Back to skill

Security audit

Wekan

Security checks for vulnerabilities and agentic risk

Overview

The skill is for legitimate WeKan board management, but it can modify live boards with a token and has weak scoping, under-disclosed destructive actions, and an unpinned Git-installed CLI.

Review before installing. Use a dedicated least-privileged WeKan account, avoid admin tokens, confirm all create/move/archive/delete actions before execution, do not expose login token output in chat or logs, and prefer a pinned reviewed CLI revision.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Git Dependency

Content
View full analysis
Remediation
View remediation
``` 2. Prefer a signed, immutable release from a trusted package registry when available. 3. Verify package hashes or other integrity metadata during installation. 4. Review the pinned dependency source, including build and installation hooks, before approving it. 5. Use automated dependency monitoring to identify security advisories and intentional pin updates. 6. Run the CLI under a dedicated, least-privileged operating-system account. 7. Configure an agent-specific WeKan account with only the board permissions required for its tasks; avoid administrative tokens. 8. Rotate `WEKAN_TOKEN` immediately if dependency compromise is suspected, and review WeKan audit records for unauthorized activity. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/user-install.md (reported line 7)May include surrounding context.

md
- partial functionality with older versions
- Install the CLI from the github repo, this can be down in the openclaw Control interface under skills.
- Verify CLI is present with `wekancli --version`
- Use `wekancli login` to authenticate with your Wekan instance and acquire an access token
- It may be advisable to setup agent specific accounts for interacting with WeKan
- Delete APIs may only be invoked by users with the `admin` role

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger text is broad enough to activate on generic 'board' or Trello-like task discussions, which can cause the agent to invoke this skill in situations the user did not specifically intend. Because the skill performs state-changing actions against a live Wekan instance using an authenticated token, accidental activation can lead to unintended data modification or disclosure of board contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents destructive operations like moving and archiving cards without any warning, guardrails, or confirmation requirements. In an agent context, this increases the chance that a model will directly execute irreversible or disruptive actions against user boards, especially when coupled with a preconfigured authentication token.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that wekancli login prints a token and user ID, but provides no warning not to expose that token in logs, chat output, transcripts, or telemetry. In an agent context, this is dangerous because the model may surface command output verbatim, leaking a reusable authentication secret that can enable unauthorized access to the WeKan instance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill manages WeKan by creating, moving, and archiving cards, lists, and boards. This reference file additionally documents wekancli delete operations, which are materially more destructive than the stated scope and are not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames the skill as a board-management tool for Trello-like operations on boards, lists, and cards. This file also documents authentication (login) and account/user retrieval and enumeration (get user, list users), which are broader administrative/account capabilities not described in that manifest summary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.