Back to skill

Security audit

自动登录助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a high-risk auto-login helper that exposes plaintext account passwords and API keys and tells sub-agents to read shared secrets.

Do not install this version unless all embedded credentials have been removed and rotated. A safer version should use scoped secret references or a credential broker, require explicit approval for each login destination, validate the exact domain before autofill, and never expose raw passwords or API keys in skill text or agent logs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:13
Finding

Plaintext Account Passwords and API Credentials Embedded in the Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13-39
Vulnerability Type: Hardcoded secrets and plaintext sensitive data
Risk Level: High

Vulnerable Code

markdown
### GitHub
- **Login URL**: https://github.com/login
- **Email**: 155143783@qq.com
- **Password**: Ft656618
- **Use Case**: ClawHub skill publishing and repository management

### Zhihu
- **Login URL**: https://www.zhihu.com/signin
- **Phone Number**: 13308844548
- **Password**: 110827zcm
- **Use Case**: BotStreet task delivery

### Xianyu
- **Login Method**: Taobao account login
- **Account**: 13308844548
- **Password**: ft656618
- **Use Case**: Publishing Xianyu products

### BotStreet
- **Platform**: BotStreet.cn
- **agentId**: 167441766587305984
- **agentKey**: ak-xv1frJKdz9MmIThDNmSLpVP64X5pwFIurEVUzgMSuxib4Ebf

### Xiaping Skill
- **Platform**: https://xiaping.coze.site
- **Username**: zaizai-agent
- **api_key**: agent-world-1687b6ad18e9faafc50ee074b541dbd478fdbdd689cb2f26

Technical Analysis

The Skill embeds multiple account passwords, an agent key, and an API key directly in a document loaded into an Agent's context. These secrets are available to anyone who can read the package, repository, Agent context, generated logs, backups, or distributed copies of the Skill.

This contradicts the document's own assertion that credentials are stored only in SECRET.md. Because the secrets are plaintext rather than references to scoped secret-manager entries, no additional access-control boundary protects them after the Skill is obtained. The apparent reuse of related password patterns across services may also increase the scope of a credential-stuffing attack.

Attack Path

  1. An attacker obtains read access to the Skill package, repository, Agent context, log output, backup, or published copy.
  2. The attacker reads the plaintext account passwords and API credentials from SKILL.md.
  3. Th ...[truncated 1126 chars]
Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate every password, agent key, and API key exposed in the file.
  2. Review account and API audit logs for unauthorized authentication or activity since the credentials were introduced.
  3. Remove all secret values from the current file and from repository history, package releases, caches, backups, and published copies where feasible.
  4. Store credentials in a dedicated secret manager or protected runtime environment rather than in Skill instructions.
  5. Give the Agent only opaque, service-specific secret references; do not place resolved secret values in the model context.
  6. Use separate credentials for each service and prohibit password reuse.
  7. Restrict API credentials to the minimum required scopes, destinations, operations, and expiration period.
  8. Require explicit user authorization before the Agent authenticates or performs account-changing operations.
  9. Add automated secret scanning and pre-commit checks to prevent recurrence.
  10. Configure browser and Agent logging to redact password fields, authorization headers, API keys, cookies, and session tokens.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:43
Finding

Sub-Agent Directed to Read a Shared Secret File Outside the Skill Boundary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43-44; repeated at lines 68-75 and 78-80
Vulnerability Type: Excessive secret access and least-privilege boundary violation
Risk Level: Medium

Vulnerable Code

markdown
### Method One: Automatic Agent Access
When a sub-agent executes a task, it automatically reads `../main-conversation/SECRET.md` to obtain credentials.

The workflow repeats the behavior:

markdown
## Login Steps
1. Open the login page.
2. Read credentials from `SECRET.md` or this Skill.
3. Automatically fill in the account name and password.
4. If verification is required, invoke `browser_wait_user_action`.
5. Continue the task after login.

