Back to skill

Security audit

闲鱼数据抓取

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated Xianyu scraping purpose, but it uses unsafe installation, self-update, persistence, credential, and upload behavior that should be reviewed before use.

Review this skill carefully before installing. Avoid the curl | bash flow and sudo, disable or remove cron and self-update unless you can verify the code source, keep any Gitee token and Xianyu cookie narrowly scoped, use a private upload destination, and inspect exactly which screenshots and data files will be pushed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (9)

T03 · Remote Payload Retrieval and Execution

Error
Location
INSTALL.md:5
Finding

Unverified Remote Installer Is Piped Directly into Bash

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
update.sh:24
Finding

Self-Updater Replaces Executable Skill Files with an Unverified Remote Archive

Content
View full analysis
/dev/null | jq -r '.version' || echo "0.0.0") DOWNLOAD_URL="https://gitee.com/$GITEE_OWNER/$GITEE_REPO/archive/main.zip" if command -v curl &> /dev/null; then curl -sL "$DOWNLOAD_URL" -o "$TEMP_DIR/update.zip" elif command -v wget &> /dev/null; then wget -q "$DOWNLOAD_URL" -O "$TEMP_DIR/update.zip" fi unzip -q "$TEMP_DIR/update.zip" -d "$TEMP_DIR" UPDATE_DIR="$TEMP_DIR/xianyu-data-grabber-main" rm -rf "$SCRIPT_DIR"/* cp -r "$UPDATE_DIR"/* "$SCRIPT_DIR/" chmod +x "$SCRIPT_DIR"/*.sh "$SCRIPT_DIR"/*.py 2>/dev/null || true ``` ### Technical Analysis The updater derives the publisher account from an editable local configuration, downloads the mutable `main` branch, and validates only that the ZIP file exists and is nonempty. It does not verify a signature, trusted digest, immutable commit identifier, or expected file manifest. After extraction, it deletes the current skill files, copies the remote archive into the executable skill directory, and marks downloaded shell and Python files executable. The dispatcher exposes this behavior through both `check-update` and `self-update`, even though the former name suggests a non-modifying operation. Because cron jobs can later invoke files from this directory, replacement code can also gain automatic future execution. ### Attack Path 1. An attacker compromises the configured Gitee account, convinces a user to configure an attacker-controlled owner, or modifi ...[truncated 885 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
install.sh:109
Finding

Installer Automatically Adds Persistent Recurring Cron Jobs

Content
View full analysis
"$CRON_FILE" << 'EOF' # Xianyu data-grabbing scheduled tasks 0 9 * * * cd ~/.openclaw/workspace && ./skills/xianyu-data-grabber/run.sh grab "Magisk" "KernelSU" "救砖" "刷机" >> logs/xianyu-cron.log 2>&1 0 10 * * 1 cd ~/.openclaw/workspace && ./skills/xianyu-data-grabber/run.sh grab-all >> logs/xianyu-cron.log 2>&1 0 15 * * * cd ~/.openclaw/workspace && python3 skills/xianyu-data-grabber/visualize.py >> logs/xianyu-visualize.log 2>&1 0 20 * * * cd ~/.openclaw/workspace && python3 skills/xianyu-data-grabber/recommend.py >> logs/xianyu-recommend.log 2>&1 0 2 * * * cd ~/.openclaw/workspace && ./skills/xianyu-data-grabber/run.sh clean >> logs/xianyu-clean.log 2>&1 EOF if command -v crontab &> /dev/null; then (crontab -l 2>/dev/null || true; cat "$CRON_FILE") | crontab - echo "Scheduled tasks have been installed into the system crontab" fi ``` ### Technical Analysis The general installer modifies the user's crontab automatically without a separate opt-in confirmation. Five jobs survive the installation session and execute skill code on daily or weekly schedules. Persistent scheduling is not required for the skill's core on-demand scraping and OCR functions. It therefore exceeds the minimum privileges and lifecycle needed to satisfy an ordinary scraping request. Re-running the installer also appends duplicate entries because it does not check for existing managed jobs. The separate `cron-setup.sh` is less severe because it writes a proposed schedule and prints manual installation instructions. The unsafe behavior is the automatic installation performed by `install.sh`. ### Attack Path 1. A user installs the skill to perform an on-demand data collection task. 2. The installer appends recurring jobs without obtaining separa ...[truncated 712 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
grabber.js:99
Finding

