Back to skill

Security audit

Auto Push System Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is built to auto-send content to Feishu, but its default recipient and unchecked file paths create a real risk of sending unintended local files.

Review carefully before installing. Replace the hard-coded Feishu chat ID, disable recurring cron until tested, restrict processing to a dedicated trusted content directory, avoid running with access to secrets or personal files, and remove the file-renaming behavior or add approval before any external send.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install.sh:126
Finding

Log-Controlled Arbitrary File Disclosure and Modification

Content
View full analysis
/dev/null; then log "Content already processed: $path" continue fi # Process the content "$(dirname "${BASH_SOURCE[0]}")/push-content.sh" "$path" "$title" content_found=$((content_found + 1)) fi fi done < "$log_file" ``` ```bash # Check if file exists if [ ! -f "$CONTENT_PATH" ]; then log "❌ Content file not found: $CONTENT_PATH" return 1 fi # Read content content=$(head -1000 "$CONTENT_PATH" 2>/dev/null || echo "Content read failed") # Create Feishu document log "Creating Feishu document: $TITLE" # Try different methods to create Feishu content if command -v openclaw >/dev/null 2>&1; then # Method 1: Send as message (fallback if document creation fails) message="📄 **Auto-Push System Notification**\n\n**Title**: $TITLE\n**Time**: $(date '+%Y-%m-%d %H:%M:%S')\n**Status**: Content generated successfully\n\n**Preview**:\n$content" openclaw message send \ --channel feishu \ --target "$TARGET_CHAT_ID" \ ...[truncated 3187 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install.sh:44
Finding

Hard-Coded Feishu Recipient Can Cause Unauthorized Content Disclosure

Content
View full analysis
"$CONFIG_DIR/settings.conf" << 'EOF' # Auto-Push System Configuration # Target Feishu chat for notifications TARGET_CHAT_ID="oc_c133e85bd6eb593e08dcf7aed3a8530b" ``` ```bash message="📄 **Auto-Push System Notification**\n\n**Title**: $TITLE\n**Time**: $(date '+%Y-%m-%d %H:%M:%S')\n**Status**: Content generated successfully\n\n**Preview**:\n$content" openclaw message send \ --channel feishu \ --target "$TARGET_CHAT_ID" \ --message "$message" 2>&1 | tee -a "$LOG_FILE" ``` ### Technical Analysis The installer generates a configuration containing a concrete Feishu chat identifier rather than requiring the operator to supply and confirm a destination. The runtime push script then transmits file content to that destination. A chat identifier is not necessarily an authentication secret, but it is security-sensitive routing configuration. The audited repository provides no evidence that the embedded conversation belongs to the installing user or organization. The installer also does not fail closed when the setting has not been explicitly reviewed. This behavior is particularly dangerous in combination with the arbitrary file-selection vulnerability: selected local content can be sent to the hard-coded recipient. Even during legitimate use, AI summaries and conversation briefs may contain confidential information. ### Attack Path 1. A user follows the documented installation procedure. 2. The installer creates `config/settings.conf` with the embedded Feishu chat ID. 3. The user does not notice or replace the preconfigured identifier. 4. The user manually runs the monitor or enables the documented cron schedule. 5. A legitimate or forged `CONTENT_READY` record is processed. 6. The generat ...[truncated 880 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/package-skill.sh:412
Finding

Unsafe Cron Uninstallation Instruction Can Delete Unrelated Scheduled Tasks

Content
View full analysis
Remediation
View remediation
"$HOME/crontab.backup.$(date +%Y%m%d%H%M%S)" ``` 4. Display the proposed diff and require confirmation before replacement. 5. Handle the case where the user has no existing crontab. 6. Prefer an exact path and exact comment match if block markers cannot be used. 7. Supply a dedicated uninstall script that is idempotent and tested instead of a broad copy-and-paste pipeline. 8. Keep cron registration opt-in and clearly disclose the execution frequency, command, log destination, and removal procedure. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (32)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 83)May include surrounding context.

