Back to skill

Security audit

1688 Finance Tax

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly a tax calculator, but its API-key storage, configurable credential destination, and automatic usage reporting need review before installation.

Review this skill before installing if you will use real business or tax data. Prefer a platform-managed secret store over telling the agent your AK or passing it on the command line, verify OPENCLAW_GATEWAY_URL is trusted and local or HTTPS, and assume usage events may be reported to the 1688 gateway after commands run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/capabilities/configure/service.py:57
Finding

API Key Exposed Through Command-Line Arguments and Unprotected Plaintext Storage

Content
View full analysis
bool: """Directly write openclaw.json as a fallback.""" try: config: dict = {} if OPENCLAW_CONFIG_PATH.exists(): try: with open(OPENCLAW_CONFIG_PATH, "r", encoding="utf-8") as config_file: content = config_file.read().strip() if content: config = json.loads(content) except json.JSONDecodeError: return False config.setdefault("skills", {}) config["skills"].setdefault("entries", {}) config["skills"]["entries"].setdefault(SKILL_NAME, {}) skill_entry = config["skills"]["entries"][SKILL_NAME] skill_entry["apiKey"] = api_key # Remove the legacy format. if "env" in skill_entry and isinstance(skill_entry["env"], dict): skill_entry["env"].pop(ENV_AK_NAME, None) if not skill_entry["env"]: del skill_entry["env"] OPENCLAW_CONFIG_PATH.parent.mkdir(parents=True, exist_ok=True) with open(OPENCLAW_CONFIG_PATH, "w", encoding="utf-8") as config_file: json.dump(config, config_file, ensure_ascii=False, indent=2) return True except Exception: return False ``` ### Technical Analysis The configuration interface r ...[truncated 2231 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/capabilities/configure/service.py:24
Finding

Environment-Controlled Gateway URL Can Receive API Keys and Bearer Tokens

Content
View full analysis
bool: """Write configuration through the OpenClaw Gateway REST API.""" try: import requests except ImportError: return False gateway_url = os.environ.get("OPENCLAW_GATEWAY_URL", "http://localhost:18789") token = os.environ.get("OPENCLAW_GATEWAY_TOKEN", "") payload = { "skills": { "entries": { SKILL_NAME: { "apiKey": api_key } } } } try: headers = {} if token: headers["Authorization"] = f"Bearer {token}" response = requests.patch( f"{gateway_url}/api/config", headers=headers, json=payload, timeout=5, ) return response.ok except Exception: return False ``` ### Technical Analysis `OPENCLAW_GATEWAY_URL` is used directly as the destination for a request containing the complete finance-tax API key. When present, `OPENCLAW_GATEWAY_TOKEN` is also placed in the `Authorization` header. The implementation does not validate: - Whether the destination is a loopback address or an approved gateway host. - Whether a remote destination uses HTTPS. - Whether URL user information, fragments, or unusual schemes are present. - Whether redirects remain within the approved destination. - Whether TLS verification and destination policy are appropriate for remote gateway use. The `requests` library follows redirects by default. Consequently, even an initially expected endpoint could redirect the request and its sensitive JSON body to another destination. Authorization-header forwarding behavior may vary by redirect relationship, but the API key remains in the request body and i ...[truncated 1804 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (44)

Tainted flow: 'gateway_url' from os.environ.get (line 31, credential/environment) → requests.patch (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/capabilities/configure/service.py (reported line 48)May include surrounding context.

python
headers = {}
        if token:
            headers["Authorization"] = f"Bearer {token}"
        response = requests.patch(
            f"{gateway_url}/api/config",
            headers=headers, json=payload, timeout=5,
        )

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Direct reading and writing of openclaw.json, environment AKs, and configuration state via REST or local file mutation is materially more powerful than the advertised tax-analysis use case. This creates integrity and confidentiality risks because a user may trigger secret discovery, config tampering, or persistence mechanisms under the guise of a benign financial workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Direct reading and writing of openclaw.json, environment AKs, and configuration state via REST or local file mutation is materially more powerful than the advertised tax-analysis use case. This creates integrity and confidentiality risks because a user may trigger secret discovery, config tampering, or persistence mechanisms under the guise of a benign financial workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Direct reading and writing of openclaw.json, environment AKs, and configuration state via REST or local file mutation is materially more powerful than the advertised tax-analysis use case. This creates integrity and confidentiality risks because a user may trigger secret discovery, config tampering, or persistence mechanisms under the guise of a benign financial workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Direct reading and writing of openclaw.json, environment AKs, and configuration state via REST or local file mutation is materially more powerful than the advertised tax-analysis use case. This creates integrity and confidentiality risks because a user may trigger secret discovery, config tampering, or persistence mechanisms under the guise of a benign financial workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Direct reading and writing of openclaw.json, environment AKs, and configuration state via REST or local file mutation is materially more powerful than the advertised tax-analysis use case. This creates integrity and confidentiality risks because a user may trigger secret discovery, config tampering, or persistence mechanisms under the guise of a benign financial workflow.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 8)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-finance-tax
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhub

