Back to skill

Security audit

ai-morning-brief

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an AI daily-report generator, but it includes unsafe automatic delivery and networking choices that users should review before installing.

Install only after reviewing and editing the delivery and scheduling pieces. Remove or parameterize the hard-coded DingTalk session, avoid the cron entry that runs an external /root script, keep external push disabled until the destination is explicitly chosen, and do not provide broad credentials such as GITHUB_TOKEN unless a reviewed feature actually needs them. The network fetcher should also be fixed to keep TLS verification enabled and block private, loopback, link-local, and metadata-service URLs before use in sensitive environments.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ai_daily.py:291
Finding

Global TLS Certificate Verification Disabled

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ai_daily.py:301
Finding

Unrestricted URL Fetching Allows Server-Side Request Forgery

Content
View full analysis
str: # 机器之心需要使用真实浏览器 UA if use_browser_ua or 'jiqizhixin' in url: ua = 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36' else: ua = 'Mozilla/5.0 (compatible; AIDaily/1.0; +https://example.com/bot)' req = urllib.request.Request( url, headers={ 'User-Agent': ua, 'Accept': 'application/rss+xml, application/xml, text/xml', 'Accept-Language': 'zh-CN,zh;q=0.9,en;q=0.8' } ) try: with urllib.request.urlopen(req, context=self.ssl_context, timeout=timeout) as response: return response.read().decode('utf-8', errors='ignore') ``` RSS-controlled links are placed into report items: ```python link_elem = entry.find('link') if link_elem is not None: link = link_elem.get('href', link_elem.text) if hasattr(link_elem, 'get') else (link_elem.text or "") else: link = "" if title and link: items.append(NewsItem( title=title, source=url, url=link, published=published, content=content, category="rss" )) ``` The application later fetches those links: ```python try: # 抓取网页正文 content = fetcher.fetch_article_content(item.url) ``` `fetch_article_content()` passes the supplied value directly to `fetch_url()`: ```python def fetch_article_content(self, url: str) -> str: """抓取文章正文内容""" html = self.fetch_url(url, timeout=15) ``` ### Technical Analysis URLs can originate from editable configuration and from untrusted RSS or Atom entr ...[truncated 2141 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/push-to-dingtalk.sh:5
Finding

Generated Report Content Is Sent to a Hard-Coded DingTalk Group

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
install.md:23
Finding

Installation Guidance Creates Persistent Execution of an Unaudited External Script

Content
View full analysis
> /root/.openclaw/workspace/logs/ai_morning_report.log 2>&1 ``` The same absent script is also presented as the recommended execution method: ```bash python3 /root/.openclaw/workspace/scripts/ai_morning_report_push.py ``` The installation document acknowledges that the script is separate from the Skill: ```text **推送脚本(单独):** - `/root/.openclaw/workspace/scripts/ai_morning_report_push.py` ``` ### Technical Analysis The recommended cron entry survives the current Skill run and executes every day. However, `ai_morning_report_push.py` is not included in the audited project tree and resides outside the Skill directory. The user therefore cannot verify the behavior of the scheduled component from this package. Any file already present or later placed at that path will inherit automatic execution under the crontab owner's account. The external location can also change independently from the installed Skill. Scheduling is reasonable for a daily-report Skill when optional, transparent, and limited to audited package code. Persistently invoking an absent external delivery script exceeds that minimum requirement. ### Attack Path 1. A user follows the installation guide and adds the documented cron entry. 2. The cron entry persists across sessions and system restarts handled by the cron service. 3. At the scheduled time, Python executes `/root/.openclaw/workspace/scripts/ai_morning_report_push.py`. 4. The executed file is not part of the audited Skill and may contain unrelated, modified, or attacker-controlled behavior. 5. Any code in that file runs with the permissions of the crontab owner. 6. Replacing th ...[truncated 926 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/ai_daily.py:296
Finding

