Back to skill

Security audit

设计框架套件 - 主控路由

Security checks for vulnerabilities and agentic risk

Overview

This skill is presented as a Telegram routing component, but it includes broad helper scripts that read local credentials, call OpenRouter, send Telegram messages or images, and accept unrestricted file and destination inputs.

Review this carefully before installing. It may be useful for a Telegram-based design generation workflow, but it uses stored OpenRouter and Telegram credentials, sends content to external services, can forward local file contents to Telegram targets supplied by callers, and has unsafe shell/Python handling that should be fixed before use on any shared or sensitive system.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
generate_prompt.sh:22
Finding

Untrusted Arguments Are Interpolated into Executable Python Source

Content
View full analysis
"$ENV_FILE" ``` The same unsafe construction appears in other scripts. For example: ```bash python3 << PYEOF import re, sys try: with open("$FRAMEWORK_FILE") as f: text = f.read() ``` ```bash python3 -c " import json print(json.dumps({'bot_token': '''$BOT_TOKEN''', 'chat_id': '$TARGET'})) " > "$KEY_TMPFILE" ``` ```bash python3 << PYEOF import json, urllib.request, time, sys with open("$KEY_TMPFILE") as f: env = json.load(f) with open("$MSG_FILE") as f: text = f.read() ``` ### Technical Analysis Shell variables are expanded directly into Python programs passed through `python3 -c` or unquoted heredocs. Quoting a value with Python triple quotes does not make it safe. An argument containing triple-quote delimiters or a filename containing quotation marks and Python syntax can terminate the intended string and introduce an arbitrary Python expression or statement. Affected externally supplied values include: - `FRAMEWORK_FILE` and `IMAGE_FILE` in `generate_prompt.sh` - `FRAMEWORK_FILE` in `extract_ratio.sh` - `ASPECT_RATIO` in `generate_image.sh` - `TARGET` in `send.sh` - `MSG_FILE` and `TARGET` in `send_text.sh` For triple-quoted fields, a value shaped like the following can introduce expression evaluation: ```text ''' + (__import__('os').system('ATTACKER_COMMAND') or '') + ''' ``` For a value placed inside a normal double-quoted Python string, a quotation mark followed by Python statements can escape the string. This is not re ...[truncated 1629 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
generate_prompt.sh:12
Finding

Predictable Temporary Files Expose API Keys and Telegram Bot Tokens

Content
View full analysis
&2 # 将变量写入临时 json,供 Python 读取(避免 heredoc 变量展开问题) ENV_FILE="/tmp/openclaw-genprompt-env-$$.json" # 无论成功还是失败,退出时都清理临时文件(含 API Key 明文) trap 'rm -f "$ENV_FILE"' EXIT python3 -c " import json, sys data = { 'api_key': '''$API_KEY''', 'framework_file': '''$FRAMEWORK_FILE''', 'image_file': '''$IMAGE_FILE''' } print(json.dumps(data)) " > "$ENV_FILE" ``` Comparable files include: ```bash KEY_TMPFILE="/tmp/openclaw-img-key-$$.json" ``` ```bash KEY_TMPFILE="/tmp/openclaw-send-key-$$.json" ``` ```bash KEY_TMPFILE="/tmp/openclaw-sendtext-key-$$.json" ``` ### Technical Analysis The scripts construct temporary filenames in the shared `/tmp` directory using the process ID. Process IDs are observable or guessable, and the files are created using ordinary shell redirection rather than `mktemp` with exclusive creation. No restrictive `umask` or explicit file mode is set. With a common `umask` of `022`, files created through redirection can be readable by other local users. These files contain plaintext OpenRouter API keys or Telegram bot tokens. Predictable creation also introduces a symbolic-link race. A local attacker may pre-create a path that the script is expected to use and point it at another file writable by the OpenClaw account. Shell redirection follows the symbolic link, potentially overwriting that destination with secret-bearing JSON. The `trap` reduces the lifetime of the files but does not prevent disclosure or a race while the script is running. Additionally ...[truncated 1588 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
send.sh:4
Finding