systemctl --user status cron

3. Feishu authorization

Ensure your Feishu app has user access token

text

### **Installation**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 292)May include surrounding context.

systemctl --user status cron

3. Feishu authorization

Ensure your Feishu app has user access token

text

### **Installation**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/package-skill.sh (reported line 113)May include surrounding context.

sh
systemctl --user status cron

# 3. Feishu authorization
# Ensure your Feishu app has user access token
```

### **Installation**

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README.md (reported line 331)May include surrounding context.

md
# 1. Backup current configuration
bash scripts/backup-config.sh

# 2. Update skill files
cp -r new-version/* .
# 3. Reconfigure
bash scripts/configure.sh

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documentation describes a general-purpose automated Feishu publishing workflow, but also embeds a fixed target chat ID and describes broader operational behaviors such as system log writes, /tmp scanning, and scheduled execution that are not clearly surfaced as sensitive actions. This mismatch can conceal data exfiltration destinations and overbroad resource access from users reviewing only the high-level description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documentation describes a general-purpose automated Feishu publishing workflow, but also embeds a fixed target chat ID and describes broader operational behaviors such as system log writes, /tmp scanning, and scheduled execution that are not clearly surfaced as sensitive actions. This mismatch can conceal data exfiltration destinations and overbroad resource access from users reviewing only the high-level description.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/install.sh (reported line 310)May include surrounding context.

sh
s
    echo "   Recent items:"
    tail -3 "$PROCESSED_LOG" 2>/dev/null | while read line; do
        title=$(echo "$line" | grep -o '"title":"[^"]*"' | cut -d'"' -f4)
        time=$(echo "$line" | grep -o '"processed_at":"[^"]*"' | cut -d'"' -f4)
        echo "     • $title ($time)"
    done
else
    echo "   No processed content yet"
fi

# Check scheduled tasks
echo -e "\n⏰ Scheduled Tasks:"
crontab -l 2>/dev/null | grep -E "(check-content|ai-podcast|skill-digest|conversation|openclaw)" | while read line; do
    echo "   ✅ $line"
done

echo -e "\n🎯 System Status:"
echo "   Auto-Push System is $(if [ -f "$SYSTEM_LOG" ]; then echo "✅ Active"; else echo "❌ Inactive"; fi)"
EOF

chmod +x "$SCRIPTS_DIR/status.sh"

# Create health-check.sh
cat > "$SCRIPTS_DIR/health-check.sh" << 'EOF'
#!/bin/bash
# Auto-Push System Health Check

CONFIG_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/../config" && pwd)"
source "$CONFIG_DIR/settings.conf"

echo "🏥 Auto-Push System Health Check"
echo

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/package-skill.sh (reported line 417)May include surrounding context.

sh
crontab -l | grep -v "auto-push" | crontab -

# Remove skill files
rm -rf ~/.openclaw/workspace/skills/auto-push-system-skill-1.0.0

# Remove log files (optional)
rm -f /var/log/auto-push-*.log

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/package-skill.sh (reported line 417)May include surrounding context.

sh
crontab -l | grep -v "auto-push" | crontab -

# Remove skill files
rm -rf ~/.openclaw/workspace/skills/auto-push-system-skill-1.0.0

# Remove log files (optional)
rm -f /var/log/auto-push-*.log

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/package-skill.sh (reported line 420)May include surrounding context.

sh
rm -rf ~/.openclaw/workspace/skills/auto-push-system-skill-1.0.0

# Remove log files (optional)
rm -f /var/log/auto-push-*.log
rm -f /tmp/auto-push-processed.jsonl
```

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/package-skill.sh (reported line 421)May include surrounding context.

