Back to skill

Security audit

PaperMC AI Operations

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a PaperMC server-management tool, but it needs Review because it ships an exposed ClawHub token, broad publishing upload scripts, unverified executable downloads, and restart code that can kill processes.

Install only after the publisher removes and revokes the exposed ClawHub token, removes publishing utilities from the runtime package, restricts executable downloads to trusted verified sources, and changes restart logic to use a clearly configured service with explicit operator confirmation. If used despite Review status, run it under a dedicated unprivileged server account and review every downloaded JAR and restart action manually.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
publish_skill.py:11
Finding

Hardcoded ClawHub bearer token is exposed and included in publication artifacts

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
plugin_manager.py:61
Finding

Unverified remote JAR files are installed into executable server locations

Content
View full analysis
None: """Download and install plugin from URL""" if filename is None: filename = url.split("/")[-1] dest = PLUGINS_DIR / filename print(f"[download] fetching: {url}") try: urllib.request.urlretrieve(url, dest) print(f"[install] installed: {filename}") except Exception as e: print(f"[error] download failed: {e}") ``` ```python # update_paper.py:53-69 def update_from_url(url: str) -> None: """Update PaperMC from URL""" print(f"[update] downloading: {url}") # Backup first backup_jar() # Download new jar temp_jar = SERVER_DIR / "papermc.jar.new" try: urllib.request.urlretrieve(url, temp_jar) # Replace old jar if PAPER_JAR.exists(): PAPER_JAR.unlink() temp_jar.rename(PAPER_JAR) print("[update] papermc.jar updated successfully") print("[update] restart server to apply changes") except Exception as e: print(f"[error] update failed: {e}") if temp_jar.exists(): temp_jar.unlink() ``` ```python # plugin_upgrade_framework.py:468-511 def _get_download_url(self, plugin_name: str, version: str) -> Optional[str]: """获取下载URL""" try: # 尝试从Hangar获取 url = f"{HANGAR_API_BASE}/projects/{plugin_name}/versions/{version}" response = self.session.get(url, timeout=10) if response.status_code == 200: data = response.json() if data.get("downloads") and data["downloads"].get("PAPER"): download_info = data["downloads"]["PAPER"] return download_info.get ...[truncated 4105 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
plugin_upgrade_framework.py:668
Finding

Automatic restart bypasses the declared safety interface and can forcibly terminate a matching process

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
- `plugin_upgrade_framework.py` - Intelligent plugin upgrade framework

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · backup.sh (reported line 40)May include surrounding context.

sh
# Clean old backups (keep last 10)
echo "[backup] cleaning old backups, keep latest 10 ..."
cd "${BACKUP_DIR}"
ls -t world-backup-*.tar.gz 2>/dev/null | tail -n +11 | xargs -r rm -f

echo "[backup] done"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill can automatically restart the server when auto_restart is enabled, leading into a flow that may terminate and later kill the active PaperMC process without an immediate confirmation barrier. In this server-management context, unexpected restart behavior can cause player disruption, unsaved state loss, and possible corruption of live server data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script recursively enumerates local text-like files and later prepares them for upload to an external API, creating a broad exfiltration path for source code, documentation, configs, and other sensitive plaintext artifacts. In the context of a PaperMC server-management skill, this publishing behavior is outside the operational scope and increases the risk of accidentally disclosing secrets or proprietary data present in the working tree.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script uploads all discovered text files to a remote service without interactive confirmation or a clear warning about the transmission scope, so a user may unintentionally send sensitive local data. This is especially risky because recursive collection and remote publication happen in one flow, with no review gate before exfiltration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code performs an external POST to ClawHub to publish the collected files, which is a data-transfer capability unrelated to managing a Minecraft server. Because the upload is automatic and broad in scope, misuse or accidental execution can leak internal project contents to a third party.

Content

No source excerpt is available for this finding.

Tainted flow: 'files' from open (line 29, file read) → requests.post (network output)

High
Category
Data Flow
Confidence
80% confidence
Finding

File contents flow to a network sink. This may indicate data exfiltration of sensitive files.

Content

Scanner excerpt · publish_to_clawhub.py (reported line 49)May include surrounding context.

python
try:
        print("正在上传技能...")
        response = requests.post(
            f"{API_BASE}/skills/{SKILL_SLUG}",
            headers=headers,
            data=payload,

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill for managing PaperMC Minecraft servers, including lifecycle management, backups, plugin operations, and health monitoring. This file instead implements an AI usage/cost logging utility under ~/.openclaw/cost_logs, with no PaperMC/server-management functionality at all.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill for managing PaperMC Minecraft servers, backups, plugin operations, and health monitoring. This file instead implements a generic local accounting tool for tracking DeepSeek and Kimi model token usage and generating spending reports, with no PaperMC or server-management functionality.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains a hardcoded bearer credential and uses it to upload local repository files to an external service. Embedding live secrets in a distributable skill is dangerous because anyone with access to the file can reuse the token for unauthorized API actions, and the outbound publishing behavior is unrelated to the stated PaperMC server-management purpose, increasing supply-chain and data-exfiltration risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README asserts a 'controlled interfaces only' safety model, but later documents update and plugin installation flows that accept arbitrary URLs for downloading server jars or plugins. Even though these actions are wrapped in helper scripts, URL-based fetch-and-install is still a direct supply-chain risk because an agent could be induced to retrieve and deploy untrusted code while believing it is operating within approved safety boundaries.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and documents capabilities that imply shell, filesystem, environment, and network access, but it does not declare any explicit tool scope or permission boundaries in the manifest. In an agent setting, missing scope declarations increases the chance that a consumer or runner grants broader privileges than intended, especially for scripts that download artifacts and modify server files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to install plugins and update PaperMC from remote URLs, but it does not prominently warn that these artifacts are executable code with integrity, authenticity, and privacy risks. In a server-management skill, users may interpret the examples as endorsed-safe workflows and fetch malicious or tampered JARs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

标题和全文内容均以中文呈现,未说明这是面向特定中文用户群的区域性文档,也未提供多语言或用户选择。根据语言/区域政策,这属于未经用户选择而强制特定语言的自然语言策略问题。

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · manage_server.py (reported line 23)May include surrounding context.

python
def run_command(cmd: list[str], check: bool = True) -> int:
    """Execute command in server directory"""
    print(f"[cmd] {' '.join(cmd)}")
    result = subprocess.run(cmd, cwd=SERVER_DIR)
    if check and result.returncode != 0:
        raise SystemExit(result.returncode)
    return result.returncode

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The code runs a privileged subprocess using sudo to restart a system service, which changes system state and may interrupt availability. While the command itself is printed, there is no explicit warning, confirmation, or explanatory disclosure that this action requires elevated privileges and will restart the server service.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.install_untrusted_source

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
publish_skill.py:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
publish_to_clawhub.py:13

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
simple_publish.sh:3

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
viaversion_upgrade_report.json:27