Back to skill

Security audit

GARSS Studio RSS API

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a GARSS RSS API guide, but it asks agents to clone and run an unpinned Docker stack and normalizes weak credential handling.

Install only if you are comfortable with an agent starting GARSS locally through Docker. Keep it on loopback, change the default access code, avoid putting passwords in URLs, do not send tokens to non-HTTPS or unfamiliar hosts, and review any clone/build step before running it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:75
Finding

Credentials and Bearer tokens may be transmitted to an untrusted cleartext endpoint

Content
View full analysis
``` ```markdown If the user gives a URL containing `?pw=...`, use that value as `accessCode`. ``` ### Technical Analysis Authentication legitimately requires transmitting an access code and using the resulting Bearer token. However, the Skill permits the base URL to be changed without requiring HTTPS, validating the destination host, or limiting remote destinations to an explicit allowlist. Consequently, an attacker-controlled or mistakenly supplied `GARSS_BASE_URL` can receive the access code during login. The same endpoint can then receive the returned Bearer token in later authenticated requests. HTTP is acceptable for a service strictly bound to loopback, but it does not provide transport confidentiality or server authentication for non-loopback destinations. Reading a password from a URL query parameter also increases exposure because URLs commonly enter browser history, logs, proxy records, telemetry, screenshots, and copied messages. The behavior exceeds minimum privilege when the Skill sends reusable authentication material to any us ...[truncated 1228 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Predictable hard-coded development access credential

Content
View full analysis
Remediation
View remediation
`. 6. Store credentials in a secret manager or protected environment variable and prevent them from entering source control or logs. 7. Add rate limiting, failed-login monitoring, token expiration, and credential rotation. 8. Display a prominent warning or refuse startup when a default or weak credential is detected. ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:39
Finding

Mutable remote repository is cloned and built without integrity verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

  1. Ensure env file exists:
bash
cp .env.example .env

Skip this if .env already exists.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api.md (reported line 50)May include surrounding context.

bash
BASE_URL='http://127.0.0.1:25173'
TOKEN="$(curl -sS -X POST "$BASE_URL/api/auth/login" \
  -H 'Content-Type: application/json' \
  -d '{"accessCode":"banana"}' \
  | node -pe 'JSON.parse(fs.readFileSync(0, "utf8")).token')"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    envVars:
      - name: GARSS_BASE_URL
        required: false

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill normalizes use of a hardcoded default access code ('banana') for authentication and even embeds it in a browser URL example, which encourages insecure default credential usage and increases the chance of unauthorized local access if the service is exposed beyond localhost. While framed as a dev setup convenience, publishing and operationalizing a shared default secret without strong warning is a real security weakness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation includes a concrete access code value ("banana") with no warning that it is a sensitive example credential that must be changed. In practice, example credentials are often copied into deployments or prompts, which can lead to trivial unauthorized access if the default remains active.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata says it is for reading, refreshing, summarizing, or inspecting RSS news, but the documented API also exposes state-changing operations such as creating, updating, and deleting subscriptions, categories, and settings. This creates a scope mismatch that can cause an agent or operator to grant the skill more authority than intended, enabling unauthorized modification or destruction of user data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 50)May include surrounding context.

bash
BASE_URL='http://127.0.0.1:25173'
TOKEN="$(curl -sS -X POST "$BASE_URL/api/auth/login" \
  -H 'Content-Type: application/json' \
  -d '{"accessCode":"banana"}' \
  | node -pe 'JSON.parse(fs.readFileSync(0, "utf8")).token')"

Static analysis

No suspicious patterns detected.