Back to skill

Security audit

Remnawave Account Creator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an admin account-creation tool, but it needs Review because it uses privileged credentials insecurely and can modify or delete accounts without enough safeguards.

Install only in a tightly controlled admin workspace. Treat the example VPN/subscription values as compromised, rotate any matching credentials, require validated TLS, avoid running the bundled delete/test scripts against production, and review the create/delete/logging code before allowing an agent to invoke it with untrusted account parameters.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
create-account.js:481
Finding

Shell Command Injection Through User-Controlled Account Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
create-account.js:116
Finding

TLS Certificate Validation Can Be Disabled for Credential-Bearing Connections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
README.md:49
Finding

Live-Looking VPN and Subscription Credentials Are Embedded in Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
log-creation.js:96
Finding

Full Subscription URLs and Personal Data Are Stored in Plaintext Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
log-creation.js:153
Finding

Unsanitized Username Is Incorporated into Log File Paths

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (138)

Tainted flow: 'HEADERS' from os.environ.get (line 21, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The script sends an Authorization bearer token derived from the environment or a local .env file in outbound HTTPS requests while explicitly disabling TLS certificate verification. This creates a realistic man-in-the-middle risk where the API token and response data could be intercepted or modified, especially since the destination is a raw IP address rather than a hostname with normal certificate validation expectations.

Content

Scanner excerpt · test-update-user.py (reported line 41)May include surrounding context.

python
try:
        if method == 'GET':
            resp = requests.get(url, headers=HEADERS, verify=False)
        elif method == 'PUT':
            resp = requests.put(url, json=data, headers=HEADERS, verify=False)
        elif method == 'PATCH':

Tainted flow: 'HEADERS' from os.environ.get (line 21, credential/environment) → requests.put (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

This PUT request transmits a bearer token and performs authenticated state-changing operations while TLS verification is disabled. An attacker positioned on the network could intercept the token or tamper with the request, potentially causing unauthorized account modifications on the remote service.

Content

Scanner excerpt · test-update-user.py (reported line 43)May include surrounding context.

python
if method == 'GET':
            resp = requests.get(url, headers=HEADERS, verify=False)
        elif method == 'PUT':
            resp = requests.put(url, json=data, headers=HEADERS, verify=False)
        elif method == 'PATCH':
            resp = requests.patch(url, json=data, headers=HEADERS, verify=False)
        elif method == 'POST':

Tainted flow: 'HEADERS' from os.environ.get (line 21, credential/environment) → requests.patch (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The PATCH request leaks sensitive authentication material to the network stack under insecure transport settings because certificate verification is disabled. Since this endpoint updates user data, interception or tampering could directly lead to unauthorized changes and token compromise.

Content

Scanner excerpt · test-update-user.py (reported line 45)May include surrounding context.

python
elif method == 'PUT':
            resp = requests.put(url, json=data, headers=HEADERS, verify=False)
        elif method == 'PATCH':
            resp = requests.patch(url, json=data, headers=HEADERS, verify=False)
        elif method == 'POST':
            resp = requests.post(url, json=data, headers=HEADERS, verify=False)

Tainted flow: 'HEADERS' from os.environ.get (line 21, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The POST request sends the bearer token and modification payload to a remote endpoint with TLS verification turned off. This makes credential exposure and request/response manipulation plausible, particularly because the script automates administrative-style user and squad updates.

Content

Scanner excerpt · test-update-user.py (reported line 47)May include surrounding context.

python
elif method == 'PATCH':
            resp = requests.patch(url, json=data, headers=HEADERS, verify=False)
        elif method == 'POST':
            resp = requests.post(url, json=data, headers=HEADERS, verify=False)
        
        print(f"状态码:{resp.status_code}")
        try:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The skill documents a destructive API operation that accepts a user-controlled UUID and presents it without any guardrails, confirmation workflow, authorization scoping guidance, or safety constraints. In an agent/tooling context, this can enable parameter abuse or accidental account deletion if untrusted input is passed into the DELETE call, especially since the same document also points to a live bearer token location.

Content

Scanner excerpt · API-REFERENCE.md (reported line 164)May include surrounding context.