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 25)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-finance-tax
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhub

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 40)May include surrounding context.

python
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。

环境变量(从项目根目录 .env 读取):
    SKILL_NAME     skill 名称,默认 1688-finance-tax
    SKILL_VERSION  skill 版本,默认 1.0.0
    SKILL_CHANNEL  发布渠道,默认 clawhub

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/_tracker.py (reported line 26)May include surrounding context.

python
def _load_env_file() -> None:
    """解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
    env_path = _ROOT_DIR / ".env"
    if not env_path.exists():
        return
    with open(env_path, encoding="utf-8") as f:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code reads API keys from environment variables and stores them in persistent configuration, which is not justified by a tax-calculation skill's stated purpose. In this context, secret access and persistence are especially suspicious because they create an unnecessary credential exposure surface unrelated to tax computations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This skill is described as a finance/tax calculation tool, but the code instead performs runtime credential configuration and persistence. That mismatch is dangerous because it expands the skill's privileges and secret-handling behavior beyond user expectations, increasing the chance of covert credential collection or unauthorized platform reconfiguration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs integrators to enforce a '中文输出' constraint for customers. This is a natural-language locale policy restriction, and the file does not indicate any user choice, opt-in, or justified region-specific limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The distribution document explicitly states that the skill includes direct HTTP GET calls to a pre-production API and a telemetry reporting module, which exceeds the stated finance/tax calculation purpose and introduces external network behavior not obvious from the high-level skill description. Hidden or under-disclosed network access increases the risk of unintended data disclosure, dependency on insecure pre-production services, and unexpected outbound communication from an agent environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

An HTTP GET telemetry/reporting mechanism is documented even though such tracking is not necessary for local tax estimation functionality. This creates a risk that user inputs, metadata, or usage patterns are transmitted externally without clear necessity or informed consent, which is especially sensitive in a finance/tax context where queries may contain business or taxpayer information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises execution capabilities that imply access to environment variables, local files, write operations, and network communication, but it does not declare any explicit tool scope or allowed-tools boundary. That weakens least-privilege controls and makes it harder to constrain credential access, file modification, and outbound requests if the skill or its referenced code behaves unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance says to use the skill whenever the user mentions broad terms like '税务', '税率', '发票', or '纳税人' together with calculation issues, but it does not clearly bound when the skill should not activate. Several of these terms are common in general business discussions, so the trigger scope is ambiguous and may cause unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document states that '对客中文' is a hard requirement, which forces a specific output language regardless of user preference. This is a natural-language locale policy issue because no user choice or opt-in mechanism is provided.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI unconditionally attempts to report skill usage after every command, even though this tax-calculation skill's declared purpose does not mention telemetry. Hidden or unrelated data reporting can create privacy and compliance risks, especially in a finance/tax context where command arguments may contain sensitive business or tax information if the tracker captures them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Telemetry is triggered automatically after every command with no visible notice, consent, or configuration in this file. In a tax-oriented skill, silent reporting is more concerning because users may reasonably expect confidentiality around pricing, invoices, taxpayer status, and related financial calculations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction '仅使用中文' forces a specific language for all user-facing content. Under the policy, language constraints are only acceptable when the user is given a choice or the restriction is clearly justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational guidance exclusively in Chinese and does not mention any option for other languages or a user language preference. Under the policy rule for natural-language violations, forcing a specific language without opt-in is in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs collection of sensitive financial and tax-related data such as报价、上游成本、获票情况、利润/利润率, but provides no notice about privacy, retention, or minimization. Even if needed for calculation, missing data-handling guidance can cause users to disclose confidential business information without informed consent, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language documentation entirely in Chinese, starting with the module docstring and continuing through function docstrings/comments. The policy for this audit flags language or locale constraints when a skill forces a specific language without user opt-in, and this file does not indicate any optional language selection or a clearly justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural-language strings entirely in Chinese, including the module description and runtime error/output messages. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.