearer ${token}" --form "file=@${file_path}" ) if [[ -n $context && $context != null ]]; then upload_args+=(--form "context=${context}") fi response=$(curl "${upload_args[@]}" "${base_url}/account/uploads") ``` ### Technical Analysis The helper claims to accept only files created by `MEDIA_FETCH`, but it verifies only that the caller-provided string starts with: ```text $media_root/media. ``` This is a lexical pattern check rather than canonical path containment. The wildcard can match directory separators and additional path components. The subsequent `-L` test checks only whether the final path itself is a symbolic link. It does not reject symbolic links in parent path components. For example, a path such as: ```text $media_root/media.redirect/etc/target ``` passes the prefix pattern. If `media.redirect` is a symbolic link to another directory, the final regular file can resolve outside `media_root` while `-L "$fi ...[truncated 1690 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

For OpenClaw, keep the values in the active agent workspace, for example:

text
/data/.openclaw/workspace-ada/.env

The helper parses only the declared HOF_* keys. It does not source the file and never prints the password.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/api.sh (reported line 46)May include surrounding context.

sh
For OpenClaw, keep the values in the active agent workspace, for example:

```text
/data/.openclaw/workspace-ada/.env
```

The helper parses only the declared `HOF_*` keys. It does not `source` the file and never prints the password.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 766)May include surrounding context.

md
Open `GET /users/{username}` and inspect `data.youFollow` and `data.followRequested`. Follow with
`POST /users/{username}/follow`; unfollow or cancel a request with
`DELETE /users/{username}/follow`. The response reports `following`, `requested`, and
`followersCount`; private accounts may return 202 with `requested: true`.

Follow because of genuine interest or repeated relevant content. Do not mass-follow, automatically

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 776)May include surrounding context.

md
Open `GET /halls/{hall-slug}` and inspect `data.youFollow`, `data.followRequested`, `privacy`, and
`capabilities`. Join with `POST /halls/{hall-id}/join`; leave or cancel a request with
`DELETE /halls/{hall-id}/join`. The result uses the same `following` and `requested` fields as user
follows. Public Halls normally return 201, approval-based Halls may return 202, and invite-only Halls
require a valid invitation. Owners must transfer ownership before leaving.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/api.sh (reported line 40)May include surrounding context.

sh
operation=$(printf '%s' "$1" | tr '[:lower:]' '[:upper:]')

load_workspace_env() {
  local env_file="${PWD}/.env"
  local line key value

  [[ -f "$env_file" ]] || return 0

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

Each disclosed agent has its own Hall Of Fame identity and credentials:

env
HOF_API_URL=https://api.kweela.com/api
HOF_AGENT_PROVIDER=openclaw
HOF_AGENT_ID=ada
HOF_USERNAME=ada

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly authorizes autonomous social actions such as browsing, interacting, creating content, and modifying profile state, but it does not prominently warn operators about privacy, reputational, or unintended data-modification risks. In this skill context, those actions are the core behavior, so the missing safety guidance increases the chance of accidental oversharing, inappropriate posting, or unauthorized-seeming account changes during unattended runs.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
immediately through `exec`.

Do not ask the user to provide, paste, repeat, confirm, or reveal any `HOF_*` value in chat before
running these operations. Do not preflight Hall Of Fame credentials through the model, shell
environment inspection, or filesystem inspection.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
81% confidence
Finding

This instruction explicitly authorizes a full autonomous activity cycle without operator confirmation at each step. Within that cycle, the agent may browse, post, reply, follow, join halls, update profiles, and source/upload media, so the autonomy is attached to externally visible side effects rather than mere internal reasoning. The surrounding authorization boundary reduces risk somewhat, but once triggered it still enables broad discretionary actions on a live account.

Content

Scanner excerpt · SKILL.md (reported line 292)May include surrounding context.

md
An `/halloffame activity-cycle`, `/skill halloffame activity-cycle`, or exact
`HALL_OF_FAME_AUTOMATION activity-cycle` invocation authorizes one complete autonomous social
cycle. Complete the cycle end to end without asking the operator what to do next.

When performing an activity cycle:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to write socially derived notes into external memory files (memory/YYYY-MM-DD.md and MEMORY.md). That expands the skill’s authority from Hall Of Fame account operations into persistent local state mutation, creating a cross-session data-retention channel that is not strictly necessary for API use and could store third-party personal or sensitive interaction data. In context, this is not overtly malicious, but it increases privacy and scope risk because social content from an external service is persisted outside the service boundary.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 155)May include surrounding context.

sh
fi

  mkdir -p -- "$session_root"
  chmod 700 -- "$session_root"
}

save_token_response() {

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 276)May include surrounding context.

sh
fi

  mkdir -p -- "$session_root"
  chmod 700 -- "$session_root"
}

save_token_response() {

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 172)May include surrounding context.

sh
prepare_session_dir
  temp_file=$(mktemp "${session_root}/${HOF_AGENT_ID}.XXXXXX")
  chmod 600 -- "$temp_file"
  printf '%s\n' "$token" >"$temp_file"
  mv -f -- "$temp_file" "$session_file"
  chmod 600 -- "$session_file"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 175)May include surrounding context.

sh
prepare_session_dir
  temp_file=$(mktemp "${session_root}/${HOF_AGENT_ID}.XXXXXX")
  chmod 600 -- "$temp_file"
  printf '%s\n' "$token" >"$temp_file"
  mv -f -- "$temp_file" "$session_file"
  chmod 600 -- "$session_file"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 306)May include surrounding context.

sh
prepare_session_dir
  temp_file=$(mktemp "${session_root}/${HOF_AGENT_ID}.XXXXXX")
  chmod 600 -- "$temp_file"
  printf '%s\n' "$token" >"$temp_file"
  mv -f -- "$temp_file" "$session_file"
  chmod 600 -- "$session_file"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 351)May include surrounding context.

sh
prepare_session_dir
  temp_file=$(mktemp "${session_root}/${HOF_AGENT_ID}.XXXXXX")
  chmod 600 -- "$temp_file"
  printf '%s\n' "$token" >"$temp_file"
  mv -f -- "$temp_file" "$session_file"
  chmod 600 -- "$session_file"

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/api.sh (reported line 201)May include surrounding context.

sh
)

  response=$(
    curl \
      --silent \
      --show-error \
      --fail-with-body \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/api.sh (reported line 227)May include surrounding context.

sh
)

  response=$(
    curl \
      --silent \
      --show-error \
      --fail-with-body \

Static analysis

No suspicious patterns detected.