6. 删除用户

http
DELETE /api/users/{uuid}

响应: 200 OK

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
78% confidence
Finding

The documented curl command includes the '-k' option, which disables TLS certificate validation while sending an authorization bearer token to a remote admin API. In this skill context, that makes the workflow more dangerous because the tool manages privileged account operations; using insecure TLS settings can expose tokens and administrative changes to man-in-the-middle attacks.

Content

Scanner excerpt · README.md (reported line 90)May include surrounding context.

或者运行更新命令(如果后续 API 支持):

bash
curl -k -X PATCH "https://8.212.8.43/api/users/{uuid}" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"trafficResetInterval": "WEEKLY"}'

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The script directly accesses a bearer token from a fixed local .env path and then uses it for privileged API operations. In an agent-skill setting, secret consumption from user workspace files is sensitive because it can silently leverage existing credentials to change remote system state, especially when combined with disabled TLS verification.

Content

Scanner excerpt · add-user-to-squad.py (reported line 10)May include surrounding context.

python
import os

# 读取配置
ENV_FILE = os.path.expanduser('~/.openclaw/workspace/.env')
with open(ENV_FILE) as f:
    for line in f:
        if line.startswith('REMNAWAVE_API_TOKEN='):

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Passing --force-recreate allows the script to delete an existing user account without an interactive confirmation or strong warning. In an administrative account-management context, destructive actions on production identities can cause service disruption, data loss, and unintended revocation of user access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

On a create failure indicating a duplicate username, the script may automatically search for and delete an existing account, then retry creation, without prior operator approval. This is dangerous because an error path can silently trigger destructive actions against legitimate accounts, increasing the blast radius of API inconsistencies or lookup errors.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · add-user-to-squad-generic.js (reported line 22)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · create-account.js (reported line 33)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · create-account.js (reported line 44)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · create-account.js (reported line 106)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · delete-user.js (reported line 14)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · get-by-username.js (reported line 11)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/env-loader.js (reported line 4)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/env-loader.js (reported line 14)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/env-loader.js (reported line 18)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/env-loader.js (reported line 20)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/env-loader.js (reported line 32)May include surrounding context.

js
/**
 * Remnawave API Token 加载器
 * 
 * 从 .env 文件读取 REMNAWAVE_API_TOKEN
 * 
 * 用法:
 * const { getRemnawaveToken } = require('./lib/env-loader');

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · add-user-to-squad-generic.js (reported line 18)May include surrounding context.

js
const path = require('path');

// .env 文件路径(workspace 根目录)
const ENV_FILE = path.join(__dirname, '../../../.env');

/**
 * 从 .env 文件读取 Remnawave API Token

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · add-user-to-squad-generic.js (reported line 30)May include surrounding context.

js
const path = require('path');

// .env 文件路径(workspace 根目录)
const ENV_FILE = path.join(__dirname, '../../../.env');

/**
 * 从 .env 文件读取 Remnawave API Token

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · create-account.js (reported line 27)May include surrounding context.

js
const path = require('path');

// .env 文件路径(workspace 根目录)
const ENV_FILE = path.join(__dirname, '../../../.env');

/**
 * 从 .env 文件读取 Remnawave API Token

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · create-account.js (reported line 41)May include surrounding context.

js
const path = require('path');

// .env 文件路径(workspace 根目录)
const ENV_FILE = path.join(__dirname, '../../../.env');

/**
 * 从 .env 文件读取 Remnawave API Token

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/env-loader.js (reported line 15)May include surrounding context.

js
const path = require('path');

// .env 文件路径(workspace 根目录)
const ENV_FILE = path.join(__dirname, '../../../.env');

/**
 * 从 .env 文件读取 Remnawave API Token

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
add-squad-to-iven.js:15

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
add-squad-to-user.js:15

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
add-user-to-squad-generic.js:74

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
create-account.js:106

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
delete-pear-pc.js:17

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
delete-single-user.js:18

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
delete-user.js:14

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
get-by-username.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
get-user.js:15

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
list-all-squads.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
list-all-users.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-account.js:50

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-iven.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-kiki-all.js:10

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-kiki-full.js:10

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-rui-all.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-rui-full.js:10

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-rui.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-selene.js:12

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
search-users.js:21

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SOP-搜索账号.md:69

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
add-user-to-squad.py:32

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
check-prerequisites.js:198

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
test-update-user.py:41