Back to skill

Security audit

Castreader Openclaw Skill

Security checks for vulnerabilities and agentic risk

Overview

CastReader’s core goal is understandable, but it handles arbitrary web pages and extracted text in ways that create review-level security and privacy risks.

Install only if you are comfortable with page text and generated summaries being sent to a remote TTS service and audio being sent through Telegram. Avoid private, internal, authenticated, paywalled, business, chat, document, and ebook URLs unless the skill is fixed to use HTTPS, validate URLs, keep Chromium sandboxing enabled, use safe temp files, and avoid shell interpolation for summaries.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/read-url.js:29
Finding

Article Text and API Credentials Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract.js:21
Finding

Unrestricted URL Navigation Permits Server-Side Request Forgery

Content
View full analysis
'); process.exit(1); } extract(url) ``` `read-url.js` passes the supplied URL directly to the extractor: ```javascript const output = execFileSync('node', [extractScript, url], { encoding: 'utf-8', timeout: 60000, }); extract = JSON.parse(output); fs.writeFileSync(extractFile, JSON.stringify(extract, null, 2)); ``` ### Technical Analysis No validation restricts the URL to public HTTP or HTTPS resources. The implementation does not reject loopback, RFC1918 private addresses, link-local addresses, cloud metadata servic ...[truncated 1691 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract.js:29
Finding

Chromium Sandbox Disabled While Rendering Untrusted Pages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:68
Finding

Generated Summary Text Is Interpolated into a Shell Command

Content
View full analysis
" > /tmp/castreader-summary.txt node scripts/generate-text.js /tmp/castreader-summary.txt ``` The summary is generated from extracted webpage paragraphs: ```markdown 📋 Summary: {write 2-3 sentence summary from paragraphs} ``` ### Technical Analysis Webpage content is untrusted input. A malicious article can contain quotes, command substitutions, backticks, shell metacharacters, or instructions intended to influence the generated summary. The prescribed command interpolates that generated text into a shell string. Double quotes do not neutralize command substitution such as `$(...)` or backticks, and an embedded quote can terminate the quoted argument. Newlines may also introduce additional commands. This is an instruction-level coding flaw: the package does not invoke a shell in `generate-text.js`, but `SKILL.md` explicitly directs the hosting Agent to construct and execute the unsafe shell command. ### Attack Path 1. An attacker publishes a webpage containing text designed to make a summary include shell syntax, such as command substitution or a closing quotation mark followed by a command. 2. A user asks the Skill to read that URL. 3. The Agent extracts the page and creates the requested summary. 4. The user selects summary-only audio. 5. Following `SKILL.md`, the Agent substitutes the summary into the `echo ""` command. 6. The shell interprets attacker-controlled syntax while creating the summary file. 7. Injected commands execute with the operating-system privileges of the Agent process. Successful exploitation depends on the gen ...[truncated 461 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/read-url.js:35
Finding

Predictable Shared Temporary Paths Store Extracted Content without Explicit Protection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package-lock.json:875
Finding