User-Controlled Keywords Reach Shell Commands through Screenshot Filenames

Content
View full analysis
0 && !args.includes('--config')) { keywords = args.filter(a => !a.startsWith('--')); } const keyword = keywords[i]; const screenshotPath = path.join( screenshotDir, `xianyu-${keyword}.png` ); await page.screenshot({ path: screenshotPath, fullPage: true }); const output = execSync( `python3 ${pythonScript} "${item.screenshot}"`, { encoding: 'utf8', maxBuffer: 10 * 1024 * 1024 } ); ``` The enhanced variant uses the same unsafe shell API: ```javascript const screenshotPath = path.join( screenshotDir, `xianyu-${keyword.replace(/[/\\:*?"<>|]/g, '_')}.png` ); const output = execSync( `python3 ${pythonScript} "${item.screenshot}" 2>/dev/null`, { encoding: 'utf8', maxBuffer: 50 * 1024 * 1024, timeout: 60000 } ); ``` ### Technical Analysis Command-line keywords are attacker-influenced and become filesystem paths. Those paths are interpolated into command strings passed to `execSync`, which invokes a shell. Double quotes do not suppress command substitution. In the enhanced variant, the filename filter removes several filesystem characters but does not remove dollar signs, parentheses, or backticks. Consequently, payloads using `$(command)` or backtick substitution can remain inside the double-quoted shell argument and execute. The basic variant performs no filename sanitization at all. Sanitizing shell metacharacters is not a reliable repair because the data should never pass through a shell in the first place. ### Attack Path 1. An attacker causes the Agent to run the scraper with a crafted keyword containing shell substitution syntax. 2. The scraper incorporates the keyword into a screenshot filename. 3. The screenshot path is retained in `allResults`. 4. During OCR, the path is interpolated into an `execSync` command string. 5 ...[truncated 569 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
uploader.sh:64
Finding

Gitee Access Token Is Exposed in Git Process Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
install.sh:79
Finding

Credential Configuration Is Created without the Documented Restrictive Permissions

Content
View full analysis
"$WORKSPACE_DIR/.xianyu-grabber-config.json" << 'EOF' { "gitee": { "token": "", "owner": "", "repo": "xianyu-data" }, "xianyu": { "cookie": "" }, "grabber": { "keywords": ["Magisk", "KernelSU", "救砖", "刷机"], "screenshotDir": "legion/screenshots", "dataDir": "legion/data", "uploadToGitee": false, "ocrLanguage": "chi_sim+eng" } } EOF chmod +x "$SKILL_DIR"/*.sh "$SKILL_DIR"/*.py 2>/dev/null || true ``` `SKILL.md` claims: ```markdown - Cookie: stored in the configuration file with permission 600 - Gitee Token: stored in the configuration file with permission 600 ``` ### Technical Analysis The installer creates a file intended to hold a personal access token and an authenticated marketplace cookie, but it never applies mode `0600`. Actual permissions therefore depend on the caller's current `umask`. The only permission-setting operation makes program files executable. It does not protect the credential file. This contradicts the security guarantees stated in `SKILL.md`. The installation guide further suggests `chmod -R 755 ~/.openclaw/workspace`, which could make sensitive workspace files readable by other local users. ### Attack Path 1. The installer creates `.xianyu-grabber-config.json` under a permissive `umask`, or the user follows the recommendation to make the workspace mode `755`. 2. The user later adds a Gitee token and authenticated Xianyu cookie. 3. Another local user or process reads the configuration file. 4. The attacker reuses the token to access Gitee or reuses the cookie to impersonate the marketplace session. ### Impact Assessment Exposure can compromise the user's Gitee repositories and authenticated Xianyu session. The exact scope depends on token scopes, cookie validity, parent-directory permissions, and ...[truncated 39 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
visualize.py:107
Finding

