Back to skill

Security audit

Data Sentinel Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed webpage monitoring tool with expected local state, manual scheduling, and optional Telegram alerts, but users should scope URLs and recurring jobs carefully.

Install only if you are comfortable with a tool that fetches monitored URLs, stores change state locally, can be scheduled through cron, and may send alert details to Telegram when configured. Avoid monitoring private dashboards, account pages, internal hosts, or cloud metadata URLs unless you have network controls and understand what alert text may leave the machine.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/monitor.py:19
Finding

Arbitrary URL Fetching Enables Server-Side Request Forgery

Content
View full analysis

Vulnerability Details

File Location: scripts/monitor.py:19-31, 130-140
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: High

Vulnerable Code

python
def fetch_url_content(url):
    """获取网页内容"""
    headers = {
        'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36'
    }
    try:
        # 启用 SSL 验证确保安全
        response = requests.get(url, headers=headers, timeout=30, verify=True)
        response.raise_for_status()
        return response.text
    except requests.exceptions.SSLError as e:
        return f"ERROR: SSL verification failed - {str(e)}"
    except Exception as e:
        return f"ERROR: {str(e)}"
python
def main():
    """主函数"""
    # 解析命令行参数
    if len(sys.argv) < 2:
        print("使用方法:monitor.py <url> [rule]")
        sys.exit(1)

    url = sys.argv[1]
    rule = sys.argv[2] if len(sys.argv) > 2 else "content"

    # 获取页面内容
    content = fetch_url_content(url)

Technical Analysis

The monitoring URL is taken directly from a command-line argument and passed to requests.get() without validating its scheme, hostname, resolved IP address, or destination network. Python Requests also follows redirects by default, and the code does not validate redirect targets.

Consequently, a user who can create or influence a monitoring task may cause the machine running the Skill to send HTTP requests to destinations accessible from that machine. Potential targets include loopback interfaces, RFC 1918 private networks, link-local services, and cloud instance metadata endpoints.

The use of verify=True only validates HTTPS certificates. It does not prevent SSRF, requests to plain HTTP endpoints, access to internal addresses, or redirection to protected networks.

Although the complete response body is not directly included in notifications, it is parsed, hashed, and compared with previously stored state. Price-like values and change information can be emitted thr ...[truncated 1859 chars]

Remediation
View remediation

Remediation Suggestions

  1. Permit only explicitly supported schemes, normally https and, only if required, http. Reject URLs containing unsupported schemes, embedded credentials, malformed hosts, or ambiguous address representations.
  2. Resolve the hostname before making a request and reject every address classified as loopback, private, link-local, multicast, reserved, unspecified, or otherwise non-global.
  3. Explicitly block cloud metadata destinations, including link-local metadata addresses and provider-specific metadata hostnames.
  4. Disable automatic redirects or validate every redirect destination with the same scheme, hostname, DNS, and IP-address checks before following it.
  5. Mitigate DNS rebinding and time-of-check/time-of-use issues by ensuring that the validated address is the address used for the connection.
  6. Prefer an administrator-managed allowlist of approved domains where the deployment does not require unrestricted Internet monitoring.
  7. Apply outbound firewall or proxy rules so the Skill cannot reach loopback, private networks, link-local ranges, metadata services, or sensitive management networks.
  8. Restrict monitoring-task creation to authorized users and validate URLs again when scheduled tasks execute.
  9. Avoid returning raw network errors to untrusted users, and ensure logs and notifications do not disclose internal addresses or response-derived secrets.
  10. Add tests covering direct private addresses, alternative IP encodings, IPv6 loopback and private ranges, DNS rebinding scenarios, and public-to-private redirects.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (20)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities that imply network access plus local file read/write, but it does not declare any explicit tool scope or permission boundaries. That increases the chance of over-broad runtime access, unintended file modification, or network exfiltration if the skill is invoked in a permissive agent environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation phrases are broad enough that the skill may trigger on generic monitoring-related requests without clear confirmation of scope, target, or side effects. In an agent system, this can lead to unintended monitoring setup, repeated network access, local data retention, or outbound notifications being configured or used without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes collecting webpage content, storing prior values locally, and sending alerts through Telegram or email, but it does not clearly warn users that monitored URLs and extracted content may persist on disk and be transmitted to third parties. This creates a privacy and data-handling risk, especially if users monitor sensitive pages, internal dashboards, or personal account data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The file explicitly instructs users to install recurring cron jobs via crontab, which creates persistence on the host. While this appears to be legitimate for a monitoring skill, persistence is still security-relevant because it causes code to execute repeatedly and can continue running long after the user forgets it was installed.

Content

Scanner excerpt · crontab-example.txt (reported line 4)May include surrounding context.

text
# ═══════════════════════════════════════════════════════════════
# Data Sentinel Pro - 数据监控 Cron 配置
# 说明:将下方配置添加到现有 crontab 中
# 编辑方式:crontab -e
# ═══════════════════════════════════════════════════════════════

# 监控示例 1:商品价格监控(每 30 分钟检查一次)

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

This instruction again directs the user to add entries through crontab -e, reinforcing persistent scheduled execution. In the context of an automation skill this is expected, but it still increases host risk because periodic tasks can consume resources, mask unexpected behavior, or continue operating without ongoing user awareness.

