Back to skill

Security audit

MiniMax Token Plan Tool

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its MiniMax search and image-analysis purpose, but its image tool can read local image files and fetch arbitrary remote image URLs with a concrete SSRF weakness before uploading content to MiniMax.

Install only if you are comfortable sending search queries and selected images to MiniMax. Do not pass sensitive local image paths, and avoid using the remote-image URL feature on untrusted URLs until the SSRF weakness is fixed or the runtime is isolated from private networks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
minimax_token_plan_tool.js:291
Finding

Remote Image Fetching Is Vulnerable to SSRF Through DNS Rebinding and Incomplete IPv6 Filtering

Content
View full analysis
5) { throw new Error('Too many redirects while fetching remote image'); } const url = await validateRemoteImageUrl(imageUrl); return new Promise((resolve, reject) => { const client = url.protocol === 'http:' ? http : https; const req = client.request(url, { method: 'GET', timeout: 15000, headers: { 'User-Agent': 'MiniMax-Token-Plan-Tool/1.0' } }, (res) => { ``` Successfully retrieved image data is subsequently transmitted to the MiniMax API: ```js const p ...[truncated 3063 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose understates the real behavior: the skill can read arbitrary local image files and fetch arbitrary remote URLs before transmitting image content to MiniMax. That mismatch is dangerous because users may trust it as a simple API wrapper while it actually introduces additional attack surface including local file exfiltration, SSRF-like outbound fetching, DNS-based network access, and broader network exposure.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

Default recommendation: put MINIMAX_API_KEY and MINIMAX_API_HOST in ~/.openclaw/.env.

bash
# ~/.openclaw/.env
MINIMAX_API_KEY="sk-your-key"

# China Mainland

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
Execute `minimax_token_plan_tool.js` with environment variable `MINIMAX_API_KEY` and optional `MINIMAX_API_HOST` to dynamically register these tools:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · minimax_token_plan_tool.js (reported line 23)May include surrounding context.

js
const path = require('path');
const { URL } = require('url');

// Get API key from environment
const API_KEY = process.env.MINIMAX_API_KEY;

// Get API host from environment. Only MiniMax official API hosts are allowed.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares environment-variable requirements but does not declare an explicit permission or allowed-tools scope, which weakens visibility and policy enforcement around sensitive capabilities. In this context the skill also supports network operations and local file handling, so the missing scope makes its effective privileges broader and less auditable than users may expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The image tool accepts arbitrary local file paths and remote URLs, then reads or fetches those resources and forwards the contents to the external MiniMax API. In an agent setting, this materially expands the skill from a simple API wrapper into a file-read and network-fetch primitive, which can expose sensitive local files or enable SSRF-style access to internal resources despite some hostname/IP filtering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The understand-image operation uploads either local file contents or remotely fetched image bytes to a third-party API, but the tool interface does not give a strong user-facing warning at the point of use. In agent environments, this can cause unintentional exfiltration of sensitive local data because a caller may not realize that a local path will be read and transmitted off-host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Accessing process environment secrets is a distinct capability that is not mentioned in the manifest description. While common for API clients, this capability is not justified by the stated scope as written and should be declared when auditing developer intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The code transmits the user's search query to a remote API endpoint. While network use is inherent to a search tool, the exposed tool description does not explicitly warn that queries are sent to a third-party service, which is relevant for privacy-sensitive inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.