Back to skill

Security audit

Drission Sota Toolkit

Security checks for vulnerabilities and agentic risk

Overview

The skill combines ordinary web search with high-risk local browser-control features, while its registry metadata understates those capabilities.

Do not install this as a normal scraper. Only evaluate it in a disposable VM or container with no personal browser profile, no authenticated sessions, and Chrome DevTools exposed only to a dedicated test browser. Before publication or trusted use, align the manifests, disable autonomous invocation consistently, remove or strongly broker CDP takeover paths, fix the wrapper path validation, keep Chromium sandboxing enabled, and pin dependencies.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
_meta.json:7
Finding

Misleading manifest permits autonomous invocation of undisclosed high-risk browser-control capabilities

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/nuclear_option.py:8
Finding

Direct browser takeover is protected only by a forgeable environment variable

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sota_core.py:33
Finding

Protected launcher allows path traversal and arbitrary Python-file execution

Content
View full analysis
1 else None if not script_name: return # Sub-process will connect to this socket def handle_auth(): try: conn, _ = server.accept() data = conn.recv(1024) if data == b"AUTH_REQUEST": conn.sendall(b"AUTH_GRANTED") conn.close() except: pass threading.Thread(target=handle_auth).start() # 3. Secure Launch run_protected_script(script_name) ``` From `scripts/sota_core.py`: ```python def run_protected_script(script_name): """ Secure Execution: Uses subprocess with clean environment. """ base_dir = os.path.dirname(os.path.abspath(__file__)) script_path = os.path.join(base_dir, script_name) # 1. Clean Environment clean_env = os.environ.copy() clean_env['SOTA_INTERNAL_AUTH'] = 'TRUE' # 2. Atomic Execution subprocess.run( [sys.executable, script_path], env=clean_env, check=True ) ``` ### Technical Analysis The wrapper accepts `script_name` directly from `sys.argv` and passes it to `os.path.join()` without an allowlist, canonicalization, containment check, extension check, or symlink policy. An absolute second path operand causes `os.path.join()` to discard `base_dir`. A relative value containing `../` can escape the scripts directory. Consequently, after the displayed challenge is answered, the wrapper can execute any readable Python file selected by the caller. The claimed clean environment is also inaccurate: `os.environ.copy()` retains all inherited variables and merely adds `SOTA_INTERNAL_AUTH`. ### Attack Path 1. An attacker or untrusted automation places or identifies a Pyth ...[truncated 960 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/python_relay.py:58
Finding

Chrome DevTools relay can be started and used without the documented authorization gate

Content
View full analysis
127.0.0.1:{remote_port} ---") server = socket.socket(socket.AF_INET, socket.SOCK_STREAM) server.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1) # CRITICAL: Set timeout so accept() doesn't block forever server.settimeout(5.0) try: server.bind(('127.0.0.1', local_port)) server.listen(5) except Exception as e: print(f"Failed to bind port {local_port}: {e}") return start_time = time.time() threading.Thread(target=self.monitor, args=(start_time,), daemon=True).start() while self.running: try: client_sock, addr = server.accept() self.last_activity = time.time() try: target_sock = socket.create_connection(('127.0.0.1', remote_port), timeout=5) threading.Thread(target=self.pipe, args=(client_sock, target_sock), daemon=True).start() threading.Thread(target=self.pipe, args=(target_sock, client_sock), daemon=True).start() ``` The module starts the relay directly: ```python if __name__ == "__main__": SecureRelay().start(9223, 9222) ``` ### Technical Analysis The relay correctly binds only to loopback and implements idle and maximum-lifespan limits. However, it performs no authorization check before starting and does not authenticate accepted clients. Because the module has a direct executable entry point, it can bypass `secure_wrapper.py` entirely. Loopback binding prevents direct remote access but does not protect against other processes running under the same host or user context. The relay forwar ...[truncated 1069 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sota_security.py:5
Finding

Lockfile authorization can be forged and is not issued by the documented wrapper

Content
View full analysis
60: print("!!! Security token expired. Please re-authorize.") sys.exit(1) ``` The gate is consumed by `direct_takeover.py`: ```python def direct_page_takeover(): verify_access_control() # Mandatory physical gate print("Executing high-privilege page takeover...") # ... logic continues ... ``` However, `secure_wrapper.py` creates a Unix socket and never creates or signs `sota_active.lock`: ```python socket_path = "/tmp/.sota_auth.sock" # Clean up stale sockets if os.path.exists(socket_path): os.remove(socket_path) ``` ### Technical Analysis The lockfile check verifies only that a path exists and has a modification time no more than 60 seconds old. It does not verify file ownership, permissions, file type, contents, cryptographic authenticity, nonce, issuing process, requested operation, or whether the token has already been consumed. Any process with write access to the current user's `~/.openclaw/tmp` directory can create or touch the file and satisfy the check. The documented flow is also internally inconsistent because `secure_wrapper.py` does not issue this lockfile. The currently reviewed `direct_takeover.py` contains placeholder behavior after the chec ...[truncated 997 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/drission_util.py:20
Finding

Chromium is launched with its process sandbox disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded dependency constraints prevent reproducible, reviewed installations

