Back to skill

Security audit

Meo Mai Moi MCP

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for connecting Meo Mai Moi, but it asks for write-capable OAuth access by default and documents a user-supplied code exchange in a way that could be unsafe if run through a shell.

Review the requested OAuth scopes before installing or authorizing. Prefer narrow read-only scopes for initial connection, grant write scopes only for specific tasks, and do not let an agent paste an authorization code into a shell command unless the client passes it as a literal argument and validates it conservatively.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/openclaw.md:58
Finding

OAuth Authorization Code Can Be Used for Shell Command Injection

Content
View full analysis
' ``` ``` ### Technical Analysis The documented procedure accepts any bare string that does not contain `=` or `&` as an OAuth authorization code. It then demonstrates placing that value inside a single-quoted shell command. The validation rules do not reject single quotes, command separators, newlines, control characters, shell metacharacters, or unexpectedly long values. Consequently, a value such as: ```text '; attacker-command; # ``` contains neither `=` nor `&`, so it satisfies the documented bare-code rule. If an agent substitutes it into the command and executes the resulting string through a shell, the single quote terminates the intended argument and the subsequent content is interpreted as a separate command. Keeping this exchange in a private channel protects the credential from disclosure but does not prevent a malicious or compromised participant in that channel from supplying an injection payload. ### Attack Path 1. The agent starts the documented headless OpenClaw OAuth flow. ...[truncated 1179 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/connection.md:27
Finding

Broad Connection Requests Automatically Receive Unnecessary Write Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
5. Only after projection, discover tools and start with a read such as
   `list_pets`.

Never ask for an OAuth access token, refresh token, client secret, stored
OAuth file, or Meo personal API token. A headless OpenClaw flow has a narrow
private-chat exception for the short-lived authorization URL and single-use
code; follow [references/openclaw.md](references/openclaw.md).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/openclaw.md (reported line 60)May include surrounding context.

md
- Successful probe but missing native Meo tools in the current chat → ask for
  `/new` or `/reset`; do not authorize again.

Never paste access tokens, refresh tokens, personal API tokens, invitation
URLs/codes, authorization headers, or full personal records into chat, prompts,
issues, or logs. The only connection exception is OpenClaw's short-lived,
PKCE-bound authorization URL and single-use code (or a private paste of the

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/safety.md (reported line 40)May include surrounding context.

md
- Successful probe but missing native Meo tools in the current chat → ask for
  `/new` or `/reset`; do not authorize again.

Never paste access tokens, refresh tokens, personal API tokens, invitation
URLs/codes, authorization headers, or full personal records into chat, prompts,
issues, or logs. The only connection exception is OpenClaw's short-lived,
PKCE-bound authorization URL and single-use code (or a private paste of the

Static analysis

No suspicious patterns detected.