Telegram Sending Helpers Permit Arbitrary File and Destination Selection

Content
View full analysis
\" \"\"" >&2 exit 1 fi BOT_TOKEN=$(python3 -c "import json; print(json.load(open('$HOME/.openclaw/openclaw.json'))['channels']['telegram']['botToken'])") # 写入临时文件供 Python 读取 MSG_TMPFILE="/tmp/openclaw-send-msg-$$.txt" KEY_TMPFILE="/tmp/openclaw-send-key-$$.json" # 无论成功还是失败,退出时都清理临时文件(含 Bot Token 明文) trap 'rm -f "$MSG_TMPFILE" "$KEY_TMPFILE"' EXIT if [ -f "$FRAMEWORK_TEXT" ]; then # 用 cat 直接写入临时文件,避免命令替换吞末尾换行 printf '%s\n' "📋 设计框架(来自群组设计需求):" > "$MSG_TMPFILE" printf '\n' >> "$MSG_TMPFILE" cat "$FRAMEWORK_TEXT" >> "$MSG_TMPFILE" else printf '%s' "📋 设计框架(来自群组设计需求): ${FRAMEWORK_TEXT}" > "$MSG_TMPFILE" fi python3 -c " import json print(json.dumps({'bot_token': '''$BOT_TOKEN''', 'chat_id': '$TARGET'})) " > "$KEY_TMPFILE" ``` The image helper similarly accepts any existing image and any destination: ```bash IMAGE_FILE="${1:-}" TARGET="${2:-}" if [ -z "$IMAGE_FILE" ] || [ -z "$TARGET" ]; then echo "Usage: ./send_image_only.sh \"<图片文件路径>\" \"\"" >&2 exit 1 fi # ... RESPONSE=$(curl -s -X POST "https://api.telegram.org/bot${BOT_TOKEN}/sendPhoto" \ -F "chat_id=${TARGET}" \ -F "photo=@${IMAGE_FILE}" \ -F "caption=🎨 设计框架图") ``` ### Technical Analysis The documentation states that generated material is sent to the configured bot owner and group. However, the sending scripts do not enforce either configured identity. They accept a destination directly from the caller and use the privileged Telegram bot token to send data to that destination. `send.sh` additionally interprets its first argument as a local file whenever ...[truncated 1924 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个负责消息监听和状态路由的主控 skill,但提供的代码并未包含任何消息处理、事件触发、群聊监听或子 skill 调度逻辑。它的主要功能是读取本地配置并提供文件路径/ID 等参数。虽然配置读取可能是该系统的辅助模块,但就该代码片段本身而言,其实际行为与声明的核心目的明显不符,因此应判定为 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

声明描述的是一个负责监听 Telegram 群消息并按状态分发到子技能的主控路由能力,但实际提供的代码只是 config.sh 配置文件。它确实与该系统相关,因为包含群组、触发 mention 和 bot 标识等参数;但就此代码片段本身而言,并没有实现所声明的核心行为。另一方面,配置里还出现了“将设计框架和概念图私发给主人”的目标用户 ID,这属于描述中未明确提及的能力方向。基于描述与该代码片段实际行为/能力不一致,应判定为存在 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个消息驱动的主控路由器 skill,核心能力应是监听群消息、识别 @mention、根据状态分发到子 skill。实际代码却是一个独立的本地脚本:接收文件路径参数,读取文件,解析像素尺寸或比例文本,并映射到预定义标准宽高比后输出结果。两者在主要用途、触发方式和功能能力上都明显不一致,因此应判定为描述与行为严重不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个“主控路由”类 skill,核心能力应是监听群消息并按状态分发到子 skill。提供的代码却完全没有任何消息监听、@mention 检测、状态管理或子 skill 路由逻辑。相反,它是一个独立的图像生成实现,包含读取本地配置文件中的 OpenRouter 凭据、调用外部图像生成接口、处理返回图像并写入本地磁盘等能力。这些都是与声明用途显著不同的主要行为,因此属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个消息驱动的“主控路由”组件,其核心职责应是接收群消息、识别 @mention、根据状态分发到不同子技能。但实际代码完全没有消息监听、事件处理、会话状态或子技能路由相关实现。相反,它是一个独立的 prompt 生成工具:接收文件路径参数,读取本地设计框架和图片,调用远程模型生成生图提示词,并在失败时使用本地规则降级生成。因此其主要目的与声明严重不符。此外,代码还涉及本地凭据读取、文件访问和外部 API 请求,这些资源访问和能力也未在声明中体现。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个主控路由器型 skill,核心行为应为监听群消息 @mention、维护/读取状态并路由到子 skill。提供的代码却仅实现了一个消息发送工具:接收文本或文件路径和目标用户 ID,读取本地 openclaw 配置中的 Telegram 凭据,构造消息内容,按 Telegram 长度限制切分,并调用 sendMessage 接口私发。两者在主要用途、触发方式和资源访问上均明显不一致。尤其是声明未提及任何本地敏感配置读取、Telegram 私信发送或网络调用能力,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个主控路由类 skill:监听群消息 @mention,并根据状态分发到子 skill。但实际代码并未实现任何消息监听、@mention 解析、状态管理或子 skill 路由逻辑。相反,它执行的是独立的消息发送功能:校验本地图片文件、从 $HOME/.openclaw/openclaw.json 读取 Telegram botToken,然后通过 Telegram 的 sendPhoto API 将图片发送到指定目标。这属于 materially different primary purpose,且包含未声明的外部通信与敏感配置访问能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个“主控路由”类技能,核心行为应是监听群消息、识别 @mention、根据状态选择并调用子技能。实际代码没有任何监听、路由、状态管理或子 skill 调用逻辑,而是一个独立的消息发送工具。它还访问了未声明的本地配置资源($HOME/.openclaw/openclaw.json 中的 Telegram 凭据),并对外发起网络请求发送消息到 Telegram。这些都是与声明目的明显不同的主要能力,因此属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