sh
# Remove log files (optional)
rm -f /var/log/auto-push-*.log
rm -f /tmp/auto-push-processed.jsonl
```

## Next Steps

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes continuous monitoring, processing, and Feishu delivery of AI-generated content but does not clearly warn users that enabling the skill may result in ongoing automatic transmission of potentially sensitive content to external destinations. In a skill specifically designed to watch logs and push content, this omission increases the risk of unintended disclosure because users may enable automation without understanding the privacy and data-flow implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installation and cron scheduling guidance enables unattended recurring execution, but the documentation does not warn that once configured it can continuously detect, process, and send content without per-message approval. That is dangerous in this context because the skill is explicitly built for automated content forwarding, so a user could unintentionally operationalize persistent exfiltration of sensitive summaries, conversations, or reports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage section documents force-push and export operations without any warning that these actions can disclose private or regulated content to Feishu or exported files. In a workflow handling conversation briefs and AI-generated summaries, these examples materially increase the chance of accidental disclosure because they normalize direct bulk transmission and export without emphasizing consent, review, or classification checks.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 296)May include surrounding context.

| Cron Not Running | Check service status: systemctl --user status cron | | Content Not Detected | Verify log files contain CONTENT_READY signals | | API Rate Limits | Implement exponential backoff or batch processing | | Permission Issues | Check log file permissions, use sudo if needed |

Diagnostics

bash

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises shell-based installation, configuration, cron setup, and operational scripts, but does not declare any explicit tool scope or permissions. This creates a transparency and consent gap: a user may invoke or install the skill without understanding that it requires command execution and filesystem access, increasing the risk of unintended system modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promotes fully automatic pushing of AI-generated content to Feishu and group chats without a prominent warning that content will be transmitted to external recipients. In this context, automated outbound messaging is sensitive because summaries, briefings, or generated content may contain confidential, regulated, or mistaken information, and the automation reduces the chance of human review before disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation highlights logging and audit features but does not warn that monitored content, titles, file paths, and operational metadata may be written to system logs such as /var/log. In a monitoring-and-push skill, this increases exposure of sensitive data because logs are often broadly readable by admins, backup systems, or log aggregators and may persist far longer than the original content.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 25)May include surrounding context.

sh
fi

# Check cron
if ! command -v crontab >/dev/null 2>&1; then
    echo "❌ Cron not found. Please install cron service."
    exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install.sh (reported line 33)May include surrounding context.

sh
# Check log directory
if [ ! -d "$LOG_DIR" ]; then
    echo "📁 Creating log directory: $LOG_DIR"
    sudo mkdir -p "$LOG_DIR"
fi

# Create symbolic links

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installer writes a hard-coded Feishu chat ID into default configuration, causing future automated transmissions to go to a preset external destination chosen by the skill author. This is dangerous because users may unknowingly send internal or sensitive content to the wrong recipient, and the hidden default increases the likelihood of silent data exfiltration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The installer seeds scheduled workflows for multiple content-generation and search tasks that go beyond a narrow 'auto-push existing content' setup. Expanding automation scope increases the chance of unexpected data collection, unattended execution, and later transmission of outputs without the user explicitly opting into each workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated push script reads up to 1000 lines from arbitrary content files and sends the preview to Feishu automatically when matching log signals are found, without an installation-time warning, approval step, or per-send confirmation. In a monitoring workflow, this can leak sensitive local file contents to an external chat destination with little user visibility.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 310)May include surrounding context.

sh
# Check scheduled tasks
echo -e "\n⏰ Scheduled Tasks:"
crontab -l 2>/dev/null | grep -E "(check-content|ai-podcast|skill-digest|conversation|openclaw)" | while read line; do
    echo "   ✅ $line"
done

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/package-skill.sh (reported line 414)May include surrounding context.

sh
# Check scheduled tasks
echo -e "\n⏰ Scheduled Tasks:"
crontab -l 2>/dev/null | grep -E "(check-content|ai-podcast|skill-digest|conversation|openclaw)" | while read line; do
    echo "   ✅ $line"
done

Static analysis

No suspicious patterns detected.