Session Setup Executes an Unsupported Dependency's Installation Script

Content
View full analysis
&& npm install --silent 2>/dev/null ``` ``` The dependency is specified with a semver range: ```json "dependencies": { "puppeteer": "^23.0.0" } ``` The lockfile currently resolves the package with integrity metadata, but records an installation script and an unsupported release: ```json "node_modules/puppeteer": { "version": "23.11.1", "resolved": "https://registry.npmjs.org/puppeteer/-/puppeteer-23.11.1.tgz", "integrity": "sha512-53uIX3KR5en8l7Vd8n5DUv90Ae9QDQsyIthaUFVzwV6yU750RjqRznEtNMBT20VthqAdemnJN+hxVdmMHKt7Zw==", "deprecated": "< 24.15.0 is no longer supported", "hasInstallScript": true, "license": "Apache-2.0", "dependencies": { "@puppeteer/browsers": "2.6.1", "chromium-bidi": "0.11.0", "cosmiconfig": "^9.0.0", "devtools-protocol": "0.0.1367902", "puppeteer-core": "23.11.1", "typed-query-selector": "^2.12.0" } } ``` ### Technical Analysis Running `npm install` executes permitted package lifecycle scripts with the privileges of the Agent account. Puppeteer's installation behavior is expected for browser provisioning, and the lockfile pins the package to an integrity-checked registry artifact. No malicious dependency or unsafe non-registry source was identified. Nevertheless, repeating installation during runtime increases supply-chain and network exposure. Suppressing standard error also hides useful warnings and failures. The locked Puppeteer release is explicitly marked unsupported, which increases the likelihood that browser security fixes are unavailable. This finding represents unsafe dependency lifecycle ...[truncated 1108 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises an end-to-end 'read any web page aloud' skill that extracts article text from any URL and converts it to audio (MP3). However, the supplied code is focused on extracting readable text from the current document: scoring content candidates, filtering navigation/comments/ads, handling shadow DOM, splitting paragraphs, refining highlightable elements, and applying site-specific extraction rules. There is also a WeChat extractor and embedded Mozilla Readability logic. These behaviors support article extraction, but the key promised capabilities—voice synthesis, audio playback, MP3 creation, and likely URL retrieval—are absent from this code chunk. Because the actual code's primary visible purpose is extraction rather than reading aloud or audio generation, the description materially overstates what this code does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises an end-user capability centered on turning any web page URL into spoken audio/MP3. The code shown instead focuses on extracting readable text/content from the current document, parsing metadata, caching extraction results, and handling special cases such as WeRead canvas-based layouts and highlight overlays. While article extraction is one supporting part of a read-aloud tool, the core promised behavior—AI voices, audio playback/synthesis, and MP3 generation—is absent from this code chunk. Additionally, the chunk includes substantial functionality unrelated to the declared description, namely DOM/canvas text mapping and highlight overlay logic for a specific reader environment. Therefore the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on a text-to-speech skill that takes any URL/web page and converts article text into spoken audio/MP3. This code chunk instead implements extraction and synchronization infrastructure: parsing page content from multiple domains, reconstructing paragraph positions, creating highlight overlays, and handling Kindle-specific OCR and glyph decoding. Those are materially different capabilities from 'read aloud' and 'convert to audio.' While text extraction could support a TTS product, the supplied code does not itself perform audio generation, voice selection, or MP3 conversion, and it includes substantial undeclared behavior (highlighting, OCR, multi-site document/chat extraction, extension messaging). Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose centers on turning arbitrary web pages into spoken audio/MP3. However, this code chunk is an extraction pipeline only: it parses DOM content, detects titles/language, handles site-specific selectors, deduplicates paragraphs, supports highlightable element mapping, and waits for SPA content to stabilize. It is heavily tailored to extracting text from chat AI websites and some document/reading sites. There is no evidence of speech synthesis APIs, audio encoding, MP3 creation, network calls to a TTS service, or playback controls. Therefore the supplied code does not accurately represent the declared 'read aloud / convert URL to audio' purpose; it represents a text-extraction subsystem with materially different primary behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code aligns with the text-extraction portion of the description but does not implement the core advertised audio functionality. It fetches a URL and extracts clean article text using Puppeteer and an extractor bundle, then outputs JSON. There is no code for speech synthesis, AI voice selection, audio encoding, MP3 creation, or reading content aloud. Therefore, the declared description materially overstates the skill’s actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description promises an end-to-end webpage-to-audio capability: take any URL, extract article text, and read the page aloud. This code chunk does only the TTS portion for one paragraph from an already-produced extraction file. While generating natural-voice MP3 audio is aligned with part of the description, the primary user-facing promise of accepting a URL and extracting webpage/article content is not implemented here. The code’s actual scope is narrower and materially different: paragraph-level audio generation from structured local input, with reliance on another tool (extract.js) for extraction.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description centers on taking a webpage URL, extracting article text, and reading that page aloud. The actual code chunk only accepts a local text file path as input, reads its contents, calls a text-to-speech API, and writes an MP3 output file. While the TTS/audio generation portion is consistent with 'convert text to audio,' the key advertised capability—handling arbitrary web pages/URLs and extracting article text—is absent from this code. That is a material purpose mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims the skill can extract article text from any URL and convert it to audio (MP3). The code instead automates Chrome, loads a specific extension, navigates to a page, and sends a TOGGLE_READING message to trigger in-browser read-aloud playback. This supports 'listen to a webpage' at a high level, but materially differs from the declared implementation and capabilities: there is no text extraction pipeline, no MP3 creation/export, and the code relies on a local browser extension and browser automation not disclosed in the description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bundle includes targeted extraction for private/editable cloud document platforms such as Google Docs, Notion, Feishu, DingTalk, and Yuque, including logic for editable and dynamically loaded content. That enables access to potentially confidential business or personal documents outside the advertised article/webpage scope, raising serious data exposure risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bundle implements extraction logic for many contexts far beyond ordinary public webpages, including AI chats, cloud docs, ebook readers, and novel platforms. That materially expands the data-access surface of the skill and enables collection of sensitive or copyrighted content inconsistent with the declared purpose, increasing the risk of over-collection and misuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Kindle-specific code captures blob-backed page images, performs OCR, inspects proprietary render/token data, and builds highlight overlays. This goes beyond normal webpage text extraction and can recover book content from protected reader contexts, creating elevated privacy, copyright, and policy risk if invoked on user reading sessions.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: basic-ftp==5.2.0 — 4 advisory(ies): GHSA-6v7q-wjvx-w8wg (basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Exe); CVE-2026-39983 (basic-ftp has FTP Command Injection via CRLF); CVE-2026-41324 (basic-ftp vulnerable to denial of service via unbounded memory consumption in Cl) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
94% confidence
Finding

