T09 · Insecure Skill Coding Practices
- Location
index.json:44- Finding
Bundled API Key and Request-Signing Secret
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate local Markdown search purpose, but the published package includes private indexed data and credentials and may install an unverified executable during setup.
Review before installing. Do not install this release as-is unless the bundled index is removed, exposed credentials are rotated, and setup no longer downloads or installs ripgrep without explicit consent and integrity verification. If used, configure a narrow knowledge_path and keep secrets out of Markdown notes because search results can inject note content into conversations.
index.json:44Bundled API Key and Request-Signing Secret
index.json:3Distribution of a Private User Knowledge Index and Absolute Filesystem Metadata
scripts/knowledge_base.py:31Unverified Remote Executable Download and Unsafe Archive Extraction
clawhub.json:103Runtime Network and Executable-Write Behavior Exceeds Declared Permissions
The manifest permissions only declare Markdown reads and index-file writes, but the documented init behavior includes installing ripgrep, which can modify the system outside the declared permission scope. This mismatch undermines transparency and any permission-based trust model, because users and tooling may approve the skill expecting limited file access while the actual behavior performs broader system changes.
The index exposes a live third-party Web service API key and associated private signing secret inside searchable knowledge content. Anyone with access to this skill or index can extract and abuse those credentials for unauthorized API usage, quota exhaustion, billing/availability impact, and possible impersonation of legitimate requests.
The script contains built-in remote software download and installation logic for a knowledge-base CLI, which expands the trust boundary from local indexing to arbitrary network retrieval and code placement. Because the downloaded artifact is installed without strong integrity verification such as signature or pinned checksum validation, compromise of the release channel, transport, or implementation errors could lead to execution of untrusted code.
The trigger phrase "查看知识库" is broad and can plausibly match ordinary user requests to view or discuss the knowledge base rather than explicitly request the stats action. That can cause unintended action execution, which is a real security and safety issue because the skill is designed to react to natural-language triggers and may disclose repository metadata or alter agent behavior unexpectedly.
The install flow includes shell execution and writes an index/config file, while the changelog indicates init may also install ripgrep, yet the user-facing installation section does not prominently warn about these system and data changes. Lack of explicit disclosure increases the chance of uninformed execution, especially for users who expect a passive knowledge-base integration rather than commands that alter the environment.
The changelog states that the init flow auto-detects and installs ripgrep across platforms, which expands the skill's behavior beyond indexing local Markdown files into system modification and package management. Auto-installing software through a shell-driven initialization step can surprise users, introduce supply-chain risk, and execute privileged or platform-specific install logic not clearly constrained by the manifest.
Suspicious Unicode normalization or mixed-script content
This JSON index embeds many document summaries and titles that explicitly constrain content language, such as repeated '语言: 英文', '语言: 荷兰语', and China-specific locale framing like '北京时间' and '依据中国气象局...编写'. Because the file is a manifest-style metadata index consumed by other systems, these natural-language declarations can enforce language or locale behavior without presenting any opt-in or alternative choice to the user.
The documented search triggers include very broad natural-language phrases such as 'In the knowledge' and similar variants. In an agent setting, overly permissive trigger matching can cause unintended search execution during ordinary conversation, which may expose local knowledge snippets and alter model behavior without clear user intent.
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/
# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/
# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/
# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/
# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats
The documentation explicitly describes autonomous execution: file changes can trigger index updates, and matching a trigger word can execute search and inject context automatically. Autonomous actions over local content increase the risk of unintended processing and disclosure, especially when coupled with broad trigger matching.
**Auto-Trigger Conditions:**
| Trigger Type | Condition | Auto Execute |
|--------------|-----------|-------------|
| `auto_refresh` | Config enabled + file change detected | Incrementally update index |
| Search request | Message contains trigger word | Execute search and inject context |
The auto-trigger rule states that any message containing a trigger word may execute search and inject context. This creates an intent-confusion issue where incidental wording can cause retrieval of local files and context insertion, potentially leaking sensitive content from the user's knowledge base into the conversation.
The example workflow encourages the AI to save new conversation-derived content into the persistent knowledge base and link it with existing content. Persistent memory writes can turn prompt-injected or incorrect content into durable context that affects future sessions, creating a cross-session poisoning risk.
Example:
User: AI, I just learned about MOPD (Multi-Teacher On-Policy Distillation) from this paper.
AI: Should I save this to your knowledge base?
User: Yes, save under "AI学习/模型训练" with tags: [AI, 蒸馏, MOPD]
AI: ✅ Saved! Want me to connect it with existing knowledge about model training?
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Step 1: Create or edit config file
nano ~/.openclaw/skills/markdown-knowledge/config.json
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Confirm knowledge_path points to correct directory
Step 3: Check file permissions
chmod 755 ~/.openclaw/skills/markdown-knowledge/
Step 4: Rebuild
python3 knowledge_base.py build
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Confirm knowledge_path points to correct directory
Step 3: Check file permissions
chmod 755 ~/.openclaw/skills/markdown-knowledge/
Step 4: Rebuild
python3 knowledge_base.py build
The Chinese trigger phrases are similarly broad and likely to overlap with normal speech. In multilingual deployments this raises the chance of accidental invocation, causing unintended searches over local content and expanding exposure of stored knowledge.
The Chinese auto-trigger rule allows any message containing trigger words to execute search. This is a real security design issue because it increases the probability of unintended retrieval and context injection from local documents, especially when users discuss the knowledge base descriptively rather than issuing a command.
The skill documentation, trigger phrases, example queries, and user-facing guidance are written entirely in Chinese, including the prescribed invocation commands and AI response wording. This effectively imposes a language/locale requirement without opt-in or justification, which matches the language/locale policy violation criteria.
The helper is presented as a check for ripgrep, but it actually downloads an archive from the internet, extracts it, and writes a binary into the user's local bin directory. That mismatch is security-relevant because users and calling agents may invoke initialization expecting a harmless dependency check while instead causing a system modification and network fetch.
The code modifies the user's environment by downloading and installing ripgrep into ~/.local/bin without any interactive confirmation or prior warning. In an agent-executed context, silent system modification is particularly risky because the action may occur non-interactively and bypass the user's expectation of read-only or low-impact behavior.
Initialization writes a configuration file and immediately builds an index over a user-supplied or guessed directory, which processes potentially large amounts of local data without an explicit warning or confirmation step. In a skill or agent setting, automatically scanning user directories can expose sensitive file metadata and contents to later components and is more dangerous than in a standalone local CLI because the action may be triggered indirectly.
No suspicious patterns detected.