Back to skill

Security audit

skill shield

Security checks for vulnerabilities and agentic risk

Overview

This security-scanner skill mostly matches its stated purpose, but it ships an under-disclosed authenticated Moltbook posting script with a hardcoded bearer token and makes stronger safety claims than its simple scanner supports.

Review this package before installing. The local scanner may be useful, but do not treat its A-F rating as proof of safety, avoid relying on the unpinned npx install path, and do not run the Moltbook publishing script unless the hardcoded token has been removed and replaced with your own explicitly scoped credential.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/upload_to_moltbook.py:12
Finding

Hardcoded Moltbook API Bearer Token

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/skillshield.py:184
Finding

Bypassable Text-Matching Scanner Produces Misleading Security Trust Ratings

Content
View full analysis
List[str]: """Get all relevant files to scan""" files = [] scannable_extensions = ('.py', '.js', '.ts', '.md', '.sh', '.json', '.yaml', '.yml', '.toml', '.txt') if os.path.isfile(path): if path.endswith(scannable_extensions): files.append(path) else: for root, dirs, filenames in os.walk(path): dirs[:] = [d for d in dirs if not d.startswith('.') and d not in ['node_modules', '__pycache__', 'venv', '.git']] for filename in filenames: if filename.endswith(scannable_extensions): files.append(os.path.join(root, filename)) return files ``` Sensitive behavior is detected through raw textual matching: ```python def _check_sensitive_files(self, content: str, filename: str): """Check for access to sensitive files""" for pattern, desc, severity in self.SENSITIVE_FILES: if re.search(pattern, content, re.IGNORECASE): self._add_warning('sensitive_file', severity, desc, filename) self.permissions['files']['read'].add(pattern) ``` The exfiltration rule relies on file-wide string co-occurrence rather than actual data flow: ```python has_env_read = re.search(r'os\.environ|getenv|os\.getenv', content) has_http_send = re.search(r'requests\.(post|put|patch)|urllib', content) has_json_encode = re.search(r'json\.dumps', content) if has_env_read and has_http_send: severity = 'critical' if has_json_encode else 'high' ``` Trust ratings are then derived solely from the warnings produced by th ...[truncated 3469 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:26
Finding

Unpinned npx Installation Executes Mutable Third-Party Supply-Chain Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (28)

Tainted flow: 'req' from os.environ.get (line 25, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The script sends an authenticated HTTP request using a bearer token sourced from the environment or, worse, a built-in fallback secret. While posting to Moltbook is intentional, this still creates a credential-handling and outbound-network risk because the skill is advertised as a security scanner, not as a publisher, and it transmits privileged credentials to an external service.

Content

Scanner excerpt · scripts/upload_to_moltbook.py (reported line 36)May include surrounding context.

python
method='POST'
        )
        
        with urllib.request.urlopen(req, timeout=10) as response:
            result = json.loads(response.read())
            return result
    except Exception as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skillshield.py (reported line 31)May include surrounding context.

python
# Sensitive file patterns
    SENSITIVE_FILES = [
        (r'\.env', '读取 .env 文件', 'high'),
        (r'\.bashrc', '读取 .bashrc', 'medium'),
        (r'\.zshrc', '读取 .zshrc', 'medium'),
        (r'\.ssh[/\\]', '访问 SSH 目录', 'critical'),

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skillshield.py (reported line 31)May include surrounding context.

python
# Sensitive file patterns
    SENSITIVE_FILES = [
        (r'\.env', '读取 .env 文件', 'high'),
        (r'\.bashrc', '读取 .bashrc', 'medium'),
        (r'\.zshrc', '读取 .zshrc', 'medium'),
        (r'\.ssh[/\\]', '访问 SSH 目录', 'critical'),

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
70% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/skillshield.py (reported line 74)May include surrounding context.

python
�幕截图', 'high'),
        (r'webhook', 'Webhook 调用', 'low'),
        (r'socket\.', '网络 socket 操作', 'medium'),
        (r'ftplib|smtplib', 'FTP/SMTP 协议', 'medium'),
        (r'tempfile\.(mkdtemp|mkstemp)', '创建临时文件', 'low'),
    ]
    
