Back to skill

Security audit

爱图表 桑基图

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Sankey-chart API integration, but its credential handling can execute injected shell code and its bundled CLI exposes broader actions than the skill’s stated purpose.

Install only if you are comfortable sending chart data to Aitubiao’s API and storing an API key locally. Use a key copied directly from the official Aitubiao console, avoid pasting keys from untrusted messages, remove ~/.aitubiao/credentials when no longer needed, and be cautious with export/download paths until the credential parsing and attachment URL validation are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/aitubiao-cli.sh:64
Finding

Arbitrary Command Execution Through Executable Credential File

Content
View full analysis
&2 echo "Please configure credentials first. See SKILL.md for setup instructions." >&2 exit 1 fi source "$CREDENTIALS_FILE" ``` ```bash cmd_auth() { local api_key="${1:-}" if [[ -z "$api_key" ]]; then echo "Error: API Key required. Usage: aitubiao-cli.sh auth " >&2 echo "Get one at: https://app.aitubiao.com/setting/api-keys?utm_source=skill_skill-clawhub&channel=skill-clawhub" >&2 exit 4 fi if [[ ! "$api_key" =~ ^sk_v1_ ]]; then echo "Error: Invalid API Key format (must start with sk_v1_)" >&2 echo "Get a valid key at: https://app.aitubiao.com/setting/api-keys?utm_source=skill_skill-clawhub&channel=skill-clawhub" >&2 exit 4 fi mkdir -p "$(dirname "$CREDENTIALS_FILE")" cat > "$CREDENTIALS_FILE" << EOF API_KEY=$api_key BASE_URL=https://api.aitubiao.com CHANNEL=skill-clawhub EOF chmod 600 "$CREDENTIALS_FILE" ``` ### Technical Analysis The credential loader executes `~/.aitubiao/credentials` as shell code by using `source`. The `auth` command writes the supplied API key directly into that executable file without shell-safe serialization. Validation only requires the value to begin with `sk_v1_`. It does not validate the complete value or reject shell metacharacters, command substitutions, whitespace, or newline characters. Consequently, attacker-controlled shell syntax can be persisted after the accepted prefix. Although the file is assigned mode `0600`, those permissions only restrict other users from reading or modifying it. They do not prevent malicious content supplied through the `auth` argument from being execu ...[truncated 1289 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/aitubiao-cli.sh:466
Finding

Unrestricted Server-Controlled Attachment URL Fetching

Content
View full analysis
&2 exit 3 fi ``` ```bash local task_result local status local attachment local attempts=0 local max_attempts=300 while (( attempts < max_attempts )); do task_result=$(api_request GET "/api/v1/projects/export/task/${task_id}" 10 "" "true") status=$(echo "$task_result" | jq -r '.status // empty') if [[ "$status" == "success" ]]; then attachment=$(echo "$task_result" | jq -r '.attachment // empty') if [[ -z "$attachment" ]]; then echo "Error: Download attachment missing from task response" >&2 echo "$task_result" >&2 exit 3 fi local actual_path actual_path=$(download_attachment "$attachment" "$output_path" "$format") ``` ### Technical Analysis The export-task response controls the entire attachment URL. The CLI passes that value directly to `curl` and enables redirect following with `-L`. The implementation does not enforce: - An HTTPS-only URL scheme. - An allowlist of authorized export or CDN hostnames. - Rejection of loopback, private, ...[truncated 1826 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a Sankey-chart generator, but its documented behavior includes broader capabilities such as credential management, quota checks, and exporting/downloading projects to the local filesystem. This expands the trust boundary beyond what a user would reasonably infer from the description, increasing the risk of unintended credential handling and local file writes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill is designed to maintain persistent authentication state across sessions, as evidenced by its compatibility assumptions and credential workflow. Session persistence increases risk because a later invocation could reuse previously stored credentials without the user's fresh awareness, especially in a skill triggered by broad phrases.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: 爱图表-桑基图
description: AI桑基图(流向图)生成。用户上传数据或粘贴表格,自动生成流向可视化图表,展示数据在环节间的流动关系。触发词:桑基图、流向图、sankey、流量图、数据流向、关系图、转化路径、用户流转、资金流向、create sankey、flow diagram、sankey chart。
license: MIT
compatibility: Requires network access to api.aitubiao.com, Bash shell, curl, and jq
metadata:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger list includes broad phrases like '关系图', '数据流向', and 'flow diagram', which may match ordinary user requests not intended for this skill. Over-broad invocation can cause accidental activation, leading to unnecessary remote data transmission or credential prompts in contexts where the user did not intend to use this third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill does not prominently warn users that their uploaded data will be sent to a remote API and that API credentials may be stored locally. This lack of transparent disclosure undermines informed consent and can expose sensitive business or personal data to external systems unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to store a user API key in ~/.aitubiao/credentials with cross-session persistence. Persisting third-party credentials locally is broader than necessary for a one-off chart-generation task and raises the risk of later unauthorized reuse, leakage to other processes, or use without renewed user consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script materially exceeds the stated Sankey-only purpose by exposing generic chart creation, PPT generation, 3D illustration creation, quota inspection, and project export. In an agent-skill setting, this violates least privilege and broadens what a caller can make the agent do with the user's API key and local filesystem, increasing the chance of unintended actions or data exfiltration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The ability to create PPT presentations and 3D illustrations is unrelated to a Sankey-diagram skill and gives the agent broader paid-generation powers than advertised. If an attacker can influence prompts or command selection, they can consume credits or create unintended artifacts outside the user's expected scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The download/export command can write arbitrary project exports to local paths, which is a stronger capability than merely generating a Sankey chart. In an agent context, local file-write plus project selection/export can be abused to place unexpected files on disk or exfiltrate accessible project data to the local environment.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/aitubiao-cli.sh (reported line 50)May include surrounding context.

sh
check_jq() {
  if ! command -v jq &>/dev/null; then
    echo "Error: jq is required but not installed." >&2
    echo "Install it with: sudo apt install jq  (or brew install jq on macOS)" >&2
    exit 4
  fi
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/aitubiao-cli.sh (reported line 278)May include surrounding context.

sh
BASE_URL=https://api.aitubiao.com
CHANNEL=skill-clawhub
EOF
  chmod 600 "$CREDENTIALS_FILE"

  echo "Credentials saved to $CREDENTIALS_FILE"
  echo "  API_KEY: ${api_key:0:12}...${api_key: -4}"

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill includes functionality to download/export created projects to local files, which goes beyond simple chart generation. While not inherently malicious, writing files locally increases the attack surface by introducing path-handling risks, accidental overwrites, and data exfiltration concerns if users are not clearly informed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Quota/account inspection is not necessary for basic Sankey generation and exposes extra account metadata to the agent. While lower severity than write/export actions, it still enlarges accessible surface area and may leak billing, balance, or feature-entitlement information without clear user expectation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script unconditionally sets LANG and LC_ALL to C.UTF-8, and on MSYSTEM overwrites any existing locale settings. This is a natural-language locale policy concern because it imposes a specific locale on all users rather than offering a choice or limiting it to a clearly documented opt-in mode.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The documentation claims channel switching is supported via another script, implying configurability, but this file enforces a single expected BASE_URL and writes a fixed CHANNEL during auth. That creates an intent/documentation mismatch about how configurable the client actually is.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.