声明描述的是一个‘主控路由’能力,核心行为应是监听群消息中的 @mention,并依据状态分发到子技能。但提供的代码并未实现消息监听或路由逻辑,而是执行定时/条件式的超时检查、清理本地临时状态,并在超时时向 Telegram 群发出取消通知。这属于与声明主目的明显不同的功能。虽然这些操作可能是某个设计框架流程的辅助部分,但就该代码块本身而言,其实际行为并不能被‘监听群消息并路由’准确代表,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code performs remote image generation, sends user content off-host, and writes generated files to disk, which materially differs from the declared role of a routing controller. This mismatch is dangerous because operators may grant or invoke the skill under false assumptions, enabling unreviewed network access and file creation in a context that appears low-risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation materially differs from the stated metadata: instead of only routing group mentions, it generates image prompts, reads local files, accesses credentials, and sends data to an external LLM API. This mismatch undermines user trust and platform security review because users may grant or invoke the skill under false assumptions about its behavior.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

The fallback logic directly extracts and emits up to 300-400 characters from the supplied framework text, which can unintentionally reproduce sensitive or proprietary content instead of generating a sanitized summary. If the framework file contains secrets, internal instructions, or confidential copy, the script may expose them verbatim in downstream outputs or logs.

Content

Scanner excerpt · generate_prompt.sh (reported line 69)May include surrounding context.

sh
if not prompt:
        # 终极兜底:截取框架前 300 字
        prompt = re.sub(r'\s+', ' ', framework_text)[:300].strip()
    return prompt
# ──────────────────────────────────────────────

if image_file and image_file.strip():

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script exfiltrates supplied design-framework content to Telegram and independently retrieves bot credentials from local configuration, which materially exceeds the declared role of a routing skill. In an agent-skill context, this creates an undisclosed outbound data channel for potentially sensitive user or group content and enables private forwarding outside the original conversation boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata describes a routing controller for group @mentions, but this script reads Telegram credentials and sends a private photo message to an arbitrary target chat. That capability materially exceeds the stated purpose and enables covert exfiltration or unauthorized outbound messaging under the bot identity.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · send_image_only.sh (reported line 25)May include surrounding context.

sh
BOT_TOKEN=$(python3 -c "import json; print(json.load(open('$HOME/.openclaw/openclaw.json'))['channels']['telegram']['botToken'])")

RESPONSE=$(curl -s -X POST "https://api.telegram.org/bot${BOT_TOKEN}/sendPhoto" \
  -F "chat_id=${TARGET}" \
  -F "photo=@${IMAGE_FILE}" \
  -F "caption=🎨 设计框架图")

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script retrieves a persisted Telegram bot token from a local credential store and can send arbitrary file contents to any provided chat ID. That is materially broader than the stated skill purpose of routing group @mentions, so it creates an exfiltration and unauthorized outbound messaging capability using stored credentials.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · timeout_notify.sh (reported line 16)May include surrounding context.

sh
elapsed=$(( now - triggered ))

if [ "$elapsed" -ge 600 ]; then
    rm -f /tmp/design-framework-waiting \
          /tmp/design-framework-timestamp \
          /tmp/design-framework-sender-username \
          /tmp/design-framework-ref-image \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill manifest declares disable-model-invocation: true but does not declare any permissions or allowed-tools, while the surrounding description clearly implies interaction with Telegram and operational installation steps. In a skill that can trigger network and shell-capable behavior through sub-skills or runtime integration, missing tool scoping weakens least-privilege controls and makes unintended external access harder to audit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and the entire SKILL.md content are written only in Chinese, with no indication that users may choose another language or locale. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This shell config file contains user-facing natural-language instructions exclusively in Chinese, including deployment guidance and field descriptions. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script reads a persistent OpenRouter API key from the user's local configuration and uses it to call an external service, even though the skill metadata describes a message-routing controller rather than an image-generation client. This expands the skill's authority beyond its stated purpose and creates credential-use and data-exfiltration risk if the skill is invoked unexpectedly or repurposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script silently retrieves a sensitive API key from local credentials and transmits it in an Authorization header to a third-party service without any disclosure or consent flow. While the key is intended for that service, undisclosed credential use is still a security and trust issue because users may not expect this skill to consume stored secrets at all.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user's prompt is sent to an external API with no explicit privacy or network disclosure, which can expose sensitive text, business data, or personal information to a third party. In the context of a skill presented as a routing tool, this is more concerning because users are less likely to anticipate outbound transmission of message content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script reads an API credential directly from the user's home directory and uses it to call a third-party service, despite the declared skill purpose being a routing controller. This creates an unnecessary secret-access capability and enables unauthorized billing, secret misuse, and hidden outbound API activity if the skill is invoked unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Reading an API key from a local credential file without any user-facing notice is a sensitive behavior that bypasses informed consent. Even if the key is used only for the intended provider, the undisclosed access to local secrets expands the trust boundary and can lead to secret exposure or unapproved spend.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.