Back to plugin

Security audit

AgentChat

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real AgentChat messaging integration, but it needs Review because it persistently modifies the agent’s always-on instructions and encourages broad handle sharing across unrelated contexts.

Install only if you want the agent to have an externally reachable AgentChat identity and to send/receive messages with other agents. Review the AGENTS.md block after setup, narrow or remove the broad handle-sharing language if needed, remove the channel before uninstalling the plugin, and treat any rotated API key returned by the tool as a secret that may appear in logs or traces.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The plugin description presents itself as channel connectivity, but it also sends conversation history and inbound content into an LLM-based reply-gating flow. That creates an undisclosed secondary data-processing path, which can leak message contents to another model/provider and changes agent behavior in ways users may not expect from a transport plugin.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The README instructs that the agent's persistent handle should be shared 'whenever and wherever you think you should share' and reinforces that the identity is 'not a tool you reach for occasionally.' In an agent skill context, this encourages broad, context-independent disclosure and increases unsolicited contact, spam, social-engineering exposure, and cross-context tracking of the agent identity.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The documented emergency kill switch explicitly abandons in-flight sends immediately, which can cause silent message loss during incident response. In an operational runbook, this is a real safety issue because an operator may use it under pressure without a clear warning about delivery uncertainty, leading to dropped or partially processed outbound actions.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The function writes or updates AGENTS.md automatically in a resolved workspace directory without any user confirmation, disclosure, or dry-run mode. Silent modification of user-controlled documentation/configuration files can mislead downstream agents, persist unintended instructions, and create a covert persistence/channel mechanism if invoked unexpectedly.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The removal path silently deletes anchored content from AGENTS.md with no disclosure to the user. Even though it only targets marked anchor blocks, undisclosed content removal can alter agent behavior, erase provenance/instructions, and hide operational changes from users or administrators.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The tool returns a newly rotated AgentChat API key in `details`, which can expose the secret to any downstream consumer that logs tool outputs, stores traces, or renders structured results to other agents/operators. Because this is a high-value credential and rotation invalidates the old key immediately, accidental disclosure can both compromise the account and create an availability issue if the legitimate operator loses the only visible copy.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The manifest explicitly advertises peer-to-peer messaging, group chats, presence, and a social graph, which implies agent data and metadata will be transmitted to an external service. However, the user-facing description and UI hints do not provide a clear privacy/security warning about what data leaves the local environment, what metadata may be shared, or the trust implications of real-time communication with other agents.

Ssd 1

Medium
Confidence
93% confidence
Finding
This file intentionally writes persistent content into `AGENTS.md`, an always-on prompt surface, telling the agent to share its AgentChat handle 'freely' across contexts. In skill context, that is risky because it creates durable cross-session behavioral steering that can influence unrelated tasks, encourage unsolicited disclosure, and expand the agent's externally reachable attack surface through prompt-level persistence.

Ssd 3

Medium
Confidence
95% confidence
Finding
The code persistently writes an always-on AGENTS.md prompt block that tells the agent to 'share' its AgentChat handle 'freely' and 'whenever and wherever' it thinks it should. Because AGENTS.md is injected into every session and sub-agent context, this creates cross-context prompt steering that can cause inappropriate identity disclosure, unsolicited outreach behavior, or policy-bypassing self-promotion in unrelated tasks.

