Back to skill

Security audit

A skill for OpenClaw that verifies link validity, source credibility, and factual accuracy of online content.

Security checks for vulnerabilities and agentic risk

Overview

The skill is a simple URL checker, but it overstates fact-checking abilities and can make unrestricted network requests to any user-supplied URL.

Review before installing. Use it only for non-sensitive public URLs, and do not rely on it for real fact-checking unless the publisher adds actual verification logic, source evidence, URL allowlisting or private-network blocking, request timeouts, response-size limits, and clear privacy disclosure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:6
Finding

Server-Side Request Forgery Through Unrestricted User-Supplied URLs

Content
View full analysis
(.*?)<\/title>/i); return titleMatch ? titleMatch[1].trim() : null; } catch (e) { return null; } } ``` The user-controlled value reaches both request functions without validation: ```js const { url, fact } = args; // Check URL accessibility let checkResult = null; if (url) { try { const result = await checkUrlAccessibility(url); const title = await getPageTitle(url); checkResult = { url, accessible: result.accessible, statusCode: result.status, title }; } catch (e) { checkResult = { url, accessible: false, error: e.message }; } } ``` ### Technical Analysis The `url` property is accepted directly from `args` and passed to `fetch()` twice. The implementation does not restrict URL schemes, destinations, resolved IP addresses, ports, or redirects. In particular, it does not reject loopback, private, link-local, reserved, or cloud metadata addresses. This creates an SSRF primitive in which an attacker can cause the host running the skill to send HEAD and GET requests to network resources reachable from that host. Redirects are also not validated, so validation limited only to an initial hostname would remain bypassable unless every redirect destination is checked. The returned status code, accessibility result, and extracted page title provide an observable response channel. Although the implementation does not return the complete response body, ...[truncated 1562 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:6
Finding

Unbounded Response Download and Ineffective Request Timeout

Content
View full analysis
(.*?)<\/title>/i); return titleMatch ? titleMatch[1].trim() : null; } catch (e) { return null; } } ``` ### Technical Analysis The implementation attempts to configure a timeout by passing `timeout: 5000` to `fetch()`. The standard Fetch API does not define this option; implementations based on the standard generally require an `AbortSignal` for cancellation. Consequently, this property may be ignored rather than enforcing a five-second deadline. The subsequent GET request has no timeout or cancellation signal. Calling `resp.text()` buffers the complete response body in memory before title extraction. No maximum response size, streaming limit, content-type validation, or concurrency control is present. Because the requested destination is user-controlled, an attacker can select a server that responds extremely slowly, streams indefinitely, or sends a very large body. This can retain network connections and consume memory, execution time, and worker capacity. ### Attack Path 1. An attacker supplies a URL for a server under their control. 2. The server delays headers, transmits data very slowly, streams without completion, or returns an extremely large response. 3. The HEAD request may remain active because the non-standard `timeout` option does not reliably cancel Fetch requests. 4. The GET request executes without any deadline. 5. `resp.text()` attempts to buffer the complete response in memory. 6. Repeated or concurrent ...[truncated 850 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims it can verify the truthfulness of information and cross-check multiple sources, but the described implementation does not define any concrete fact-verification logic, trust criteria, source quality controls, or decision methodology. This mismatch can mislead users into overtrusting the output as a real fact-check, enabling misinformation propagation or unsafe decisions based on unsupported conclusions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly instructs use of web_fetch and web_search, which are network-capable tools, but it does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: downstream systems or reviewers cannot reliably constrain or audit the skill's external access behavior, increasing the risk of unintended data transmission or misuse of network tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description, headings, and output format are entirely specified in Chinese, including the required result template, with no indication that users may choose another language. This creates a language policy concern because it appears to impose a specific locale without opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module-level documentation claims the skill can verify news facts, but the implementation contains no fact-verification logic. Security-relevant misrepresentation in docs increases the chance that users, orchestrators, or automated systems rely on false assurances and propagate unchecked information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill performs fetch requests to arbitrary user-supplied URLs without validation, restriction, or user-facing disclosure, which can enable SSRF-style access to internal services, cloud metadata endpoints, or other sensitive network targets. In an agent skill context, this is more dangerous because the skill may run in trusted infrastructure with network reachability the end user does not have.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises fact-checking functionality but does not actually verify the supplied fact, instead returning a placeholder string. This can mislead users or downstream agents into believing a claim was checked when no verification occurred, creating integrity and trust risks that are especially problematic for misinformation-sensitive workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells the agent to fetch URLs and search external sources but provides no warning that supplied links or content may be transmitted to third-party services. This is a privacy and consent issue: users may provide sensitive URLs, internal references, or proprietary text without realizing the skill will send them over the network.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.