Generated HTML Reports Embed Unescaped Attacker-Controlled Values

Content
View full analysis
{i}{keyword}" f"{count}{heat}\n" ) ``` ```python for item in data: cat = item.get('category', 'Other') count = item.get('count', len(item.get('products', []))) categories[cat] = categories.get(cat, 0) + count for cat, count in sorted_cats: percent = count / total * 100 if total > 0 else 0 width = max(percent * 3, 1) html += ( f"{cat}{count}{percent:.1f}%" f"
\n" ) ``` ```python for i, item in enumerate(sorted_data[:20], 1): keyword = item['keyword'] count = item.get('count', len(item.get('products', []))) rec = "Blue ocean" if count < 8 else ( "Normal" if count < 15 else "Red ocean" ) highlight = 'class="highlight"' if i <= 5 else '' html += ( f"{i}{keyword}" f"{count}{rec}\n" ) ``` The same pattern appears in `recommend.py:168-170, 201`, where recommendation keywords are inserted directly into HTML headings and table cells. ### Technical Analysis Keywords can originate from command-line arguments, and report data can be supplied through JSON files. The report generators insert those values directly into HTML without contextual encoding. An input such as an HTML element with an event handler can break out of the intended table cell or heading and create active content. When a victim opens the generated report, the b ...[truncated 1153 chars]
Remediation
View remediation
`, quotes, event-handler markup, and script elements. ]]>

T08 · Insecure Dependencies

Warning
Location
install.sh:42
Finding

Installer Uses Unpinned Dependencies and Bypasses Python Environment Protections

Content
View full analysis
/dev/null; then apt-get update -qq apt-get install -y -qq \ tesseract-ocr \ tesseract-ocr-chi-sim \ libtesseract-dev elif command -v yum &> /dev/null; then yum install -y tesseract tesseract-langpack-chi_sim fi pip3 install \ pillow \ pytesseract \ opencv-python-headless \ --break-system-packages \ -q cd "$WORKSPACE_DIR" npm install playwright --save -q npx playwright install chromium --quiet ``` ### Technical Analysis The installer retrieves current package versions from operating-system, Python, npm, and Playwright distribution channels without version pins, lockfiles, package hashes, or a project-specific isolated environment. `--break-system-packages` explicitly bypasses Python's protection against modifying an externally managed system installation. Running unpinned `npm install` in the shared workspace can also alter unrelated workspace dependency resolution and execute package lifecycle scripts. No evidence of a specific malicious package or typosquatted dependency was found. The risk is the unsafe supply-chain and environment-management design. ### Attack Path 1. A registry, mirror, package publisher account, or dependency release is compromised. 2. The installer resolves an unpinned affected version. 3. Package installation downloads and installs that version. 4. Installation hooks or imported package code execute under the installer's privileges. 5. The compromised component gains access to the workspace and any available user credentials. ### Impact Assessment A malicious package or browser artifact can execute code with the privileges of the installer. Even without an active compromise, incompatible dependency updates can break system Python, affect other applic ...[truncated 75 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
uploader.sh:34
Finding

Uploader Broadly Collects Data and Screenshots and Force-Pushes Them despite Conflicting Privacy Claims

Content
View full analysis
/dev/null || true cp "$DATA_DIR"/../screenshots/*.png screenshots/ 2>/dev/null || true cp "$REPORT_FILE" reports/ 2>/dev/null || true git add -A git commit -m "auto: update Xianyu data $(date '+%Y-%m-%d %H:%M')" || \ echo "No changes" git push -f \ "https://$GITEE_TOKEN@gitee.com/$GITEE_OWNER/$GITEE_REPO.git" \ main || \ git push -f \ "https://$GITEE_TOKEN@gitee.com/$GITEE_OWNER/$GITEE_REPO.git" \ master || \ echo "Push failed; check whether the repository exists" ``` `SKILL.md` states that data files are stored locally and are not uploaded to third parties, while other parts of the same document advertise automatic Gitee upload. ### Technical Analysis The upload operation copies every matching JSON file and every PNG screenshot from broad workspace directories rather than selecting only the output associated with the current request. It then stages all files and force-pushes the repository. Screenshots may contain account-specific page content loaded with the configured Xianyu cookie. The conflicting privacy statements prevent users from accurately understanding whether their data leaves the host. If the optional upload cron configuration is installed, this disclosure can occur unattended. Force-pushing also discards or rewrites remote history and is unnecessary for ordinary report publication. ### Attack Path 1. The user configures Gitee credentials and enables or invokes upload. 2. The scraper captures pages, potentially while authenticated with the user's Xianyu cookie. 3. Unrelated or older JSON and PNG files remain in the broad data and screenshot directories. 4. `uploader.sh` copies all matching files into a temporary repository. 5. `git add -A` stages the c ...[truncated 574 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (109)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The install instructions explicitly tell users to pipe a remote script from GitHub directly into bash, which executes unreviewed code immediately with no integrity check or review step. In the context of a skill that installs dependencies, modifies configuration, and sets scheduled tasks, this materially increases the risk of arbitrary code execution and full host compromise if the remote content is tampered with or the repository is malicious.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash chain removes any opportunity for the user or platform to inspect the downloaded script before execution, turning a remote fetch into immediate arbitrary command execution. In this skill's context—where installation can add cron jobs, install packages, and modify local files—this pattern is especially dangerous because it can establish persistence and system-level changes in one step.

