Back to skill

Security audit

Daily Producer

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent daily-news purpose, but it asks for broad credentials, background services, telemetry, and network-facing write access that need review before installation.

Install only after reviewing the Feishu credential flow, disabling or binding the feedback server to localhost with authentication, removing the hard-coded proxy credential, fixing shell command construction, and making telemetry and background services explicit opt-in.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/collect_detail.py:132
Finding

Shell Command Injection Through Untrusted URLs, Keywords, and Command Templates

Content
View full analysis
dict: env = os.environ.copy() env["DISPLAY"] = env.get("DISPLAY", ":99") work_dir = Path(tempfile.gettempdir()) / "dailynew-opencli-web" / hashlib.md5(url.encode("utf-8")).hexdigest() if work_dir.exists(): shutil.rmtree(work_dir, ignore_errors=True) work_dir.mkdir(parents=True, exist_ok=True) cmd = f'opencli web read --url "{url}" --format md --output "{work_dir}"' try: result = subprocess.run( cmd, shell=True, capture_output=True, text=True, timeout=timeout, env=env ) ``` ```python # scripts/collect_sources_with_opencli.py def run_opencli(cmd: str, timeout: int = 30, platform: str = "") -> dict: full_cmd = f"opencli {cmd}" env = os.environ.copy() env["DISPLAY"] = env.get("DISPLAY", ":99") try: result = subprocess.run( full_cmd, shell=True, capture_output=True, text=True, timeout=timeout, env=env ) ``` ```python # scripts/collect_sources_with_opencli.py for cmd_template in commands: if "{keyword}" in cmd_template: for kw in keywords: cmd = f'{opencli_prefix} {cmd_template.replace("{keyword}", kw)} -f json' print(f" [{name}] {cmd}", file=sys.stderr) res = run_opencli(cmd, platform=opencli_prefix) else: cmd = f"{opencli_prefix} {cmd_template} -f json" print(f" [{name}] {cmd}", file=sys.stderr) res = run_opencli(cmd, platform=opencli_prefix) ``` ### Technical Analysis The scripts concatenate untrusted values into shell command strings and execute those strings with `shell=True`. In `collect_detail.py`, the `url` value is parsed fr ...[truncated 2323 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/feedback_server.py:332
Finding

Unauthenticated Network-Exposed Arbitrary File Writes Through Path Traversal

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/render_daily.py:925
Finding

Automatic Collection and Transmission of Sensitive Reader Interaction Data

Content
View full analysis
({ tool: u.tool, prompt_preview: u.prompt })) }, interest_profile: { tag_scores: tagRanking, top_interests: tagRanking.slice(0, 5).map(t => t.tag) }, all_events: events }; ``` ```javascript function onLeave() { if (leaveHandled) return; leaveHandled = true; const summary = buildSummary(); if (IS_HTTP) navigator.sendBeacon('/api/feedback', JSON.stringify(summary)); try { const st = JSON.parse(localStorage.getItem('daily_feedback') || '[]'); st.push(summary); if (st.length > 30) st.splice(0, st.length - 30); localStorage.setItem('daily_feedback', JSON.stringify(st)); } catch(e) {} } ``` ### Technical Analysis Generated report pages automatically record detailed user behavior, including: - Time spent viewing individual articles. - Source links clicked. - Article tex ...[truncated 2092 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/collect_sources_with_opencli.py:27
Finding

Hard-Coded Proxy Credentials and Forced Use of a Fixed External Proxy

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
init/daily-init.md:84
Finding

Unpinned Third-Party Package Installation During Initialization

Content
View full analysis
/dev/null || pip install pyyaml ``` ```text - If not installed, execute: npm install -g @jackwener/opencli ``` ```text Additional installation required: pip install graphifyy - If the user selects Y: set graphify.enabled to true, ask for the data directory, and execute pip install graphifyy. ``` ```bash # SKILL.md pip install graphifyy graphify ~/graphify-data --watch & ``` ### Technical Analysis The initialization workflow instructs the Agent to install the latest registry versions of multiple third-party packages without version constraints, hashes, lock files, or an isolated environment. `npm install -g` modifies the global Node.js environment and may execute package lifecycle scripts with the Agent's privileges. Python packages may also execute installation or build logic. Because no version is pinned, the code installed during one audit may differ from the code installed during later Skill execution. The Graphify installation is optional and user-confirmed, but the supply-chain risk remains. The PyYAML fallback command and global OpenCLI installation may occur as part of normal initialization. ### Attack Path 1. Initialization checks whether a dependency is present. 2. If it is missing, the Agent invokes `pip` or `npm` against the public package registry. 3. The registry supplies the mutable latest release and any transitive dependencies. 4. A compromised maintainer account, malicious release, dependency-confusion event, or unexpected update introduces hostile installation or runtime code. 5. The package code executes with the privileges of the user running initialization. 6. A globally installed package may affect other applicati ...[truncated 482 chars]
Remediation
View remediation
--hash=sha256: graphifyy== --hash=sha256: ``` 3. For Node.js, use a project-local installation with a committed lock file rather than `npm install -g`. 4. Install with lock enforcement, such as `npm ci`, after reviewing the dependency tree. 5. Disable unnecessary lifecycle scripts where compatible with the package. 6. Require explicit user confirmation before every environment-changing installation. 7. Verify package provenance, maintainer identity, signatures or attestations where available, and expected checksums. 8. Run third-party collection tools inside a constrained environment with minimal access to credentials and user files. 9. Document exact supported versions and establish a controlled update-review process. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (118)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch involves reading local credentials/configuration and sending authenticated messages to Feishu using report-derived content. Outbound notification and credential use are materially sensitive behaviors; if not prominently disclosed and permissioned, they can lead to unintended data exfiltration or misuse of messaging integrations.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
2. **不存在** → 读取并执行 `init/daily-init.md` 初始化流程(参考 `reference/profile_template.yaml` 模板)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
python3 scripts/build_queries.py --date {date} --window 3

