Back to skill

Security audit

Discord Output Metrics Footer

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for adding Discord metric footers, but it directly reuses a local OpenAI Codex OAuth token and can mix telemetry across sessions.

Review before installing. The skill is not clearly malicious, but enabling it lets the plugin read your local OpenClaw OAuth profile and use that token against ChatGPT to fetch quota data. Install only if you accept that credential use, and prefer disabling quota fetching and subagent aggregation unless the plugin is changed to use scoped permissions and session-bound telemetry.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
assets/extension-template/index.ts:92
Finding

Cross-Session Telemetry Disclosure and Misattribution

Content
View full analysis
(); const recentOutputs: Usage[] = []; ``` The lookup function supports session-specific retrieval, but falls back to the latest globally observed output: ```ts function latestUsage(sessionKey?: string): Usage | undefined { if (sessionKey && recentBySession.has(sessionKey)) return recentBySession.get(sessionKey); return recentOutputs.at(-1); } ``` Subagent aggregation also processes outputs from unrelated sessions based primarily on temporal proximity: ```ts function aggregateSubagents(root?: Usage, cacheMs = 120000): { input: number; output: number } | null { if (!root) return null; const cutoff = Date.now() - cacheMs; let input = 0; let output = 0; for (const u of recentOutputs) { if (u === root || u.ts < cutoff) continue; if (Math.abs(root.ts - u.ts) > cacheMs) continue; if (u.sessionKey && root.sessionKey && u.sessionKey === root.sessionKey) continue; input += u.input ?? 0; output += u.output ?? 0; } return input || output ? { input, output } : null; } ``` The `llm_output` hook populates these shared caches: ```ts api.on("llm_output", async (event: any, ctx: any) => { const usage: Usage = { provider: event.provider ?? ctx.modelProviderId, model: event.model ?? ctx.modelId, input: n(event.usage?.input), output: n(event.usage?.output), total: n(event.usage?.total), ts: Date.now(), sessionKey: ctx.sessionKey }; recentOutputs.push(usage); if (usage.sessionKey) recentBySession.set(usage.sessionKey, usage); while (recentOutputs.length > 80) recentOutputs.shift(); }, { name: "discord-output-metrics-footer-llm-output ...[truncated 2809 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code reads OAuth access tokens from a file under the user's home directory and reuses them for its own authenticated requests. Accessing stored credentials unrelated to core footer rendering is dangerous because any plugin compromise, misuse, or unexpected behavior can expose account tokens and enable unauthorized access to upstream services.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This is a true credential-access finding: the design calls for locating and using an OpenAI Codex OAuth access token from the local auth store. Accessing bearer tokens from local credential storage materially increases risk because any implementation flaw, logging bug, path mix-up, or later feature expansion could expose or misuse the token, and the extension's purpose does not require such privileged secret access to function at a basic level.

Content

Scanner excerpt · references/implementation.md (reported line 54)May include surrounding context.

Codex quota

The extension reads the local OpenClaw auth profile store to find an OpenAI Codex OAuth access token, then fetches:

text
https://chatgpt.com/backend-api/wham/usage

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 39)May include surrounding context.

Install this skill into your OpenClaw workspace, then copy the bundled extension template:

bash
mkdir -p ~/.openclaw/extensions/discord-output-metrics-footer
cp -R assets/extension-template/* ~/.openclaw/extensions/discord-output-metrics-footer/

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes behavior that includes network-capable actions, specifically fetching live or cached Codex OAuth quota data, but it does not declare any tool scope such as permissions or allowed-tools. That mismatch weakens security review and enforcement because operators cannot clearly see or constrain the network capability the skill expects, increasing the chance of unintended outbound access when the extension is installed or modified.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Copy the bundled extension template:

bash
mkdir -p ~/.openclaw/extensions/discord-output-metrics-footer
cp -R assets/extension-template/* ~/.openclaw/extensions/discord-output-metrics-footer/

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The plugin exceeds a footer-formatting role by reading local authentication data and making an authenticated request to an external ChatGPT backend to obtain quota information. This expands the trust boundary from local message decoration to credential access and network activity, creating unnecessary exposure of sensitive tokens and user account metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code silently reads an access token from local auth profile data and prepares it for reuse without any visible disclosure, prompt, or consent flow. Hidden credential access is dangerous because users cannot reasonably assess that enabling a formatting plugin grants access to account tokens.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The plugin sends an authenticated request to chatgpt.com/backend-api/wham/usage using a bearer token obtained from local storage. Even if intended only to show remaining quota, this creates undisclosed outbound credential use and ties a cosmetic Discord footer feature to privileged remote account access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quota fetch transmits a bearer token to a remote endpoint with no user-facing notice in the plugin code. For a Discord footer skill, undisclosed authenticated network traffic is especially risky because it is not obviously necessary and may surprise users who expect purely local message augmentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill explicitly instructs the extension to read a local OAuth access token from the OpenClaw auth profile store and send it to an external service to retrieve quota data, but only mentions output-redaction rules rather than clear user consent, data-flow disclosure, storage limits, or trust boundaries. Even if the token is not printed, this creates a privacy and secret-handling risk because the extension accesses sensitive local credentials and performs network activity on the user's behalf.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.potential_exfiltration

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
assets/extension-template/index.ts:120