Back to skill

Security audit

1688 Distribution Material Newton

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its 1688 material-optimization purpose, but it exposes access keys and tokens through chat, command arguments, plaintext files, and environment-controlled network destinations.

Review this skill before installing. It needs a 1688 AK for its advertised features, but you should avoid pasting secrets into normal chat or exposing them in command history. Only use it in a trusted local environment, verify OPENCLAW_GATEWAY_URL and BASE_URL are not overridden to unexpected hosts, and rotate any AK or ISV token previously entered through chat or command arguments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/biz/configure/service.py:35
Finding

Access Key Can Be Transmitted to an Attacker-Controlled Gateway

Content
View full analysis
`. 3. `configure_via_gateway` constructs a request containing the complete AK in `payload.skills.entries`. 4. The Skill sends the payload to the attacker-controlled URL. 5. If present, the OpenClaw gateway bearer token is also included in the `Authorization` header. 6. ...[truncated 477 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/10_ak_configure.md:18
Finding

Access Key Is Collected Through Chat and Passed in Process Arguments

Content
View full analysis
``` - 配置完成后,直接继续执行用户最初的需求,无需额外说明。 ``` ### Technical Analysis The documented workflow explicitly asks the user to send the AK in a chat message. It then instructs the Agent to place the extracted AK directly in the command-line argument list. This exposes the secret through two independent channels: - The chat message can be retained in conversation history, telemetry, support exports, or Agent execution records. - Command-line arguments may be visible in process inspection tools, execution logs, shell history, job records, or orchestration audit trails. Masking the credential in the command's later output does not protect the original chat message or process argument. ### Attack Path 1. The Skill reports that no AK is configured. 2. Following the Skill instructions, the Agent asks the user to submit the AK in chat. 3. The user sends the complete credential, causing it to enter the conversation record. 4. The Agent invokes `cli.py configure` with the AK as an argument. 5. A party with access to transcripts, execution logs, shell history, or process metadata retrieves the credential. 6. The exposed AK is reused outside the Skill within the permissions granted to that credential. ### Impact Assessment The vulnerability can disclose a long-lived identity credential to local observers or systems retaining Agent transcripts and execution metadata. An attacker obtaining the AK may invoke 1688 gateway functionality under the affected user's identity, limited only by the AK's server-side perm ...[truncated 12 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/biz/isv_token/cmd.py:20
Finding

ISV Tokens Are Exposed in CLI Output and Stored in a Plaintext File

Content
View full analysis
None: """将所有 ISV token 保存到本地文件。""" TOKEN_FILE.parent.mkdir(parents=True, exist_ok=True) with open(TOKEN_FILE, "w", encoding="utf-8") as f: json.dump(tokens, f, ensure_ascii=False, indent=2) # 设置文件权限为 600(仅当前用户可读写) os.chmod(TOKEN_FILE, 0o600) ``` ### Technical Analysis Both the `fetch` and `status` operations place the complete token in the structured CLI output. In an Agent environment, tool output may be retained in transcripts, logs, traces, or debugging systems. A st ...[truncated 1621 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
examples/check_env.py:35
Finding

Example Installer Retrieves an Unpinned Runtime Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (94)

Tainted flow: 'cmd' from input (line 28, user input) → subprocess.run (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · examples/set_ak.py (reported line 29)May include surrounding context.

python
return

    cmd = [sys.executable, os.path.join(_PROJECT_ROOT, "scripts", "capabilities", "configure", "cmd.py"), ak]
    result = subprocess.run(cmd, capture_output=True, text=True, cwd=_PROJECT_ROOT)

    output = result.stdout.strip()
    if output:

Tainted flow: 'gateway_url' from os.environ.get (line 35, credential/environment) → requests.patch (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The code builds a network destination from the untrusted OPENCLAW_GATEWAY_URL environment variable and then sends the provided API key to that endpoint. Because the default is plain HTTP and there is no validation of scheme, host, or certificate expectations, a local or manipulated environment can redirect secrets to an attacker-controlled service or expose them in transit.

Content

Scanner excerpt · scripts/biz/configure/service.py (reported line 52)May include surrounding context.

python
headers = {}
        if token:
            headers["Authorization"] = f"Bearer {token}"
        resp = requests.patch(f"{gateway_url}/api/config",
                              headers=headers, json=payload, timeout=5)
        return resp.ok
    except Exception:

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Accessing tokens from environment variables and persisting them under the user home directory are sensitive operations outside the expected scope of a creative optimization skill. This matters because local persistence of secrets increases exposure to other local processes, backups, and accidental check-in or exfiltration.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The documented project structure and behavior indicate credential access through environment variables and related check/setup scripts. In combination with file write, network, and shell capabilities, credential handling is security-sensitive because secrets may be read, persisted, or exposed beyond the narrow business task users expect.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
1688-distribution-material-newton/
├── SKILL.md                                        # 主控 skill(本文档)
├── cli.py                                          # CLI 统一入口
├── .env                                            # Skill 基础信息
├── examples/                                       # 示例脚本
│   ├── check_env.py                                # 环境检查
│   ├── check_ak_exist.py                           # AK 配置检查

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file's behavior is entirely focused on local Python environment validation and dependency installation, not on the manifest's advertised image/title/material optimization capabilities. This mismatch is dangerous because off-purpose code in a skill can conceal unnecessary execution paths, erode user trust, and create opportunities for unintended local system modification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This example script performs package installation via subprocess, which is unrelated to the declared 1688 material-optimization skill behavior. In a skill package, unrelated environment-modifying code increases trust and supply-chain risk because users or reviewers may run it assuming it is necessary for the skill, causing unexpected system changes.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions tell the agent to solicit the user's AK secret directly in chat using a phrase like '我的AK是 xxxxxx' and extract the credential from the message. This is dangerous because chat is commonly retained, inspected, or exported, so a valid API credential may be captured and reused by unauthorized parties, leading to account or API misuse.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 8)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-open-skill-template
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhub

Static analysis

No suspicious patterns detected.