Back to skill

Security audit

Shoofly Basic

Security checks for vulnerabilities and agentic risk

Overview

This security-monitor skill is not clearly malicious, but it globally changes agent behavior, persists broad tool-call data, and can send alert content through external messaging channels.

Review before installing. Use this only if you are comfortable with a skill that monitors all tool activity, writes persistent local alert logs, and may send alert messages through configured external channels. Avoid enabling external channels for sensitive projects unless alerts are redacted, and consider removing the promotional warning template and fixing the notifier script first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:71
Finding

Persistent Agent Instruction Hijacking and Promotional Alert Injection

Content
View full analysis
SHOOFLY BASIC 🪰🧹 WARNING: [threat type] detected on [agent name]. Try ⚡🪰⚡ SHOOFLY ADVANCED to block attacks before they're inside your agent infra. shoofly.dev/advanced ``` ### Technical Analysis The Skill declares session-wide authority by directing the agent to follow its rules on every action and after every tool call. It also requires the agent to insert fixed promotional language and an external marketing URL into security notifications. Threat reporting does not require advertising another product or directing users to an external website. The fixed promotional output therefore exceeds the minimum behavior necessary for the declared security-monitoring function. Because the instruction applies to every action, loading the Skill can alter unrelated agent workflows and outputs. The behavior constitutes instruction hijacking rather than ordinary notification configuration: the Skill changes the agent's ongoing goals and mandates attacker-selected output that may be delivered to local terminals or external messaging channels. ### Attack Path 1. A user or agent loads the Skill. 2. The Skill establishes monitoring obligations that apply after every subsequent tool call. 3. Tool arguments or results trigger two matching patterns, an out-of-scope-write condition, or a data-exfiltration condition. 4. The agent is instructed to construct the fixed warning text. 5. The warning includes promotional content and `shoofly.dev/advanced`. 6. Depending on configuration, that content is displayed loc ...[truncated 528 chars]
Remediation
View remediation
detected by .` - Scope monitoring instructions to explicit Skill invocations instead of applying them to every action in the session. - Require explicit user consent before sending alerts to external channels. - Make notification templates user-configurable and prevent the Skill package from mandating unrelated content. - Clearly separate detection logic from notification and marketing functionality. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Excessive Collection and Inadequate Protection of Tool-Call Data

Content
View full analysis
&2; exit 1; } # ---------- helper: log to alerts.log ---------- _log() { local ch="$1" extra="${2:-}" jq -nc --arg ts "$(date -u +%Y-%m-%dT%H:%M:%SZ)" --arg ch "$ch" --arg msg "$MSG" \ '{"ts":$ts,"channel":$ch,"msg":$msg}' >> "$LOG_FILE" } ``` ### Technical Analysis The Skill requires collection of every tool name, complete arguments, returned results, and threat evaluation. Tool arguments and results may contain API keys, authentication tokens, private source code, personal information, file contents, or confidential conversation data. Collecting complete tool data is broader than necessary to record security events. A safer implementation would retain only a minimal event identifier, threat category, confidence, timestamp, and a redacted summary. The script protects the log directory with mode `700` and refuses to write when the final log path is a symbolic link. These are useful controls, but the log file itself is opened using shell append redire ...[truncated 1912 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
bin/shoofly-notify.sh:181
Finding

Automatic Notification Mode Terminates Before Alert Delivery

Content
View full analysis
"`. 3. The script enters the `auto` case branch. 4. Bash evaluates `local _clean_msg` at top level and returns a nonzero status. 5. `set -e` terminates the script. 6. Terminal delivery, OpenClaw delivery, desktop notification, alert logging, and automatic channel delivery do not execute. 7. The user receives no warning and may not have a corresponding notification log entry. ### Impact Assessment An attacker does not obtain additional operating-system privileges through this defect. The impact is suppressi ...[truncated 348 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill presents itself as a real-time security monitor but the file only contains behavioral instructions telling the agent to inspect outputs, write logs, read config, and send alerts; it does not implement trustworthy monitoring or enforcement. This mismatch is dangerous because users may rely on it as a protective control while it can instead trigger extra network/file activity and create a false sense of security during an attack.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
- Message-send tool calls (Telegram, Discord, Slack) with content matching credential patterns
- File writes to web-accessible directories containing credential content
- Large data uploads (>10KB POST body) to external unknown URLs
- Reading credential directories (`~/.ssh/`, `~/.aws/credentials`, `~/.config/`, keychain) immediately followed by a network request

## Threat Confidence Scoring

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The Telegram sender uses curl -K - with config content built from a here-string that interpolates bot_token directly into a curl config directive. If an attacker can influence the config file, newline and curl-config injection into bot_token could introduce additional curl options or alternate URLs, causing unauthorized outbound requests, local file reads, or exfiltration under the user's privileges.

