T09 · Insecure Skill Coding Practices
- Location
scripts/ai_daily.py:291- Finding
Global TLS Certificate Verification Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches an AI daily-report generator, but it includes unsafe automatic delivery and networking choices that users should review before installing.
Install only after reviewing and editing the delivery and scheduling pieces. Remove or parameterize the hard-coded DingTalk session, avoid the cron entry that runs an external /root script, keep external push disabled until the destination is explicitly chosen, and do not provide broad credentials such as GITHUB_TOKEN unless a reviewed feature actually needs them. The network fetcher should also be fixed to keep TLS verification enabled and block private, loopback, link-local, and metadata-service URLs before use in sensitive environments.
scripts/ai_daily.py:291Global TLS Certificate Verification Disabled
scripts/ai_daily.py:301Unrestricted URL Fetching Allows Server-Side Request Forgery
scripts/push-to-dingtalk.sh:5Generated Report Content Is Sent to a Hard-Coded DingTalk Group
install.md:23Installation Guidance Creates Persistent Execution of an Unaudited External Script
scripts/ai_daily.py:296Skill Reads an Unused GitHub Credential Beyond Functional Need
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
声明描述的核心能力是“抓取热点信息并生成简报”,但该代码实际执行的是“将已存在的日报推送到钉钉群”。这属于额外且未声明的对外通信能力,且代码主功能与描述不一致:没有体现抓取信息或生成简报,只体现分发/推送行为。虽然推送可能是整个技能的辅助环节,但就该代码片段本身而言,其实际用途与声明描述存在明显偏差,因此应判定为不匹配。
声明描述的是一个内容采集与简报生成技能,核心能力应包括抓取信息、整理内容并生成日报。而代码片段的行为是读取本地 output 目录中的日报文件,并基于正则规则做格式与内容完整性检查。这属于生成流程中的辅助质检脚本,不等同于抓取或生成本身。虽然它与“AI 日报”主题相关,但其主要目的与声明的主功能存在实质差异,因此应判定为描述与实际行为不匹配。
声明的核心用途是“自动抓取热点信息并生成结构化中文简报”,而实际代码只是一个 view.sh 查看工具:解析日期参数,定位 output/AI-Daily-<date>.md 文件,若不存在则列出可用 Markdown 文件,存在则 cat 输出内容。它没有任何网络抓取、LLM/Agent 热点收集、摘要生成或简报构建逻辑。虽然“查看日报”可被视为相关配套功能,但该代码片段的主要行为与声明的主要目的明显不一致;同时声明权限为空,但代码确实读取本地文件并列目录。综上应判定为描述与实际行为不匹配。
The file description states it generates a structured Chinese briefing, and the filtering logic later excludes non-Chinese articles and papers rather than offering a language choice. This is a language-policy constraint applied by default, with no opt-in or user-selectable locale behavior documented.
The method comment says it supports Chinese filtering, and the implementation drops items that do not contain Chinese characters. Later comments and logic also skip English papers, which constitutes a natural-language locale restriction rather than a neutral processing choice.
Without declared permissions the skill's intent is opaque and cannot be validated.
This markdown file states that the skill generates Chinese summaries for multiple content types, which implies a forced language output. Under the policy rules, language constraints should not be imposed without explicit user opt-in or a clearly documented regional justification.
The cron example hard-codes the timezone to Asia/Shanghai, and the surrounding natural-language comments and job text are written only in Chinese. This creates a locale-specific constraint without offering user opt-in or explaining that the example is intentionally region-specific.
This markdown file repeatedly instructs the model to output in Chinese, which is a natural-language locale constraint. Under the policy rules, forcing a specific language without offering user choice or documenting a justified region-specific requirement is a violation.
The JSON schema requires the summary field to contain a Chinese summary, imposing a fixed output language. The file does not provide a language choice or explain a justified locale limitation.
This prompt requires the summary output to be in Chinese, which is a locale policy constraint. There is no accompanying user opt-in or documented regional/business justification in the file.
The report-generation prompt directs the model to produce a Chinese daily report and use professional but accessible Chinese. Because the file does not offer an alternative language or justify the locale restriction, this is a policy issue.
The example code sends user-supplied prompt content to an external API and reads an API key from an environment variable. In this markdown file, there is no warning about external data transmission, credential use, or privacy implications alongside the example.
The filter sets the language to "zh-CN", which imposes a specific locale on the skill's output or content selection. In this file there is no accompanying indication that this is optional, user-selected, or justified as a region-specific tool, so it appears to violate the language/locale policy requirement.
This markdown file documents behavior that fetches data from external services (RSS, Tavily, arXiv) and explicitly supports rerun overwrite behavior, but it does not include any caution about network access, API-backed data handling, or replacement of prior output files. For markdown files, safety-relevant behaviors that may affect privacy or user data should be disclosed clearly to the user.
The quick-start and cron instructions encourage unattended recurring execution of a network-enabled script that writes local files, but they omit any warning about external requests, API-key use, or repeated file creation/overwrite. In an agent skill context, this can lead operators to enable persistent automated behavior without understanding the data egress and filesystem side effects, increasing the risk of privacy, compliance, or operational issues.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 每日 8:00 自动生成
crontab -e
0 8 * * * cd /home/admin/.openclaw/workspace/skills/ai-daily && bash scripts/generate.sh
The documentation advertises Azure TTS voice generation even though the skill description only mentions collecting information and generating a structured report. While not directly code execution, this expands outbound service usage and data handling beyond the user-visible description.
The guide references push behavior and Feishu authorization but does not clearly warn that generated content may be transmitted to external services. This can lead users to unintentionally send internal, proprietary, or sensitive summaries outside the local environment.
The cron setup enables unattended scheduled execution of a push script without prominently warning that content generation and transmission may occur automatically every day. Unattended operation increases the chance of repeated unintended disclosure, spam, or misuse if inputs, credentials, or destinations are misconfigured.
The documentation instructs users to install a persistent cron job that repeatedly executes a workspace script, establishing ongoing scheduled behavior. Persistence is risky here because it keeps code running after initial installation and can silently continue generating or pushing content using stored authorizations.
# 编辑 crontab
crontab -e
# 添加以下内容(每天 08:12 自动推送)
12 8 * * * python3 /root/.openclaw/workspace/scripts/ai_morning_report_push.py >> /root/.openclaw/workspace/logs/ai_morning_report.log 2>&1
The format standard explicitly requires that the report contain only Chinese content, which is a natural-language locale constraint. Because the document does not present this as an opt-in preference or explain a region-specific necessity, it conflicts with the policy against forcing a specific language without user choice.
The repeated guidance to edit crontab reinforces persistent scheduled execution without corresponding security notice or disablement guidance. Even if intended for convenience, persistence can create ongoing external communication or background activity that outlives user awareness.
编辑 crontab:
crontab -e
# 修改这一行的时间
12 8 * * * python3 /root/.openclaw/workspace/scripts/ai_morning_report_push.py
The markdown explicitly treats '中文内容检测' as a required validation criterion, which indicates the skill enforces a specific language. Elsewhere it also standardizes the TTS voice to zh-CN-XiaoxiaoNeural, but the document does not mention any user opt-in or language selection, which is a natural-language locale policy concern.
No suspicious patterns detected.