Back to skill

Security audit

Baidu Text Translate

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Baidu translation helper, but users should understand it installs an external npm CLI and sends translated text to Baidu's service.

Install only if you are comfortable using Baidu's translation API and the external `@bdtrans/trans-cli` npm package. Avoid translating secrets, credentials, private documents, or regulated data unless you have confirmed that sending that text to Baidu is acceptable. Prefer `TRANS_API_KEY` or carefully managed config storage for the API key, and review the npm package/version before installation in sensitive environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned and Unverified npm Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Third-party software supply-chain risk
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: {"clawdbot":{"emoji":"🌐","requires":{"bins":["trans"],"env":["TRANS_API_KEY"]},"install":[{"id":"npm","kind":"npm","package":"@bdtrans/trans-cli","bins":["trans"],"label":"Install trans-cli (npm)"}]}}

Technical Analysis

The skill declares automatic installation of the external npm package @bdtrans/trans-cli without specifying an exact audited version, lockfile, registry restriction, or integrity hash. Consequently, future installations may resolve to package contents that differ from those present when the skill was reviewed.

The external package's implementation is not included in this project, so its installation scripts and runtime behavior could not be examined. The declared executable handles translation text and requires access to TRANS_API_KEY. If the npm package, its publisher account, or its dependency chain were compromised, malicious lifecycle or runtime code could execute in the installing user's environment.

This is a supply-chain exposure rather than proof that the named package is currently malicious. Exploitation depends on compromise, replacement, or unsafe resolution of the external dependency.

Attack Path

  1. An attacker compromises the npm publisher account, package, dependency chain, or relevant package-resolution infrastructure.
  2. The attacker publishes a malicious package version or causes installation to resolve to attacker-controlled content.
  3. The skill installer processes the unversioned @bdtrans/trans-cli declaration and retrieves the affected version.
  4. Malicious code executes through an npm lifecycle script or when the trans binary is invoked.
  5. The code accesses data available to the process, potentially including TRANS_API_KEY, submitted translation text, configuration fi ...[truncated 693 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @bdtrans/trans-cli to a specific, reviewed version rather than allowing mutable package resolution.
  2. Maintain and verify a lockfile containing registry-resolved integrity hashes.
  3. Restrict installation to the authoritative npm registry and document the trusted package publisher and source repository.
  4. Review the package, its transitive dependencies, and its npm lifecycle scripts before approving upgrades.
  5. Disable npm lifecycle scripts during installation where the package does not require them, and execute the CLI in a least-privileged environment.
  6. Provide only the required API credential to the translation process and avoid exposing unrelated secrets through its environment.
  7. Consider vendoring or otherwise reproducibly packaging the reviewed executable so that installed code matches the audited artifact.
  8. Establish dependency monitoring and a controlled update process for publisher compromise, malicious releases, and newly disclosed vulnerabilities.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

bash
trans config init               # create empty config skeleton (~/.trans-cli/config.json)
trans config init --force       # overwrite existing config
trans config set api_key <KEY>  # write api_key (creates file if absent)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is extremely broad, including generic situations like any shell pipeline with translation, trans-cli errors, API key configuration, and language-code lookups. This can cause the skill to activate in contexts where the user did not intend to use an external translation service, increasing the chance of unnecessary data exposure or accidental operational changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explains how to send text to the Baidu Translation API but does not prominently warn that user-provided content is transmitted to a third-party external service. In a translation skill, this context makes the omission more dangerous because users may supply sensitive text, credentials, internal documents, or regulated data without realizing it leaves the local environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

Config file field: api_key.

bash
trans config init               # create empty config skeleton (~/.trans-cli/config.json)
trans config init --force       # overwrite existing config
trans config set api_key <KEY>  # write api_key (creates file if absent)

Static analysis

No suspicious patterns detected.