extract-zip is pulled in by @puppeteer/browsers and is used to unpack browser archives during install/runtime setup. If a malicious or tampered archive were ever processed, the cited symlink/path traversal flaws could permit writes outside the intended extraction directory, potentially overwriting files in the build or execution environment.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
90% confidence
Finding

ws is a direct transitive dependency of puppeteer-core and is used for browser protocol communication. A vulnerable WebSocket implementation can expose the process to memory disclosure or memory-exhaustion denial of service if an attacker can interfere with or influence WebSocket traffic to the browser automation channel, which is more plausible in a networked skill that fetches arbitrary web content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly states that extracted page text is sent to a remote TTS API, but it does not clearly warn users that webpage contents may leave the local device. This is risky because users may paste private, internal, paywalled, or sensitive URLs assuming processing is local, causing unintended disclosure of extracted content to a third-party service.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill invokes local Node scripts that, by description and setup, can perform network access and environment-dependent operations, yet the manifest declares no explicit tool scope or permission boundaries. This makes the skill harder to audit and allows capability creep beyond what users and the platform metadata clearly disclose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad invocation phrases can cause the skill to trigger in situations where the user did not intend URL extraction, script execution, or Telegram delivery. In this skill, accidental activation is more dangerous because activation can lead to network access, local command execution, and outbound messaging rather than a harmless local transformation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to extract a Telegram chat ID from message metadata and use it in every outbound send operation. That introduces a separate messaging/exfiltration channel not disclosed in the high-level purpose, increasing the risk of sending content to unintended recipients or using the skill as a data-delivery mechanism.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Mandating use of an external message tool to transmit files extends the skill from local content processing into outbound communication. In context, that is more dangerous because webpage-derived or summarized content can leave the current interaction boundary and be delivered over Telegram without a clearly disclosed warning in the skill metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not warn users that processed webpage content will be sent as audio over Telegram. This undermines informed consent and increases privacy risk, especially if the extracted page contains personal, proprietary, or otherwise sensitive information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The summary-only path still performs file creation and Telegram delivery, so even reduced-content flows retain the same outbound data-transfer risk. Because summaries may include sensitive extracted material, the context does not make this safer; it still creates an undeclared exfiltration path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The WeRead extractor always returns "zh" from extractLanguage(), regardless of actual page content or user preference. This is a natural-language locale policy issue because it enforces a specific language outcome without offering opt-in or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code contains dedicated extractors for multiple AI assistant sites that selectively harvest assistant responses and related conversation content. In a skill presented as reading webpages/articles aloud, this is scope expansion into potentially sensitive conversational data, which may include private prompts, outputs, and embedded secrets.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/generate-paragraph.js:25

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/generate-text.js:16

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/read-url.js:29