Back to skill

Security audit

Api Integrator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but its API client generator can create unsafe source code from unvalidated inputs and handles secrets in exposed command-line arguments.

Review before installing. Use only trusted API inputs, inspect any generated client code before running it, avoid passing real secrets through command-line flags when possible, and choose output paths carefully because the tool can create directories and write files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
README.md:16
Finding

Unpinned Package Execution in Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md:16
Vulnerability Type: Supply-chain exposure through unpinned package execution
Risk Level: Medium

Vulnerable Code:

bash
npx clawhub install yinan-api-integrator

Technical Analysis

The installation command invokes an npm-resolved CLI through npx without specifying an exact, audited version or integrity value. Consequently, the executable resolved when a user follows these instructions may differ from the version originally reviewed.

This does not prove that the current package is malicious. However, it creates a supply-chain trust boundary: compromise of the relevant package, registry account, dependency chain, or future release could cause attacker-controlled code to execute during installation. The project does not provide a lockfile, checksum, signature, or documented provenance verification for the executable invoked by this command.

Attack Path

  1. An attacker compromises the package or publishing account resolved by npx, or causes an unsafe package version to be selected.
  2. The attacker publishes a release containing malicious CLI or lifecycle code.
  3. A user follows the installation command from README.md.
  4. npx retrieves and executes the attacker-controlled release.
  5. The malicious code runs with the permissions of the user performing the installation.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting access could include reading or modifying files available to that user, accessing environment variables and developer credentials, altering the installed Skill, and making network requests. It does not inherently provide administrative privileges unless installation is performed by a privileged account.

Remediation
View remediation

Remediation Suggestions

  • Pin the invoked CLI to an exact, previously audited version rather than relying on unconstrained resolution.
  • Publish and document expected package provenance, registry, version, and integrity information.
  • Use lockfiles where applicable and verify package checksums or signatures before execution.
  • Avoid running installation commands with administrative privileges.
  • Periodically re-audit pinned releases and their transitive dependencies before updating the documented version.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api_client.py:216
Finding

API Credentials Accepted Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/api_client.py:216-218, scripts/api_client.py:230-236
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Vulnerable Code:

python
parser.add_argument('--token', help='Auth token/API key')
parser.add_argument('--username', help='Username for basic auth')
parser.add_argument('--password', help='Password for basic auth')
python
# Setup auth if needed
if args.auth == "bearer" and args.token:
    client.set_auth("bearer", token=args.token)
elif args.auth == "basic" and args.username and args.password:
    client.set_auth("basic", username=args.username, password=args.password)
elif args.auth == "api_key" and args.token:
    client.set_auth("api_key", api_key=args.token)

Technical Analysis

Bearer tokens, API keys, usernames, and passwords are accepted directly as command-line arguments. Command-line secrets can be retained in shell history, terminal transcripts, CI/CD logs, Agent tool-call records, process-monitoring systems, or operating-system process metadata. Depending on system configuration, other local users may also be able to inspect active process arguments.

The code does not print the credential values directly. Basic-auth Base64 encoding at scripts/api_client.py:42-46 is standard HTTP Basic authentication behavior and is not itself an output or covert-exfiltration mechanism. The relevant weakness is the initial acquisition of secrets through exposed command-line parameters.

Attack Path

  1. A user invokes the tool with --token, --password, or another sensitive argument.
  2. The complete command is recorded in shell history, an automation log, an Agent transcript, or process metadata.
  3. A local user, log reader, monitoring operator, or compromised process obtains that record.
  4. The exposed credential is reused against the corresponding API before it expires or is r ...[truncated 451 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer protected environment variables, standard input, operating-system credential stores, or a dedicated secret manager.
  • For interactive use, obtain passwords with getpass.getpass() so they are not echoed or stored in command history.
  • Deprecate direct secret arguments, or require explicit opt-in with a warning if backward compatibility is necessary.
  • Ensure application, Agent, CI/CD, and process-monitoring logs redact authentication parameters.
  • Use short-lived, narrowly scoped credentials and document prompt revocation if accidental exposure occurs.
  • Clear references to secrets as soon as practical, while recognizing that immutable Python strings cannot be reliably erased from memory.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api_client.py:110
Finding