Content
View full analysis
=0.14.0 lxml>=5.1.0 websocket-client>=1.8.0 DrissionPage>=4.1.1.2 requests>=2.31.0 ``` ### Technical Analysis Every dependency uses an unbounded lower-version constraint. A future installation may therefore select releases that did not exist when the skill was reviewed. No lockfile or package hashes are supplied to ensure that installers receive the audited artifacts. This does not prove that any listed dependency is currently malicious or vulnerable. The issue is that the reviewed project does not reproducibly define the third-party code that will execute. The risk is particularly relevant because these packages process network content, implement browser control, and include native or complex parsing components. ### Attack Path 1. A new dependency version is published after the skill audit. 2. An installer resolves that version because it satisfies the `>=` constraint. 3. The package is downloaded without an expected artifact hash. 4. Unreviewed dependency code executes during installation or at runtime. 5. A compromised or incompatible release affects the skill environment. ### Impact Assessment Impact depends on the affected dependency and could range from installation failure to arbitrary code execution with the installing or runtime user's privileges. No specific compromised package or known exploitable version was established during this audit. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported behavior includes targeting a specific third-party site, scraping/extracting content, and writing evidence files, none of which are declared in the description. In context, undeclared external collection plus local evidence storage is materially more dangerous than the stated toolkit framing because it can hide surveillance, policy violations, or unauthorized data harvesting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The metadata presents the package as only basic search and aggregation, while the requirements indicate substantially broader automation support through Chrome and DrissionPage. Misrepresenting capability scope is a security issue because downstream reviewers may approve or invoke the skill under false assumptions, enabling unexpected automated browsing, scripted interaction, or collection behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest claims the skill is a minimal scraper with no high-risk capabilities, but the declared dependencies support full browser automation and protocol-level request manipulation. This kind of capability mismatch is dangerous because it can conceal a much broader operational surface from reviewers and users, undermining informed consent and making abuse or policy evasion easier.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Copying the full parent environment into a child process is not a clean environment and can unintentionally propagate sensitive variables such as tokens, proxy settings, debugging hooks, or dangerous interpreter controls. In this skill context, which explicitly launches additional Python scripts, inherited environment variables can influence child behavior, leak secrets, or weaken the claimed security boundary.

Content

Scanner excerpt · scripts/sota_core.py (reported line 41)May include surrounding context.

python
script_path = os.path.join(base_dir, script_name)
    
    # 1. Clean Environment
    clean_env = os.environ.copy()
    clean_env['SOTA_INTERNAL_AUTH'] = 'TRUE'
    
    # 2. Atomic Execution

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and likely uses powerful capabilities (environment access, filesystem read/write, network, and shell) without declaring an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege boundaries and makes it easier for a consumer to invoke a skill with broader access than expected, increasing the blast radius if the skill is misused or compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Dependencies such as DrissionPage, google-chrome-stable, and curl_cffi are not well-justified by a description limited to basic search and aggregation. Unnecessary high-capability dependencies expand the attack surface, allow behavior beyond declared scope, and make it harder to distinguish legitimate scraping from stealthier or more invasive automation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script exposes an explicit Chrome DevTools Protocol takeover path by discovering a local debugger endpoint and connecting directly to its WebSocket debugger URL. Even with a local Unix-domain-socket gate, this is a high-risk capability because it enables control of an existing browser session, which can expose authenticated sessions, page contents, cookies, and user actions far beyond ordinary automation semantics.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code implements deliberate browser-session takeover by querying /json/version and attaching to the returned webSocketDebuggerUrl, which is a standard path for assuming control over a live browser context. In skill context, this is more dangerous because the toolkit advertises stealthy web-intelligence features and local socket relaying, making unauthorized surveillance or session hijacking a plausible misuse case rather than a purely administrative automation feature.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest claims features such as 'Protocol Phantom (TLS/JA4), Local Socket Relaying, and Hardened physical gating,' but this file only issues two straightforward HTTP GET requests to arXiv and DuckDuckGo, parses HTML, and writes a JSON report. This is a semantic mismatch between the advertised capability and the actual behavior implemented here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function sends the user-supplied query to arXiv over the network without any explicit disclosure, consent flow, or privacy notice. If users provide sensitive research topics, identifiers, or proprietary terms, that data is exposed to a third party and may be logged externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The second request sends the same user query to DuckDuckGo without clear disclosure that the input is being shared with another external provider. In a web-intelligence skill context, users may reasonably submit sensitive investigative terms, making undisclosed third-party transmission more concerning.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code directly attaches to a local Chrome DevTools Protocol endpoint and instantiates a low-level browser driver, bypassing higher-level controls and any normal skill boundary assumptions. Even with an environment-variable gate, this enables arbitrary browser automation against an already-running browser context, which can expose cookies, authenticated sessions, page contents, and privileged browser actions if invoked.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Attaching to a local debugging socket is an invasive capability because the DevTools socket provides broad control over the browser, including navigation and script evaluation. In the context of a web intelligence/automation toolkit, this is more dangerous because it targets an existing local browser on 127.0.0.1, potentially inheriting user state and authenticated data rather than operating in an isolated session.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.