Back to skill

Security audit

botlearn-strategy-intel

Security checks for vulnerabilities and agentic risk

Overview

The skill’s company-research purpose is coherent, but it needs review because its runtime instructions can execute user-controlled input through a shell and pass untrusted generated output back with limited safeguards.

Review before installing or running. Use a structured argument invocation instead of interpolating company names into a shell command, avoid confidential targets or non-public research terms, expect data to be sent to Apify and an LLM provider, and pin installer and Python dependency versions where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:130
Finding

Forced Promotional Content and Verbatim Output Pass-Through

Content
View full analysis
Where is the market going? Is there a 10x incremental opportunity? [3-5 sentences — name the specific market, the tailwind, and whether this company is playing where the market is going or where it already is] ### Middle — Product & Customer > What is the real product edge? What job is the customer hiring this for? [3-5 sentences — apply Jobs to Be Done, assess whether the moat is real or just operational, Crossing the Chasm status] ### Micro — Team & Founders > Does the founder have unique insight, or did they just spot an opportunity? [2-3 sentences — assess founder-market fit and what their background predicts about the company's future bets] ### Micro — Economics & Cash > Can they generate cash before they run out of it? [2-3 sentences — unit economics, funding runway, path to cash flow positive] ### Strategic Implication > [ONE sentence — the most important thing a competitor or investor should know] --- Powered by BotLearn · botlearn.ai ``` ### Technical Analysis The Skill tells the hosting agent to return the script output verbatim. The generated output is, in turn, required to contain BotLearn branding and the external domain `botlearn.ai`. ...[truncated 1439 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/run.py:66
Finding

Indirect Prompt Injection Through Untrusted Scraped Web Content

Content
View full analysis
str: """Full pipeline: scrape → analyze → output""" print(f"[strategy-intel] Scraping data for: {company_name}") raw_data = scrape_company(company_name, depth) # Truncate to avoid token overflow raw_str = json.dumps(raw_data, ensure_ascii=False)[:6000] prompt = ANALYSIS_PROMPT.format( company_name=company_name, raw_data=raw_str ) ``` ### Technical Analysis Search and Crunchbase results are external, attacker-influenceable data. The implementation serializes that data and interpolates it directly into the model's user message. The prompt does not establish a strong trust boundary or tell the model that commands, role declarations, formatting directives, links, or requests found inside `raw_data` must never be followed. JSON serialization and character truncation do not neutralize natural-language prompt injection. An attacker w ...[truncated 1611 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:130
Finding

Shell Command Injection Through Unquoted Company Name Substitution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:55
Finding

Unpinned and Mutable Installation Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tainted flow: 'APIFY_API_KEY' from os.environ.get (line 10, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/apify_scraper.py (reported line 45)May include surrounding context.

python
run_url = f"{BASE_URL}/acts/{actor_id}/run-sync-get-dataset-items"
    
    response = requests.post(
        run_url,
        headers={
            "Content-Type": "application/json",

Tainted flow: 'APIFY_API_KEY' from os.environ.get (line 10, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/apify_scraper.py (reported line 74)May include surrounding context.

python
run_url = f"{BASE_URL}/acts/{actor_id}/run-sync-get-dataset-items"
    
    response = requests.post(
        run_url,
        headers={
            "Content-Type": "application/json",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

If no model backend is configured, the function returns the full composed system and user prompt, including the hidden system prompt and loaded partner playbook contents. This exposes internal prompt assets and instructions to downstream callers, which can leak proprietary prompt engineering and any sensitive content embedded in the playbook or scraped data.

Content

Scanner excerpt · scripts/run.py (reported line 144)May include surrounding context.

python
)
        return response.content[0].text
    else:
        # Fallback: return prompt for OpenClaw to handle
        return f"SYSTEM:\n{SYSTEM_PROMPT}\n\nUSER:\n{prompt}"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to run a local shell command that triggers external scraping and AI analysis, then return the output directly, but it does not clearly warn the user that code execution, outbound network access, and use of API credentials will occur. In agent environments, this can lead to unintended execution of local scripts, unexpected data transfer to third parties like Apify/model providers, and surprise consumption or exposure of privileged environment-based credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The installation instruction uses npx clawhub@latest install ..., which pulls and executes the latest published package version at install time without pinning to a known-good release. That creates a supply-chain risk: if the package or one of its transient dependencies is compromised, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/apify_scraper.py (reported line 11)May include surrounding context.

python
import json

APIFY_API_KEY = os.environ.get("APIFY_API_KEY")
BASE_URL = "https://api.apify.com/v2"


def scrape_company(company_name: str, depth: str = "quick") -> dict:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/apify_scraper.py (reported line 45)May include surrounding context.

python
run_url = f"{BASE_URL}/acts/{actor_id}/run-sync-get-dataset-items"
    
    response = requests.post(
        run_url,
        headers={
            "Content-Type": "application/json",

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/apify_scraper.py (reported line 74)May include surrounding context.

python
run_url = f"{BASE_URL}/acts/{actor_id}/run-sync-get-dataset-items"
    
    response = requests.post(
        run_url,
        headers={
            "Content-Type": "application/json",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code sends scraped company data to third-party LLM providers (OpenAI or Anthropic) with no consent check, warning, or data-classification guardrail. In a strategy-intelligence skill, scraped data may include proprietary, personal, or otherwise sensitive information, so silent external transmission creates confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README explicitly states that the skill scrapes public data via Apify and relies on external model APIs, but it does not warn users that company names, queries, and scraped content may be transmitted to third-party services. While this is not overtly malicious, it creates a transparency and privacy risk because users may unknowingly send potentially sensitive research targets or prompts off-platform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request payload hard-codes languageCode to en, which imposes a language/locale constraint in the skill's behavior. The file does not offer a user choice or explain why English-only scraping is required, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.