Back to skill

Security audit

本地文件上传云端

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims in broad terms, but it uploads user-selected files to cloud storage using local credentials and can report failure after a successful upload, leaving public files behind without a returned link.

Review this skill before installing. Use it only for non-sensitive files, confirm your Qiniu bucket access policy and cleanup process, and fix or wait for a fix to the URL-generation bug before relying on success or failure output. Also verify the qiniu package source/version and understand that credentials are read from ~/.openclaw/config.json.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-26
Vulnerability Type: Unpinned package installation and software supply-chain exposure
Risk Level: Medium

Vulnerable Code

markdown
## Prerequisites

This skill requires the `qiniu` Python package to be installed. If it's not present, the skill will fail with an import error.

```sh
pip install qiniu
text

### Technical Analysis

The documented installation command installs the latest package version resolved by the active pip configuration without enforcing an audited version, package hash, or trusted repository. This prevents users from verifying that the installed dependency is the same version reviewed with the skill.

Python packages can execute code during installation and when imported. The script imports the dependency at startup:

```python
from qiniu import Auth, put_file

If the package distribution, configured package index, dependency chain, or a future package release is compromised, attacker-controlled code could execute in the skill's process.

Attack Path

  1. An attacker compromises a future qiniu release, one of its transitive dependencies, or the package source selected by the user's pip configuration.
  2. A user follows the documented pip install qiniu command.
  3. Pip retrieves and installs the unverified package version.
  4. The user invokes the skill.
  5. Python imports the installed package, causing attacker-controlled initialization code to execute with the privileges of the user running the skill.

Impact Assessment

Exploitation could permit arbitrary code execution under the Agent user's account. Depending on that account's privileges, this may expose local files, Qiniu credentials stored in ~/.openclaw/config.json, environment variables, and other resources accessible to the process. It could also permit modification of user-owned files or misuse of the configured cloud-storage account ...[truncated 1 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version rather than installing an unconstrained latest release.

  • Provide a lock file or requirements file containing cryptographic hashes, for example using pip's --require-hashes option.

  • Install packages exclusively from an explicitly configured and trusted package repository.

  • Audit direct and transitive dependencies before updating the pinned version.

  • Use an isolated virtual environment with only the permissions required to upload the selected file.

  • Document a reproducible installation command, such as:

    sh
    python -m pip install --require-hashes -r requirements.txt
    

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_link.py:55
Finding

Successful Upload Is Reported as Failure Due to Missing urllib Import

Content
View full analysis

Vulnerability Details

File Location: scripts/create_link.py, lines 55-60
Vulnerability Type: Incorrect post-upload error handling leading to an untracked public object
Risk Level: Medium

Vulnerable Code

python
if info and info.status_code == 200:
    encoded_key = urllib.parse.quote(key)
    file_url = f"{QINIU_DOMAIN}/{encoded_key}"
    print(f"Upload successful. URL created.", file=sys.stderr)
    return file_url
else:

The module imports at the beginning of the file do not include urllib or urllib.parse:

python
import os
import argparse
import sys
import time
import json
from pathlib import Path
from typing import Optional

Technical Analysis

After put_file successfully uploads the selected file, the script evaluates urllib.parse.quote(key). Because urllib was never imported, this expression raises a NameError.

The broad exception handler catches that error and reports the overall operation as failed:

python
except Exception as e:
    print(f"An unexpected error occurred during Qiniu upload: {e}", file=sys.stderr)
    return None

The caller consequently receives a nonzero exit status and no URL even though the remote object has already been created. This violates the documented failure semantics and can leave a potentially public file in cloud storage without providing the user with its location.

Attack Path

  1. A user supplies an existing local file through --file.
  2. The script authenticates using credentials from ~/.openclaw/config.json.
  3. put_file successfully creates the object in the configured Qiniu bucket.
  4. URL construction reaches the undefined urllib name and raises NameError.
  5. The generic exception handler reports failure and the process exits with status 1.
  6. The user may assume that no upload occurred or retry the operation.
  7. One or more remote objects can remain accessible according ...[truncated 603 chars]
Remediation
View remediation

Remediation Suggestions

  • Import the required function explicitly and use it directly:

    python
    from urllib.parse import quote
    
    python
    encoded_key = quote(key)
    
  • Separate upload exceptions from post-upload URL-construction errors so that a successful remote write is never represented as a failed upload.

  • Validate QINIU_DOMAIN before beginning the upload.

  • If URL generation fails after a successful upload, clearly report that the remote object was created and include its object key.

  • Consider deleting the newly created object when post-upload processing fails, if rollback is supported and consistent with expected behavior.

  • Add an automated test that mocks a successful put_file response and verifies that the script returns a correctly encoded URL.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior understates what the skill does by omitting that it reads local configuration or credentials and by claiming reliable URL output despite a referenced implementation defect. This mismatch can cause users or orchestrators to trust the skill with local files under incomplete assumptions, increasing the risk of unintended credential use, silent failure, or unintended public disclosure of uploaded data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill performs local file access and network exfiltration behavior but does not declare any explicit tool scope or permissions. That omission weakens transparency and policy enforcement, making it easier for a caller or agent to invoke file upload behavior without clear consent boundaries, especially since uploaded content may become publicly accessible.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest says the skill uploads a local file to Qiniu and returns a shareable URL. While authentication is necessary for upload, this implementation additionally assumes and accesses a specific local config file under ~/.openclaw to retrieve secrets and bucket settings, which is a broader local-data access behavior not described by the skill's stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The docstring at L21 is written only in Chinese, while the rest of the script is primarily in English. This creates a language-specific constraint in the skill's natural-language content without offering a user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.