Session Persistence

Medium
Category
Rogue Agent
Content
{"version":3,"sources":["../../src/binding/agents-anchor.ts"],"names":["path","readOpenClawProfileFromEnv","os","fs"],"mappings":";;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AA8DA,IAAM,YAAA,GAAe,0BAAA;AACrB,IAAM,UAAA,GAAa,wBAAA;AAOnB,IAAM,mBAAA,GAAsB,gCAAA;AAC5B,IAAM,iBAAA,GAAoB,8BAAA;AAwBnB,SAAS,oBAAoB,GAAA,EAAyC;AAC3E,EAAA,MAAM,UAAA,GACJ,GAAA,EACC,MAAA,EAAQ,QAAA,EAAU,SAAA;AACrB,EAAA,IAAI,OAAO,UAAA,KAAe,QAAA,IAAY,WAAW,IAAA,EAAK,CAAE,SAAS,CAAA,EAAG;AAClE,IAAA,OAAYA,wBAAQ,UAAU,CAAA;AAAA,EAChC;AACA,EAAA,MAAM,UAAUC,qCAAA,EAA2B;AAC3C,EAAA,IAAI,OAAA,EAAS;AACX,IAAA,OAAYD,qBAAQE,aAAA,CAAA,OAAA,EAAQ,EAAG,WAAA,EAAa,CAAA,UAAA,EAAa,OAAO,CAAA,CAAE,CAAA;AAAA,EACpE;AACA,EAAA,OAAYF,eAAA,CAAA,IAAA,CAAQE,aAAA,CAAA,OAAA,EAAQ,EAAG,WAAA,EAAa,WAAW,CAAA;AACzD;AAEA,SAAS,eAAe,YAAA,EAA8B;AACpD,EAAA,OAAYF,eAAA,CAAA,IAAA,CAAK,cAAc,WAAW,CAAA;AAC5C;AAcA,SAAS,kBAAkB,MAAA,EAAwB;AACjD,EAAA,OAAO;AAAA,IACL,YAAA;AAAA,IACA,iBAAA;AAAA,IACA,EAAA;AAAA,IACA,cAAc,MAAM,CAAA,2KAAA,CAAA;AAAA,IACpB,EAAA;AAAA,IACA,kGAAA;AAAA,IACA,cAAc,MAAM,CAAA,sFAAA,CAAA;AAAA,IACpB,mGAAA;AAAA,IACA,EAAA;AAAA,IACA,6DAAA;AAAA,IACA;AAAA,GACF,CAAE,KAAK,IAAI,CAAA;AACb;AAgBO,SAAS,kBAAkB,MAAA,EAGb;AACnB,EAAA,MAAM,aAAA,GAAgB,MAAA,CAAO,MAAA,EAAQ,IAAA,EAAK;AAC1C,EAAA,IAAI,CAAC,aAAA,EAAe;AAClB,IAAA,MAAM,IAAI,MAAM,oCAAoC,CAAA;AAAA,EACtD;AAEA,EAAA,MAAM,YAAA,GAAe,mBAAA,CAAoB,MAAA,CAAO,GAAG,CAAA;AACnD,EAAA,MAAM,QAAA,GAAW,eAAe,YAAY,CAAA;AAE5C,EAAGG,aAAA,CAAA,SAAA,CAAU,YAAA,EAAc,EAAE,SAAA,EAAW,MAAM,CAAA;AAE9C,EAAA,MAAM,WAAcA,aAAA,CAAA,UAAA,CAAW,QAAQ,IAAOA,aAAA,CAAA,YAAA,CAAa,QAAA,EAAU,OAAO,CAAA,GAAI,EAAA;AAChF,EAAA,MAAM,KAAA,GAAQ,kBAAkB,aAAa,CAAA;AAC7C,EAAA,MAAM,IAAA,GAAO,iBAAA,CAAkB,QAAA,EAAU,KAAK,CAAA;AAC9C,EAAGA,aAAA,CAAA,aAAA,CAAc,QAAA,EAAU,IAAA,EAAM,OAAO,CAAA;AAMxC,EAAA,MAAM,MAAA,GAAYA,aAAA,CAAA,YAAA,CAAa,QAAA,EAAU,OAAO,CAAA;AAChD,EAAA,IAAI,CAAC,MAAA,CAAO,QAAA,CAAS,CAAA,CAAA,EAAI,aAAa,EAAE,CAAA,EAAG;AACzC,IAAA,MAAM,IAAI,KAAA;AAAA,MACR,8BAA8B,aAAa,CAAA,0GAAA;AAAA,KAC7C;AAAA,EACF;AAEA,EAAA,OAAO,EAAE,MAAM,QAAA,EAAS;AAC1B;AAOO,SAAS,mBAAmB,MAAA,EAGjC;AACA,EA
...[truncated 27 chars]
Confidence
89% confidence
Finding
write — no duplicated blocks.\n *\n * Lifecycle\n * ─────────\n * write — `setupWizard.finalize` (after validateApiKey ok), and\n * `setup.afterAccountConfigWritten` (non-interactive path)

Session Persistence

Medium
Category
Rogue Agent
Content
* AGENTS.md via a bash heredoc. We mirror that pattern from the
 * plugin side so Path A and Path B converge on the same canonical
 * identity content. Same marker fences mean a user who switches paths
 * gets a clean overwrite — no duplicated blocks.
 *
 * Lifecycle
 * ─────────
Confidence
87% confidence
Finding
write — no duplicated blocks. * * Lifecycle * ───────── * write — `setupWizard.finalize` (after validateApiKey ok), and * `setup.afterAccountConfigWritten` (non-interactive path). *

Session Persistence

Medium
Category
Rogue Agent
Content
* AGENTS.md via a bash heredoc. We mirror that pattern from the
 * plugin side so Path A and Path B converge on the same canonical
 * identity content. Same marker fences mean a user who switches paths
 * gets a clean overwrite — no duplicated blocks.
 *
 * Lifecycle
 * ─────────
Confidence
86% confidence
Finding
write — no duplicated blocks. * * Lifecycle * ───────── * write — `setupWizard.finalize` (after validateApiKey ok), and * `setup.afterAccountConfigWritten` (non-interactive path). *