    # Suspicious domains
    SUSPICIOUS_DOMAINS = [
        'webhook', 'pastebin', 'requestbin', 'hook', 
        'ngrok', 'burpcollaborator', 'interactsh'
    ]
    
    def __init__(self, rules_dir: str = None):
        self.rules_dir = rules_dir or os.path.join(os.path.dirname(__file__), '..', 'rules')
        self.warnings = []
        self.permissions = {
            'files': {'read': set(), 'write': set(), 'delete': set()},
            'network': {'urls': set(), 'domains': set()},
            'system': {'commands': set(), 'imports': set()},
            'data': {'env_vars': set(), 'credentials': set()}
        }
        self.file_hashes = {}
    
    def scan(self, skill_path: str, deep_scan: boo

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Authenticated posting to a third-party service is not justified by the stated role of a skill security scanner and expands the attack surface unnecessarily. Any capability to send bearer-authenticated external requests from a trusted scanning environment can be abused for spam, data leakage, or unauthorized account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The code embeds a fallback API key directly in source, enabling anyone with code access to reuse the credential for unauthorized Moltbook actions. Hardcoded secrets are especially dangerous here because the script immediately uses the key for authenticated network operations, turning source disclosure into direct account compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This function performs authenticated publication to an external social platform, which is unrelated to the stated purpose of analyzing skills for security. That mismatch is dangerous because users may grant trust and permissions appropriate for a scanner while the code actually performs external content distribution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The main execution path is devoted to composing and posting promotional content rather than performing any security analysis. In a skill that claims to protect against malicious behavior, this purpose deviation materially increases risk because it suggests hidden or misleading functionality under a trusted label.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary description is written in Chinese only, which imposes a language choice on users without any opt-in or indication that the skill is region-specific. The policy for this audit flags language or locale constraints when the file does not offer a choice or clearly justify the limitation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to execute npx skills add openclaw/skillshield without pinning a specific version. This makes installation depend on whatever package/version is current at execution time, increasing supply-chain risk if the package is updated maliciously, compromised, or unexpectedly changed. In a security-focused skill, this is more dangerous because users are likely to grant the tool elevated trust.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill metadata does not declare any tool scope or permissions even though the documented commands indicate capabilities involving environment access, file reads, network activity, and shell execution. Missing capability declarations weaken reviewability and consent, making it easier for a skill to obtain broader access than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad triggers such as generic security-scan phrases can cause the skill to activate during ordinary conversations, increasing the chance of unintended execution. In a skill that may read files, access env vars, use shell commands, or reach the network, accidental invocation materially increases exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Most of the user-facing documentation is written in Chinese, while the file does not state that the skill is region-specific or provide an opt-in language selection. This creates a locale policy issue because the skill effectively imposes a language preference on users without notice or choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring states it will 'Automatically scan skills on Moltbook and post security reports'. In practice, the monitoring loop only identifies posts mentioning skill-related keywords and prints a suggestion to contact the author, while both scanning-by-URL and comment posting are unimplemented stubs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The class docstring says it will 'Monitor Moltbook for new skills and scan them', and methods such as 'Download and scan a skill from URL' and 'Post a comment to a Moltbook post' are documented as real behaviors. However, the actual code leaves these operations as TODOs or placeholder output, which contradicts the stated intent of the documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated security comment strings are entirely in Chinese, and the file does not indicate that this skill is intended only for a Chinese-speaking or region-specific audience. This can violate language/locale policy expectations because users are not given an opt-in or alternative language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The monitoring output and command-line help strings include Chinese-only user-facing text, but the script does not offer a language selection mechanism or justify a Chinese-only deployment context. That creates a natural-language policy issue under the locale-choice requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains multiple user-facing print strings entirely in Chinese, including error messages and publishing instructions. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the tool is clearly documented as region-specific, which is not indicated here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 48)May include surrounding context.

python
# Run self-scan
    print("\n🔍 正在执行自检扫描...")
    scan_result = subprocess.run(
        [sys.executable, str(skill_dir / 'scripts' / 'skillshield.py'), 
         'scan', str(skill_dir)],
        capture_output=True,

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains numerous hard-coded Chinese descriptions, warnings, summaries, CLI help strings, and status messages, making the skill effectively Chinese-only. The file does not offer any language selection, opt-in, or documentation that this is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.