other
- Location
SKILL.md:52- Finding
External Processing of Potentially Sensitive JSON Without Verifiable Privacy Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:36, 52-59, 140, 201-207
Vulnerability Type: Untrusted Remote Data Processing
Risk Level: MediumComplete Code Snippet
markdown | Two config files changed | See added/removed/changed paths | `json_diff` |markdown ## MCP Quick Start ```json { "openclaw-json": { "type": "streamable-http", "url": "https://json-toolkit-mcp.yagami8095.workers.dev/mcp" } }Add to Claude Desktop, Cursor, Windsurf, VS Code, or any MCP-compatible client. No API key needed for Free tier. Works immediately.
text ```markdown - Use for: API response comparison, config drift detection, schema evolution tracking, deployment validation.markdown ## Security & Privacy | What | Status | |------|--------| | Reads your JSON input | Yes -- for processing only | | Stores your data | **No** -- zero persistence, stateless edge processing | | Sends data to third parties | **No** -- processed entirely on Cloudflare Workers | | Logs request content | **No** -- only anonymous usage counters | | Requires authentication | Free tier: no. Pro: API key header only |Technical Analysis
The skill directs MCP-compatible clients to send complete JSON inputs to an externally hosted Cloudflare Workers endpoint. Its recommended use cases include API responses, configuration differences, config-drift detection, and deployment validation. Such documents commonly contain credentials, tokens, personal data, internal URLs, infrastructure details, or proprietary information.
The remote service implementation is not included in the audited project, so the claims of zero persistence and no content logging cannot be verified through static analysis. The statement that data is not sent to third parties is also potentially misleading because processing occurs outside the user's local trust boundary on infrastructure operated through Cloudflare.
This finding does not establish malicious collection or actual rete ...[truncated 1553 chars]
- Remediation
View remediation
Remediation Suggestions
- Display a clear warning that all submitted JSON is processed by an external service and leaves the user's local environment.
- Require explicit user consent before transmitting content that may contain configuration, API responses, credentials, personal data, or proprietary information.
- Advise users to redact tokens, passwords, private keys, cookies, connection strings, and identifying data before tool invocation.
- Provide a local or self-hosted implementation for confidential workloads.
- Publish the remote service's source code or obtain an independent assessment so its storage and logging claims can be verified.
- Document the service operator, infrastructure subprocessors, retention period, deletion process, access controls, encryption practices, incident-response policy, and applicable data-processing terms.
- Replace the claim that data is not sent to third parties with precise trust-boundary language explaining the roles of the service operator and Cloudflare.
- Enforce TLS, strict input-size limits, minimal operational logging, short retention periods, and controls that prevent request bodies from appearing in analytics or error logs.
- Warn users not to submit production secrets and offer client-side secret detection or redaction before transmission.