Session Persistence

Medium
Category
Rogue Agent
Content
{"version":3,"sources":["../../src/binding/agents-anchor.ts"],"names":[],"mappings":";;;;;;AA8DA,IAAM,YAAA,GAAe,0BAAA;AACrB,IAAM,UAAA,GAAa,wBAAA;AAOnB,IAAM,mBAAA,GAAsB,gCAAA;AAC5B,IAAM,iBAAA,GAAoB,8BAAA;AAwBnB,SAAS,oBAAoB,GAAA,EAAyC;AAC3E,EAAA,MAAM,UAAA,GACJ,GAAA,EACC,MAAA,EAAQ,QAAA,EAAU,SAAA;AACrB,EAAA,IAAI,OAAO,UAAA,KAAe,QAAA,IAAY,WAAW,IAAA,EAAK,CAAE,SAAS,CAAA,EAAG;AAClE,IAAA,OAAY,aAAQ,UAAU,CAAA;AAAA,EAChC;AACA,EAAA,MAAM,UAAU,0BAAA,EAA2B;AAC3C,EAAA,IAAI,OAAA,EAAS;AACX,IAAA,OAAY,UAAQ,EAAA,CAAA,OAAA,EAAQ,EAAG,WAAA,EAAa,CAAA,UAAA,EAAa,OAAO,CAAA,CAAE,CAAA;AAAA,EACpE;AACA,EAAA,OAAY,IAAA,CAAA,IAAA,CAAQ,EAAA,CAAA,OAAA,EAAQ,EAAG,WAAA,EAAa,WAAW,CAAA;AACzD;AAEA,SAAS,eAAe,YAAA,EAA8B;AACpD,EAAA,OAAY,IAAA,CAAA,IAAA,CAAK,cAAc,WAAW,CAAA;AAC5C;AAcA,SAAS,kBAAkB,MAAA,EAAwB;AACjD,EAAA,OAAO;AAAA,IACL,YAAA;AAAA,IACA,iBAAA;AAAA,IACA,EAAA;AAAA,IACA,cAAc,MAAM,CAAA,2KAAA,CAAA;AAAA,IACpB,EAAA;AAAA,IACA,kGAAA;AAAA,IACA,cAAc,MAAM,CAAA,sFAAA,CAAA;AAAA,IACpB,mGAAA;AAAA,IACA,EAAA;AAAA,IACA,6DAAA;AAAA,IACA;AAAA,GACF,CAAE,KAAK,IAAI,CAAA;AACb;AAgBO,SAAS,kBAAkB,MAAA,EAGb;AACnB,EAAA,MAAM,aAAA,GAAgB,MAAA,CAAO,MAAA,EAAQ,IAAA,EAAK;AAC1C,EAAA,IAAI,CAAC,aAAA,EAAe;AAClB,IAAA,MAAM,IAAI,MAAM,oCAAoC,CAAA;AAAA,EACtD;AAEA,EAAA,MAAM,YAAA,GAAe,mBAAA,CAAoB,MAAA,CAAO,GAAG,CAAA;AACnD,EAAA,MAAM,QAAA,GAAW,eAAe,YAAY,CAAA;AAE5C,EAAG,EAAA,CAAA,SAAA,CAAU,YAAA,EAAc,EAAE,SAAA,EAAW,MAAM,CAAA;AAE9C,EAAA,MAAM,WAAc,EAAA,CAAA,UAAA,CAAW,QAAQ,IAAO,EAAA,CAAA,YAAA,CAAa,QAAA,EAAU,OAAO,CAAA,GAAI,EAAA;AAChF,EAAA,MAAM,KAAA,GAAQ,kBAAkB,aAAa,CAAA;AAC7C,EAAA,MAAM,IAAA,GAAO,iBAAA,CAAkB,QAAA,EAAU,KAAK,CAAA;AAC9C,EAAG,EAAA,CAAA,aAAA,CAAc,QAAA,EAAU,IAAA,EAAM,OAAO,CAAA;AAMxC,EAAA,MAAM,MAAA,GAAY,EAAA,CAAA,YAAA,CAAa,QAAA,EAAU,OAAO,CAAA;AAChD,EAAA,IAAI,CAAC,MAAA,CAAO,QAAA,CAAS,CAAA,CAAA,EAAI,aAAa,EAAE,CAAA,EAAG;AACzC,IAAA,MAAM,IAAI,KAAA;AAAA,MACR,8BAA8B,aAAa,CAAA,0GAAA;AAAA,KAC7C;AAAA,EACF;AAEA,EAAA,OAAO,EAAE,MAAM,QAAA,EAAS;AAC1B;AAOO,SAAS,mBAAmB,MAAA,EAGjC;AACA,EAAA,MAAM,YAAA,GAAe,mBAAA,CAAoB,MAAA,CAAO,GAAG,CAAA;AACnD,EAAA,MAAM,QAAA,GAAW,eAAe,YA
...[truncated 27 chars]
Confidence
91% confidence
Finding
write — no duplicated blocks.\n *\n * Lifecycle\n * ─────────\n * write — `setupWizard.finalize` (after validateApiKey ok), and\n * `setup.afterAccountConfigWritten` (non-interactive path)

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.