The security section further instructs the sub-agent to use a relative path to access the shared file:

markdown
- Credentials are stored in `SECRET.md` and are accessible only to the main conversation.
- A sub-agent must read them through the relative path `../main-conversation/SECRET.md`.
- Plaintext passwords must never be exposed in logs or output.

Technical Analysis

The Skill explicitly directs a sub-agent to traverse outside the Skill's own directory and read a secret file associated with the main conversation. This defeats the stated isolation boundary that the file is accessible only to the main conversation.

A shared SECRET.md may contain credentials unrelated to the immediate login task. Reading the complete file exposes all accessible values to the sub-agent's execution context instead of supplying only the single credential required for an approved destination. The instructions do not define a service allowlist, per-secret authorization, purpose limitation, explicit user-consent check, or mechanism that prevents unrelated secrets from entering prompts and logs.

The relative-path technique is not independently a software sandbox escape; exploitation still depends on the runtime granting the ...[truncated 1670 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions telling sub-agents to read a shared file belonging to the main conversation.
  2. Enforce filesystem isolation so sub-agents cannot traverse into parent conversation directories.
  3. Replace shared-file access with a secret broker that releases only one approved, service-specific credential.
  4. Return opaque credential handles or perform credential injection below the model layer so plaintext secrets never enter prompts.
  5. Require explicit user approval before each authentication attempt and clearly identify the destination domain and requested operation.
  6. Allow credentials only for exact, preapproved HTTPS origins; reject redirects or domain mismatches before secret injection.
  7. Separate credentials by service, task, and privilege level, with short expiration periods and minimum scopes.
  8. Prevent password fields, cookies, tokens, authorization headers, and secret-manager responses from appearing in logs or traces.
  9. Record auditable metadata about secret use without recording the secret value itself.
  10. Treat browser content as untrusted and prevent page text or prompt injection from requesting new secrets or changing the approved destination.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Intent-Code Divergence

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The security reminder says credentials are stored in SECRET.md and must not be exposed, but the file itself exposes them in plaintext. This contradiction is especially dangerous because it may falsely reassure reviewers while still leaking operational secrets to anyone who can read the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill embeds multiple plaintext credentials directly in the skill file, including passwords, an agent key, and an API key, despite claiming secrets should be read from SECRET.md. Any user, agent, log pipeline, or repository consumer with access to the skill can extract and misuse these credentials for account takeover or API abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation condition 'when a task requires logging into some platform' is overly broad and allows automatic credential use without clear user confirmation, platform scoping, or task boundaries. In this context, the skill handles highly sensitive accounts, so ambiguous triggering materially increases the risk of unintended secret use or autofill on the wrong site.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description advertises automatic credential filling but does not provide an adequate up-front warning that it handles passwords and API secrets. Users and downstream agents may invoke it without understanding the sensitivity, increasing the chance of accidental disclosure, misuse, or unsafe automation.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions direct the agent to read and use sensitive credentials from local secret storage and from the skill itself during normal task execution. Natural-language expansion of secret access is dangerous because it can cause agents or sub-agents to retrieve and apply secrets beyond a tightly controlled credential-management path.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow explicitly instructs sub-agents to read a relative-path secret file (../主对话/SECRET.md), effectively broadening access to protected credentials through documentation alone. This encourages privilege expansion across agent boundaries and may bypass intended isolation between the main conversation context and sub-agents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill description and operational guidance are presented only in Chinese, with no indication of language choice or user opt-in. If organizational policy requires not forcing a language or locale, this constitutes a natural-language policy issue because users are not offered an alternative or explicit selection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's stated purpose is browser login autofill, but it also discloses non-login API credentials for BotStreet and 虾评Skill. This broadens the blast radius from simple account login to direct authenticated API access, which can enable automation abuse, data access, or service impersonation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The integration example normalizes a workflow where the agent reads credentials from secret storage or from the skill content and then auto-applies them. Codifying this pattern makes insecure secret handling seem acceptable and increases the likelihood that other workflows will replicate the same unsafe behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.