Skill Reads an Unused GitHub Credential Beyond Functional Need

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (49)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的核心能力是“抓取热点信息并生成简报”,但该代码实际执行的是“将已存在的日报推送到钉钉群”。这属于额外且未声明的对外通信能力,且代码主功能与描述不一致:没有体现抓取信息或生成简报,只体现分发/推送行为。虽然推送可能是整个技能的辅助环节,但就该代码片段本身而言,其实际用途与声明描述存在明显偏差,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个内容采集与简报生成技能,核心能力应包括抓取信息、整理内容并生成日报。而代码片段的行为是读取本地 output 目录中的日报文件,并基于正则规则做格式与内容完整性检查。这属于生成流程中的辅助质检脚本,不等同于抓取或生成本身。虽然它与“AI 日报”主题相关,但其主要目的与声明的主功能存在实质差异,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明的核心用途是“自动抓取热点信息并生成结构化中文简报”,而实际代码只是一个 view.sh 查看工具:解析日期参数,定位 output/AI-Daily-<date>.md 文件,若不存在则列出可用 Markdown 文件,存在则 cat 输出内容。它没有任何网络抓取、LLM/Agent 热点收集、摘要生成或简报构建逻辑。虽然“查看日报”可被视为相关配套功能,但该代码片段的主要行为与声明的主要目的明显不一致;同时声明权限为空,但代码确实读取本地文件并列目录。综上应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file description states it generates a structured Chinese briefing, and the filtering logic later excludes non-Chinese articles and papers rather than offering a language choice. This is a language-policy constraint applied by default, with no opt-in or user-selectable locale behavior documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The method comment says it supports Chinese filtering, and the implementation drops items that do not contain Chinese characters. Later comments and logic also skip English papers, which constitutes a natural-language locale restriction rather than a neutral processing choice.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file states that the skill generates Chinese summaries for multiple content types, which implies a forced language output. Under the policy rules, language constraints should not be imposed without explicit user opt-in or a clearly documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cron example hard-codes the timezone to Asia/Shanghai, and the surrounding natural-language comments and job text are written only in Chinese. This creates a locale-specific constraint without offering user opt-in or explaining that the example is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file repeatedly instructs the model to output in Chinese, which is a natural-language locale constraint. Under the policy rules, forcing a specific language without offering user choice or documenting a justified region-specific requirement is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSON schema requires the summary field to contain a Chinese summary, imposing a fixed output language. The file does not provide a language choice or explain a justified locale limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This prompt requires the summary output to be in Chinese, which is a locale policy constraint. There is no accompanying user opt-in or documented regional/business justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The report-generation prompt directs the model to produce a Chinese daily report and use professional but accessible Chinese. Because the file does not offer an alternative language or justify the locale restriction, this is a policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example code sends user-supplied prompt content to an external API and reads an API key from an environment variable. In this markdown file, there is no warning about external data transmission, credential use, or privacy implications alongside the example.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The filter sets the language to "zh-CN", which imposes a specific locale on the skill's output or content selection. In this file there is no accompanying indication that this is optional, user-selected, or justified as a region-specific tool, so it appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents behavior that fetches data from external services (RSS, Tavily, arXiv) and explicitly supports rerun overwrite behavior, but it does not include any caution about network access, API-backed data handling, or replacement of prior output files. For markdown files, safety-relevant behaviors that may affect privacy or user data should be disclosed clearly to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The quick-start and cron instructions encourage unattended recurring execution of a network-enabled script that writes local files, but they omit any warning about external requests, API-key use, or repeated file creation/overwrite. In an agent skill context, this can lead operators to enable persistent automated behavior without understanding the data egress and filesystem side effects, increasing the risk of privacy, compliance, or operational issues.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · delivery-report.md (reported line 194)May include surrounding context.

bash
# 每日 8:00 自动生成
crontab -e
0 8 * * * cd /home/admin/.openclaw/workspace/skills/ai-daily && bash scripts/generate.sh

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation advertises Azure TTS voice generation even though the skill description only mentions collecting information and generating a structured report. While not directly code execution, this expands outbound service usage and data handling beyond the user-visible description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide references push behavior and Feishu authorization but does not clearly warn that generated content may be transmitted to external services. This can lead users to unintentionally send internal, proprietary, or sensitive summaries outside the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cron setup enables unattended scheduled execution of a push script without prominently warning that content generation and transmission may occur automatically every day. Unattended operation increases the chance of repeated unintended disclosure, spam, or misuse if inputs, credentials, or destinations are misconfigured.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The documentation instructs users to install a persistent cron job that repeatedly executes a workspace script, establishing ongoing scheduled behavior. Persistence is risky here because it keeps code running after initial installation and can silently continue generating or pushing content using stored authorizations.

Content

Scanner excerpt · install.md (reported line 26)May include surrounding context.

3. 配置定时任务(可选)

bash
# 编辑 crontab
crontab -e

# 添加以下内容(每天 08:12 自动推送)
12 8 * * * python3 /root/.openclaw/workspace/scripts/ai_morning_report_push.py >> /root/.openclaw/workspace/logs/ai_morning_report.log 2>&1

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The format standard explicitly requires that the report contain only Chinese content, which is a natural-language locale constraint. Because the document does not present this as an opt-in preference or explain a region-specific necessity, it conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The repeated guidance to edit crontab reinforces persistent scheduled execution without corresponding security notice or disablement guidance. Even if intended for convenience, persistence can create ongoing external communication or background activity that outlives user awareness.

Content

Scanner excerpt · install.md (reported line 99)May include surrounding context.

Q3: 如何修改推送时间?

编辑 crontab:

bash
crontab -e
# 修改这一行的时间
12 8 * * * python3 /root/.openclaw/workspace/scripts/ai_morning_report_push.py

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown explicitly treats '中文内容检测' as a required validation criterion, which indicates the skill enforces a specific language. Elsewhere it also standardizes the TTS voice to zh-CN-XiaoxiaoNeural, but the document does not mention any user opt-in or language selection, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.