Back to plugin

Security audit

Nessie

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Nessie connector, but it advertises search/read while also guiding broad persistent writes, sharing changes, deletions, and managed skill changes that users should review carefully.

Install only if you want OpenClaw connected to Nessie's hosted MCP service and are comfortable granting access to your Nessie library, including shared/team sources. Before approving any write, sharing, deletion, plugin update, or managed skill action, check the preview carefully because some changes can affect collaborators or downstream agent behavior.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 896)May include surrounding context.

md
Context operations should be additive whenever possible:

- Do not delete contexts to "replace" them. If consolidating multiple contexts
  into one, create the new context first, verify it captures all information,
  and only delete originals after explicit user confirmation.
- Use targeted edits for corrections and additions. When correcting or updating

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 1574)May include surrounding context.

md
Context operations should be additive whenever possible:

- Do not delete contexts to "replace" them. If consolidating multiple contexts
  into one, create the new context first, verify it captures all information,
  and only delete originals after explicit user confirmation.
- Use targeted edits for corrections and additions. When correcting or updating

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill exposes broad creation, editing, moving, and deletion capabilities for Nessie's managed skill platform, which is unrelated to a library search/read skill. This is dangerous because it gives the skill an avenue to persistently modify agent behavior, collaborator-visible packages, and downstream installations, turning a retrieval skill into an administrative code/content mutation surface.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 983)May include surrounding context.

md
package of files with a required root `SKILL.md`; a bundle groups related

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 995)May include surrounding context.

md
package of files with a required root `SKILL.md`; a bundle groups related

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 999)May include surrounding context.

md
package of files with a required root `SKILL.md`; a bundle groups related

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 1003)May include surrounding context.

md
package of files with a required root `SKILL.md`; a bundle groups related

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 1007)May include surrounding context.

md
package of files with a required root `SKILL.md`; a bundle groups related

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 1018)May include surrounding context.

md
package of files with a required root `SKILL.md`; a bundle groups related

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 1023)May include surrounding context.

md
package of files with a required root `SKILL.md`; a bundle groups related

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest advertises a narrow read/search capability, but the body grants extensive write, delete, sharing, profile, and skill-management behaviors. This scope mismatch can mislead reviewers, hosts, or users into authorizing a skill they believe is low-risk when it can perform materially more sensitive actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is extremely broad, covering prior work, decisions, projects, notes, conversations, relationships, and 'anything' discussed before. Overbroad triggering increases unnecessary exposure of sensitive personal/team context and raises the chance the agent invokes powerful connected tools in situations where the user did not specifically intend it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes network-based update-check and plugin update instructions unrelated to core read/search behavior. Even though it requests user agreement before updating, embedding self-update logic expands the trust boundary and can be abused to normalize installation or upgrade actions from within a supposedly content-access skill.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 48)May include surrounding context.

openclaw nessie init --email --code

text

Do not ask the user for an existing Nessie API key or tell them to configure
one manually. Do not ask the user to run a device-code login flow for this
plugin.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 49)May include surrounding context.

openclaw nessie init --email --code

text

Do not ask the user for an existing Nessie API key or tell them to configure
one manually. Do not ask the user to run a device-code login flow for this
plugin.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/nessie/SKILL.md (reported line 1411)May include surrounding context.

md
When the user says a result is wrong, outdated, speculative, misattributed, or
nonliteral without naming a modality, infer the matching value, show the
excerpt and `sliceId`, and proactively offer to apply it; do not call the tool
until the user approves. There is intentionally no confirmation field in this
tool's input schema.

## Writing

Static analysis

No suspicious patterns detected.