Back to skill

Security audit

1688 Common Cha88 Company Risk

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended for Chinese company risk lookup, but its access-key setup handles credentials in ways users should review before installing.

Install only if you trust the 1688/OpenClaw integration and are comfortable sending company identifiers and risk-query activity to the external service. Before configuring an AK, ensure OPENCLAW_GATEWAY_URL points only to a trusted local gateway, protect the OpenClaw config file, and be aware the key may be stored under the shared cha88-base configuration namespace.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/capabilities/configure/service.py:77
Finding

Plaintext API Key Storage Without Enforced File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/capabilities/configure/service.py:36
Finding

Environment-Controlled Gateway URL Can Receive API and Bearer Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/capabilities/companyRisk/cmd.py:45
Finding

Untrusted API Response Fields Are Rendered as Active Markdown

Content
View full analysis
str: if not content_dict: return "-" parts = [] for k, v in content_dict.items(): if v is None or v == "": continue v_str = str(v).replace("|", "/").replace("\n", " ").strip() parts.append(f"**{k}**:{v_str}") return "
".join(parts) if parts else "-" ``` ```python for main_type, records in risk_map.items(): count = len(records) level_count = {} for r in records: lvl = r.get("level") or "unlabeled" level_count[lvl] = level_count.get(lvl, 0) + 1 ordered_levels = sorted( level_count.items(), key=lambda kv: _LEVEL_ORDER.index(kv[0]) if kv[0] in _LEVEL_ORDER else 99, ) level_str = "、".join(f"{lvl} {n}" for lvl, n in ordered_levels) or "-" lines.append(f"| {main_type} | {count} | {level_str} |") lines.append("") for main_type, records in risk_map.items(): if not records: continue lines.append(f"## {main_type} ({len(records)} records)\n") lines.append("| # | Risk Level | Subtype | Time | Company | Details |") lines.append("|---|---------|-------|------|---------|------|") for idx, r in enumerate(records, 1): level = r.get("level") or "-" sub_type = r.get("subType") or "-" time_str = r.get("time") or _format_timestamp(r.get("timeStamp")) if isinstance(time_str, str) and " " in time_str: time_str = time_str.split(" ")[0] company_name = r.get("companyName") or "-" content = _format_content_dict(_parse_content(r.get("contentChinese"))) ...[truncated 3256 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (51)

Tainted flow: 'gateway_url' from os.environ.get (line 36, credential/environment) → requests.patch (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The gateway URL is taken directly from an environment variable and used to send a PATCH request containing the API key and optional bearer token. If an attacker can influence the environment, they can redirect credentials to an attacker-controlled endpoint, causing secret exfiltration or unauthorized configuration changes.

Content

Scanner excerpt · scripts/capabilities/configure/service.py (reported line 53)May include surrounding context.

python
headers = {}
        if token:
            headers["Authorization"] = f"Bearer {token}"
        resp = requests.patch(f"{gateway_url}/api/config",
                              headers=headers, json=payload, timeout=5)
        return resp.ok
    except Exception:

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This referenced capability is for basic enterprise search and information retrieval, which conflicts with the skill manifest stating that pure company-info queries must not trigger this risk-analysis skill. That mismatch can cause the skill to activate on out-of-scope requests, leading to unnecessary collection, processing, or disclosure of legal-risk data when the user only asked for ordinary company information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says this skill is a tool for querying and analyzing mainland China company legal/risk data, triggered only for enterprise risk intents. However, this file documents a cross-cutting telemetry mechanism in cha88-base that reports skill invocation metadata to a gateway, which is materially different from the claimed risk-query behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 8)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 cha88-base
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhub

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 26)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 cha88-base
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhub

Credential Access

High
Category
Privilege Escalation
Confidence
63% confidence
Finding

Opening and parsing the project .env file causes the module to ingest potentially sensitive configuration into the runtime environment, even though the feature only needs simple tracking metadata. In this skill context, that creates unnecessary secret exposure surface and could enable accidental downstream leakage if other code reads or transmits environment variables.

Content

Scanner excerpt · scripts/_tracker.py (reported line 27)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

Executing _load_env_file() at import time injects .env contents into os.environ before any caller has a chance to constrain behavior. In an agent skill, import-time loading of potentially sensitive configuration is risky because it silently broadens accessible secrets and couples unrelated runtime state to telemetry support.

Content

Scanner excerpt · scripts/_tracker.py (reported line 43)May include surrounding context.

python
os.environ[key] = value


# 模块加载时解析一次 .env
_load_env_file()

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says this skill is for querying and analyzing company legal/risk signals only, and explicitly says pure enterprise information lookup should not trigger this skill. However, the file is documented and implemented as '企业搜索/企业查询', accepts a company-name keyword, calls company_search, and formats general company profile fields such as legal representative, registered capital, establishment date, type, and address rather than risk data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation performs a generic company search against /api/companySearch/1.0.0 rather than a risk- or legal-risk-specific query as promised by the skill manifest. This mismatch can cause the router to invoke the skill for sensitive compliance or risk-review tasks while returning broader enterprise-search data, creating unauthorized data access, policy bypass, and misleading outputs in a security-sensitive context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements an AK credential configuration and storage workflow even though the advertised skill is only for enterprise risk/legal-risk lookup. Introducing secret-handling functionality that is outside the declared purpose expands the attack surface, may enable unauthorized credential capture or persistence, and violates least privilege for the skill. The mismatch between stated functionality and actual behavior makes the skill context more dangerous because users invoking a company-risk tool would not reasonably expect it to write or manage access keys.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This configuration service persists credentials under SKILL_NAME = "cha88-base", which does not match the manifested enterprise-risk skill. That cross-skill credential targeting can cause this skill to modify another skill's configuration, violating least privilege and potentially enabling credential confusion or unauthorized access paths.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope even though the documented behavior requires environment access, file reads/writes, and network calls. Without an allowlisted permission boundary, an agent/runtime may grant broader capabilities than users expect, increasing the chance of unintended secret access, local-state modification, or exfiltration via networked commands.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a tool focused on querying and analyzing company legal/risk information, with triggering restricted to enterprise-risk lookup intents. However, the CLI explicitly advertises a separate configure command for setting an AK, which is an additional administrative capability not reflected in the manifest’s described behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The CLI dynamically discovers and imports every capabilities/*/cmd.py module found under the scripts directory, allowing functionality beyond the skill's declared scope to become executable without explicit registration. This increases attack surface and can enable hidden or unintended commands to run if additional modules are introduced into the package or environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code reports usage after every command via _tracker.report_skill_usage() with no visible disclosure or consent mechanism in this file. In a tool handling enterprise risk queries, silent telemetry can expose sensitive business interests, searched entities, or operational metadata, making undisclosed tracking materially risky even if the main function is legitimate.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document for an enterprise-search capability explicitly instructs the agent to chain into companyRisk queries, expanding behavior beyond the capability’s stated scope. This creates scope drift and can cause the parent skill to invoke more sensitive risk-analysis actions than intended, especially when the capability is reused in contexts that should only return basic company lookup data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to transmit company identifiers such as unified social credit codes or companyId values to an external API without any user-facing notice about data handling, third-party transmission, or sensitivity. In an enterprise or compliance context, this can cause unintended disclosure of identifiers and risk-query activity, especially when users may assume the lookup is local or internal.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The instructions and quoted agent responses are entirely in Chinese, including prescribed output such as the AK acquisition prompt and success guidance. There is no indication that the skill is region-specific or that users may choose another language, so this creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.