Content

Scanner excerpt · crontab-example.txt (reported line 21)May include surrounding context.

text
# 1. 复制上方需要的行
# 2. 替换 URL 为你的目标网址
# 3. 选择监控规则:price(价格)或 content(内容)
# 4. 运行 crontab -e 粘贴进去
# 5. 保存退出即可生效
# ═══════════════════════════════════════════════════════════════

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's natural-language comments, docstrings, and usage output are written in Chinese, and the user-facing usage/help text is only presented in Chinese. This imposes a specific language choice without opt-in or documented region-specific justification, which matches the stated language/locale policy violation rule.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest emphasizes 24/7 monitoring of webpages, prices, and competitor changes, with change detection as the core function. This code additionally performs active outbound messaging to Telegram, which is a distinct operational capability not reflected in the skill description and goes beyond mere monitoring implementation details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends monitored URL and change details to Telegram without any in-file consent prompt, warning, or minimization. If users monitor private or authenticated pages, sensitive URLs or page-derived information could be disclosed to a third-party service unexpectedly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Hardcoding Telegram as an external notification endpoint establishes a built-in data egress path. In the context of a monitoring tool that may watch confidential pages, this increases the risk of unintended disclosure to a third-party platform.

Content

Scanner excerpt · scripts/monitor.py (reported line 121)May include surrounding context.

python
"""发送通知(TG/邮件)"""
    # Telegram 通知
    if config.get('telegram_token'):
        tg_url = f"https://api.telegram.org/bot{config['telegram_token']}/sendMessage"
        data = {
            'chat_id': config.get('telegram_chat_id'),
            'text': message,

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This POST transmits monitoring alerts to Telegram, which is an external third party. Because the message includes URL and change details and the code lacks explicit consent or data classification safeguards, it can leak sensitive monitoring targets or derived information.

Content

Scanner excerpt · scripts/monitor.py (reported line 128)May include surrounding context.

python
'parse_mode': 'HTML'
        }
        try:
            requests.post(tg_url, json=data, timeout=10)
        except:
            pass

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a webpage/product-change monitoring skill, but these lines read a local config file from the user’s home directory to extract Telegram-related settings. Accessing unrelated local configuration/credentials is not an obvious requirement of simply detecting webpage changes, especially since notification behavior is not declared in the manifest text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Core invocation guidance and examples are primarily written in Chinese, which can effectively force a language/locale expectation for users despite the skill name and some headings being in English. There is no statement that the skill supports multiple languages or that Chinese is a deliberate, documented locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file title and all usage instructions are written in Chinese, and there is no indication that this skill is intentionally limited to Chinese-speaking users or that another language option exists. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description is written entirely in Chinese, which can impose a language expectation on users without offering any language choice or indicating that the skill is region-specific. Under the policy, language or locale constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Using a caret range for requests allows future compatible releases to be installed without explicit review, which increases supply-chain risk and can introduce vulnerable or behavior-changing versions. In an agent skill that continuously monitors websites, dependency compromise could affect a long-running network-enabled component.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"test": "python -m pytest tests/"
  },
  "dependencies": {
    "requests": "^2.31.0",
    "beautifulsoup4": "^4.12.0",
    "lxml": "^5.1.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

beautifulsoup4 is specified with a non-exact version, so installs may resolve to different releases over time, increasing the chance of pulling a vulnerable or malicious package version. Because this skill parses remote webpage content, a compromised parser dependency would sit directly in the data-handling path and could have outsized impact.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
},
  "dependencies": {
    "requests": "^2.31.0",
    "beautifulsoup4": "^4.12.0",
    "lxml": "^5.1.0"
  },
  "devDependencies": {

Unverifiable Dependency: beautifulsoup4 has 1 known advisory(ies) (MAL-2025-3615 (Malicious code in beautifulsoup4 (npm))), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The manifest references beautifulsoup4 without pinning an exact safe version despite a cited advisory for a malicious npm release, so it is impossible to verify whether installations will avoid the affected artifact. This is especially concerning in a web-monitoring skill because the package is central to processing fetched content, making supply-chain compromise more consequential.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

lxml is not pinned exactly, which weakens build reproducibility and exposes the project to accidental adoption of flawed upstream releases. As a parsing library often used on untrusted content, version drift can create avoidable security and stability risk.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"dependencies": {
    "requests": "^2.31.0",
    "beautifulsoup4": "^4.12.0",
    "lxml": "^5.1.0"
  },
  "devDependencies": {
    "pytest": "^8.0.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"lxml": "^5.1.0"
  },
  "devDependencies": {
    "pytest": "^8.0.0"
  },
  "python": ">=3.9",
  "author": "Anson <ai.agent.anson@qq.com>",

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script accesses ~/.openclaw/openclaw.json, which may contain notification tokens and other configuration data, but this access is not disclosed to the user beyond silent exception handling. For code-file warning requirements, access to sensitive configuration or credentials should have some visible explanation, logging, or documented warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.