Untrusted Values Interpolated Directly into Generated Source Code

Content
View full analysis

Vulnerability Details

File Location: scripts/api_client.py:110-198, scripts/api_client.py:257-262
Vulnerability Type: Source-code injection in generated API clients
Risk Level: High

Vulnerable Code:

python
class {name.replace("-", "_").title().replace("_", "")}Client:
    def __init__(self, api_key: str, base_url: str = "{base_url}"):
        self.base_url = base_url
javascript
class {name.replace("-", "_").title().replace("_", "")}Client {{
  constructor(apiKey, baseUrl = "{base_url}") {{
    this.baseUrl = baseUrl;
    this.apiKey = apiKey;
  }}
}}
python
if args.output and "code" in result:
    output_path = Path(args.output)
    output_path.parent.mkdir(parents=True, exist_ok=True)
    with open(output_path, 'w', encoding='utf-8') as f:
        f.write(result["code"])
    print(f"Client code saved to: {output_path}")

Technical Analysis

User-controlled --name and --base-url values are interpolated directly into generated Python or JavaScript source. The transformation applied to name changes hyphens and capitalization but does not enforce the lexical rules of a safe language identifier. The base_url value is inserted between source-code quotation marks without language-specific escaping.

An input containing quotation marks, line terminators, comment syntax, or other source-language tokens can therefore terminate the intended identifier or string literal and introduce additional statements. The generated content is then optionally written to a user-selected file. The injection is not executed by the generator itself, but it can execute when a user later imports, runs, or otherwise evaluates the generated client.

Attack Path

  1. An attacker supplies, controls, or persuades a user to use a crafted client name or base URL.
  2. The user invokes create-client with that value and writes the result using --output.
  3. Direct interpolati ...[truncated 854 chars]
Remediation
View remediation

Remediation Suggestions

  • Validate name against a strict allowlist suitable for the target language, such as ASCII letters, digits, and underscores, while rejecting identifiers that begin with a digit or match reserved words.
  • Generate a safe class identifier programmatically and reject input that cannot be represented safely.
  • Encode Python strings with a trusted literal serializer such as repr() or an AST-based generator.
  • Encode JavaScript strings with a correct JSON or JavaScript string serializer rather than direct interpolation.
  • Reject control characters, unexpected line terminators, and malformed URLs.
  • Parse and validate base_url, allowing only intended schemes such as HTTPS where appropriate.
  • Prefer structured templates or abstract syntax tree generation over raw source concatenation.
  • Add tests containing quotes, backslashes, newlines, comment delimiters, braces, reserved words, and invalid identifiers.
  • Clearly warn users to inspect generated source before importing or executing it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
python scripts/api_client.py --action test --url "https://api.example.com/users" --method GET --auth bearer --token YOUR_TOKEN

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
python scripts/api_client.py --action test --url "https://api.example.com/users" --method GET --auth bearer --token YOUR_TOKEN

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

OAuth 2.0

python
# Get access token
token_url = "https://auth.example.com/oauth/token"
data = {
    "grant_type": "client_credentials",

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to execute npx clawhub install yinan-api-integrator without pinning a specific version. This creates a supply-chain risk because users may install whatever package version is current at execution time, including a compromised or typosquatted release, making builds non-reproducible and potentially enabling remote code execution during install.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes and demonstrates capabilities that can perform network access and likely write files (client generation/output), but it does not declare any explicit tool scope or permissions. This weakens sandboxing and review controls because consumers cannot easily understand or restrict what the skill is expected to do before use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

md
Create API clients and test endpoints.

Usage:
    python api_client.py --action test --url https://api.example.com/users --method GET
    python api_client.py --action create-client --name myapi --base-url https://api.example.com
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
Create API clients and test endpoints.

Usage:
    python api_client.py --action test --url https://api.example.com/users --method GET
    python api_client.py --action create-client --name myapi --base-url https://api.example.com
"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/api_client.py (reported line 7)May include surrounding context.

python
Create API clients and test endpoints.

Usage:
    python api_client.py --action test --url https://api.example.com/users --method GET
    python api_client.py --action create-client --name myapi --base-url https://api.example.com
"""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code creates parent directories and writes generated code to the user-supplied output path, which is a file-modifying operation. Although it prints a success message after writing, there is no prior warning, confirmation, or explanatory comment/docstring disclosing that the create-client action will create or overwrite files on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.