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
python3 scripts/build_queries.py --date {date} --window 3

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
→ 详见 `reference/pipeline/01_build_queries.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
→ 详见 `reference/pipeline/02_collect_sources.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
- `reference/daily_payload_example.json` — 结构示例

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
python3 scripts/render_daily.py output/daily/{date}.json --output output/daily/{date}.html --force

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 233)May include surrounding context.

md
python3 scripts/render_daily.py output/daily/{date}.json --output output/daily/{date}.html --force

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The initialization skill goes beyond profile generation and instructs the agent to enumerate Feishu accounts, test credentials, and send live messages to a chat. That expands scope from local configuration into active use of secrets and external side effects, which can expose account reachability, leak organizational metadata, and trigger unauthorized notifications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly reads ~/.openclaw/openclaw.json, extracts appId/appSecret values, and uses them to obtain tenant tokens and call Feishu APIs. Accessing and operationalizing local secrets is disproportionate to the stated purpose of initializing a news profile, and creates a direct path for secret misuse or unauthorized API actions.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · program.md (reported line 416)May include surrounding context.

体: bbc, bloomberg, reuters, 36kr, ... ├── 学术: arxiv, ... ├── 搜索: google search/news/trends └── 通用: web read (任意 URL → Markdown)

text

### 连接检查

```bash
opencli doctor
# [OK] Daemon: running on port 19825
# [OK] Extension: connected (v1.5.5)
# [OK] Connectivity: connected

保活机制

/root/opencli-keepalive.sh 通过 crontab 每分钟检查,Xvfb/Chrome/x11vnc/websockify/daemon 任一挂掉自动重启。

平台目录

reference/opencli_platforms.yaml 列出了全部 31 个可用平台(12 国内 + 17 国外 + 2 通用),每个含 id、名称、描述、分类、登录要求、命令模板。

各平台输出字段

reference/opencli_output_formats.md 记录了每个平台每个命令的 JSON 输出字段、时间字段名和格式。在 2026-04-05 全量采集中实测验证过。


五、文件索引

核心配置

文件用途
config/profile.yaml

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · reference/daily_example.html (reported line 117)May include surrounding context.

html
<div class="flex-1 flex overflow-hidden max-w-[1600px] mx-auto w-full">

    <!-- ======== 左栏 ======== -->
    <aside class="w-[420px] flex-shrink-0 border-r border-gray-100 bg-white overflow-y-auto sidebar-scroll">
      <div class="p-5 space-y-5">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · reference/daily_example.html (reported line 279)May include surrounding context.

html
</div>
        </article>

        <!-- 3 -->
        <article class="bg-white rounded-xl shadow-sm p-4 card-hover">
          <div class="flex items-start justify-between">
            <h3 class="text-[15px] font-semibold text-primary leading-snug"><i class="fa-solid fa-fire text-red-500 mr-1.5 text-xs"></i>DeepSeek-V3.2 发布,推理能力追平 Gemini-3.0-Pro</h3>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · reference/daily_example.html (reported line 319)May include surrounding context.

html
</div>
        </article>

        <!-- 5 -->
        <article class="bg-white rounded-xl shadow-sm p-4 card-hover">
          <div class="flex items-start justify-between">
            <h3 class="text-[15px] font-semibold text-primary leading-snug"><i class="fa-solid fa-thumbtack text-amber-500 mr-1.5 text-xs"></i>Kimi K2.5 发布:万亿参数 + Agent Swarm 百 Agent 并行</h3>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · reference/daily_example.html (reported line 357)May include surrounding context.

html
</div>
        </article>

        <!-- 7 -->
        <article class="bg-white rounded-xl shadow-sm p-4 card-hover">
          <div class="flex items-start justify-between">
            <h3 class="text-[15px] font-semibold text-primary leading-snug"><i class="fa-solid fa-thumbtack text-amber-500 mr-1.5 text-xs"></i>AI 生成代码 14.3% 含安全漏洞,FTC 要求企业承担全部责任</h3>

Static analysis

No suspicious patterns detected.