Content

Scanner excerpt · INSTALL.md (reported line 8)May include surrounding context.

复制以下命令,发送给 OpenClaw 执行:

bash
curl -sL https://raw.githubusercontent.com/your-username/xianyu-data-grabber/main/install.sh | bash

或者本地安装:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 149)May include surrounding context.

bash
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber

# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 158)May include surrounding context.

bash
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber

# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 159)May include surrounding context.

bash
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber

# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 149)May include surrounding context.

bash
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber

# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 152)May include surrounding context.

md
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber

# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json

# 删除定时任务
crontab -l | grep -v xianyu | crontab -

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 158)May include surrounding context.

crontab -l | grep -v xianyu | crontab -

删除数据(可选)

rm -rf ~/.openclaw/workspace/legion/data/xianyu-* rm -rf ~/.openclaw/workspace/legion/screenshots/xianyu-*

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 159)May include surrounding context.

删除数据(可选)

rm -rf ~/.openclaw/workspace/legion/data/xianyu-* rm -rf ~/.openclaw/workspace/legion/screenshots/xianyu-*

text

---

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · run.sh (reported line 36)May include surrounding context.

sh
echo "  recommend           生成智能推荐(选品/定价/利润)"
    echo "  cron                配置定时任务"
    echo "  check-update        检查新版本"
    echo "  self-update         自动更新到最新版本"
    echo "  clean               清理临时文件"
    echo "  status              显示当前状态"
    echo "  help                显示帮助"

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · run.sh (reported line 196)May include surrounding context.

sh
echo "  recommend           生成智能推荐(选品/定价/利润)"
    echo "  cron                配置定时任务"
    echo "  check-update        检查新版本"
    echo "  self-update         自动更新到最新版本"
    echo "  clean               清理临时文件"
    echo "  status              显示当前状态"
    echo "  help                显示帮助"

Self-Modification

High
Category
Rogue Agent
Confidence
99% confidence
Finding

The do_self_update() function is a true self-modification primitive because it launches an update script that can alter the local installation. In the context of a scraping skill that already interfaces with external content and uploads data, adding silent self-modification materially increases supply-chain and arbitrary code execution risk.

Content

Scanner excerpt · run.sh (reported line 137)May include surrounding context.

sh
}

# 自动更新
do_self_update() {
    echo "🔄 自动更新..."
    bash "$SCRIPT_DIR/update.sh"
}

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · run.sh (reported line 197)May include surrounding context.

sh
do_check_update
        ;;
    self-update)
        do_self_update
        ;;
    clean)
        do_clean

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The updater deletes the current skill directory contents and copies in newly downloaded files without any confirmation, integrity validation, or safety interlock. If the download is malicious, corrupt, or incomplete, this can destroy the installed skill and replace it with attacker-controlled code or leave the environment broken.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The command rm -rf "$SCRIPT_DIR"/* performs destructive deletion based on a computed path and executes before any robust validation or atomic replacement. Even with quoting, logic errors, unexpected path resolution, partial updates, or manipulated runtime context can cause irreversible data loss or enable destructive behavior beyond the intended update flow.

Content

Scanner excerpt · update.sh (reported line 118)May include surrounding context.

sh
# 覆盖安装
echo "🔄 安装新版本..."
rm -rf "$SCRIPT_DIR"/*
cp -r "$UPDATE_DIR"/* "$SCRIPT_DIR/"
echo "✅ 安装完成"
echo ""

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script force-pushes collected files to a remote Gitee repository using an embedded token in the push URL, without an interactive warning or approval step. This is dangerous because it transmits local data off-host and can overwrite remote history, so misuse, misconfiguration, or adversarial modification of input paths could cause unintended disclosure and destructive repository changes.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
grabber-enhanced.js:196

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
grabber.js:163

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL.md:149