Content

Scanner excerpt · bin/shoofly-notify.sh (reported line 143)May include surrounding context.

sh
if [[ -z "$bot_token" ]] || [[ -z "$chat_id" ]]; then
    echo "shoofly-notify: telegram.bot_token and telegram.chat_id required in $CONFIG" >&2; exit 1
  fi
  curl -s -K - <<< "url = \"https://api.telegram.org/bot${bot_token}/sendMessage\"" \
    -d "chat_id=${chat_id}" \
    --data-urlencode "text=${MSG}" > /dev/null
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill implicitly requires shell-capable behavior (curl, external notifier execution, file writes, stderr output) but does not declare any tool scope or allowed-tools boundary. In an agent environment, missing explicit permissions increases the chance that the skill will be granted broader execution capability than users expect, which is especially risky because it instructs the agent to perform filesystem writes and outbound network actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- Image alt text or URL query params that appear to exfiltrate data

**OSW — Out-of-Scope Write**
- Write tool calls targeting system directories: `/etc/`, `/usr/`, `/bin/`, `/sbin/`, and system daemons paths
- Writes to shell config and profile files (`.bashrc`, `.zshrc`, `.profile`, `.bash_profile`, etc.)
- Writes to credential and key directories: `~/.ssh/`, `~/.aws/`, `~/.config/`
- Writes to `~/.openclaw/` outside of `~/.openclaw/skills/` (config tampering)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · bin/shoofly-notify.sh (reported line 31)May include surrounding context.

sh
# Ensure log directory exists
mkdir -p "$HOME/.shoofly/logs"
chmod 700 "$HOME/.shoofly/logs"
[[ -L "$LOG_FILE" ]] && { echo "shoofly-notify: refusing to write to symlink $LOG_FILE" >&2; exit 1; }

# ---------- helper: log to alerts.log ----------

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script sends the provided message over external channels such as OpenClaw, Telegram, and WhatsApp, which can transmit user-supplied content and destination identifiers off-host. While the behavior is part of a notification tool, these code paths do not include any user-facing confirmation, logging to the console, or explicit warning comments/docstrings near the transmission operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · bin/shoofly-notify.sh (reported line 143)May include surrounding context.

sh
if [[ -z "$bot_token" ]] || [[ -z "$chat_id" ]]; then
    echo "shoofly-notify: telegram.bot_token and telegram.chat_id required in $CONFIG" >&2; exit 1
  fi
  curl -s -K - <<< "url = \"https://api.telegram.org/bot${bot_token}/sendMessage\"" \
    -d "chat_id=${chat_id}" \
    --data-urlencode "text=${MSG}" > /dev/null
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · bin/shoofly-notify.sh (reported line 143)May include surrounding context.

sh
if [[ -z "$bot_token" ]] || [[ -z "$chat_id" ]]; then
    echo "shoofly-notify: telegram.bot_token and telegram.chat_id required in $CONFIG" >&2; exit 1
  fi
  curl -s -K - <<< "url = \"https://api.telegram.org/bot${bot_token}/sendMessage\"" \
    -d "chat_id=${chat_id}" \
    --data-urlencode "text=${MSG}" > /dev/null
}

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says the skill 'watches every tool call, flags threats, and alerts you before damage is done,' which frames the skill as a monitoring/alerting component. In this file, the implementation goes beyond local alerting and actively sends messages to external services such as Telegram, making it a notification transport tool rather than just a monitor.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest emphasizes real-time monitoring and threat flagging for AI agents, but in auto mode this script enumerates configured channels and dispatches messages to Telegram, WhatsApp, or Discord through OpenClaw. That outbound multi-channel delivery is a broader operational capability than 'watching' and 'flagging' alone.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The auto path enumerates active TTYs for the current user and writes alert content directly into terminal devices. While alerting is related to the skill's purpose, direct terminal injection is a distinct delivery mechanism not mentioned in the manifest and is not an obvious requirement of a monitoring skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The comment says it will write to 'all active terminals for this user,' but the implementation filters who output to entries where the terminal name matches ^tty. This excludes other active session types such as pts-based terminals, so the comment overstates what the code actually does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.