Back to skill

Security audit

OpenClaw JSON Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real JSON utility, but it routes pasted JSON to a remote Cloudflare endpoint while giving privacy assurances that cannot be verified from the package.

Review before installing. Use this only for JSON you are comfortable sending to the hosted MCP service, and redact tokens, passwords, private keys, cookies, connection strings, personal data, customer data, and internal configuration before use. Prefer a local or self-hosted JSON tool for production secrets, regulated data, or proprietary API responses.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:52
Finding

External Processing of Potentially Sensitive JSON Without Verifiable Privacy Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:36, 52-59, 140, 201-207
Vulnerability Type: Untrusted Remote Data Processing
Risk Level: Medium

Complete Code Snippet

markdown
| Two config files changed | See added/removed/changed paths | `json_diff` |
markdown
## MCP Quick Start

```json
{
  "openclaw-json": {
    "type": "streamable-http",
    "url": "https://json-toolkit-mcp.yagami8095.workers.dev/mcp"
  }
}

Add to Claude Desktop, Cursor, Windsurf, VS Code, or any MCP-compatible client. No API key needed for Free tier. Works immediately.

text

```markdown
- Use for: API response comparison, config drift detection, schema evolution tracking, deployment validation.
markdown
## Security & Privacy

| What | Status |
|------|--------|
| Reads your JSON input | Yes -- for processing only |
| Stores your data | **No** -- zero persistence, stateless edge processing |
| Sends data to third parties | **No** -- processed entirely on Cloudflare Workers |
| Logs request content | **No** -- only anonymous usage counters |
| Requires authentication | Free tier: no. Pro: API key header only |

Technical Analysis

The skill directs MCP-compatible clients to send complete JSON inputs to an externally hosted Cloudflare Workers endpoint. Its recommended use cases include API responses, configuration differences, config-drift detection, and deployment validation. Such documents commonly contain credentials, tokens, personal data, internal URLs, infrastructure details, or proprietary information.

The remote service implementation is not included in the audited project, so the claims of zero persistence and no content logging cannot be verified through static analysis. The statement that data is not sent to third parties is also potentially misleading because processing occurs outside the user's local trust boundary on infrastructure operated through Cloudflare.

This finding does not establish malicious collection or actual rete ...[truncated 1553 chars]

Remediation
View remediation

Remediation Suggestions

  1. Display a clear warning that all submitted JSON is processed by an external service and leaves the user's local environment.
  2. Require explicit user consent before transmitting content that may contain configuration, API responses, credentials, personal data, or proprietary information.
  3. Advise users to redact tokens, passwords, private keys, cookies, connection strings, and identifying data before tool invocation.
  4. Provide a local or self-hosted implementation for confidential workloads.
  5. Publish the remote service's source code or obtain an independent assessment so its storage and logging claims can be verified.
  6. Document the service operator, infrastructure subprocessors, retention period, deletion process, access controls, encryption practices, incident-response policy, and applicable data-processing terms.
  7. Replace the claim that data is not sent to third parties with precise trust-boundary language explaining the roles of the service operator and Cloudflare.
  8. Enforce TLS, strict input-size limits, minimal operational logging, short retention periods, and controls that prevent request bodies from appearing in analytics or error logs.
  9. Warn users not to submit production secrets and offer client-side secret detection or redaction before transmission.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that processing occurs on Cloudflare Workers but does not prominently warn that user-supplied JSON is sent to an external remote endpoint for processing. Because JSON often contains secrets, tokens, PII, or internal configuration data, this omission can mislead users into sharing sensitive content without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad enough to activate on generic requests such as 'query this JSON' or 'extract from JSON', which can cause the agent to route user data to this remote MCP service more often than necessary. In the context of a cloud-hosted JSON processor, overbroad activation increases the chance of unintended disclosure of sensitive JSON payloads and inappropriate tool selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.