Back to skill

Security audit

Bazhuayu Rpa Webhook

Security checks for vulnerabilities and agentic risk

Overview

This appears to be an RPA webhook utility, but it needs Review because it ships live-looking tenant credentials and its setup, migration, and logging paths can expose secrets.

Review this carefully before installing. Do not use it as packaged with the included config.json values; the exposed Feishu authorization value should be rotated, tenant-specific URLs removed, and only placeholder config shipped. Setup and migration scripts should stop printing or writing real secrets, logs should redact parameter values by default, and any RPA run should require a user-selected test or production webhook.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
config.json:2
Finding

Authorization Credential Distributed in Packaged Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
bazhuayu-webhook.py:396
Finding

Sensitive Parameters Bypass Redaction and Leak to Console and Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
setup-secure.sh:105
Finding

Setup Wizard Displays and Persists the Webhook Secret in Plaintext

Content
View full analysis
"$ENV_FILE" chmod 600 "$ENV_FILE" ``` The secret is also collected with visible input: ```bash read -p "请输入签名密钥 (Key): " WEBHOOK_KEY ``` ### Technical Analysis The setup wizard reads the signing key without silent-input protection, prints an export command containing the complete key, and writes that command to `.env.example`. Although the file is changed to mode 600, it remains a persistent plaintext copy of the secret. The `.env.example` name is especially unsafe because files with that name are commonly treated as non-sensitive templates and may be copied into packages, backups, issue reports, or source repositories. Terminal output can also be retained by session recording, CI logs, shell wrappers, or remote administration tools. These actions are unnecessary for webhook configuration and conflict with the script's claim that sensitive information is stored securely in environment variables. ### Attack Path 1. A user starts `setup-secure.sh`. 2. The user types the webhook signing key, which is visible at the terminal. 3. The script prints the complete key as part of `ENV_CONFIG`. 4. The script writes the same key to `.env.example`. 5. An attacker obtains a terminal transcript, backup, copied Skill directory, or the generated file. 6. The attacker uses the key to authenticate webhook requests, subject to the associated webhook's permissions and signature protocol. ### Impact Assessment The is ...[truncated 365 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
migrate-to-env.sh:32
Finding

Migration Process Multiplies Plaintext Copies of Existing Secrets

Content
View full analysis
"$ENV_FILE" chmod 600 "$ENV_FILE" ``` ### Technical Analysis The migration script is intended to remove a key from `config.json`, but it first makes a timestamped backup containing the original key. It then prints the key and creates another plaintext copy in `.env.migrated`. The script explicitly restricts `.env.migrated` after creation but does not explicitly secure `config.json.backup.*`. Its effective permissions depend on the source file mode, current umask, filesystem behavior, and preexisting configuration. Even if all files are mode 600, the migration increases the number of persistent secret copies and expands backup and accidental-publication exposure. Clearing the key from the active configuration therefore does not complete secret migration or deletion. ### Attack Path 1. A user runs `migrate-to-env.sh` on a configuration containing a signing key. 2. The script copies the original configuration to `config.json.backup.`. 3. The script prints the signing key in an export command. 4. The script stores another copy in `.env.migrated`. 5. The active configuration is cleared, giving the user the impression that migration is complete. 6. An attacker later reads a backup, terminal transcript, filesystem snapshot, copied directory, or `.env.migrated`. 7. T ...[truncated 512 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
setup-secure.sh:144
Finding

Untrusted Webhook URL Is Expanded Inside an Executable Heredoc

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (56)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · QUICKSTART.md (reported line 66)May include surrounding context.

配置完成后,请手动将 export 命令添加到 ~/.bashrc 或 ~/.zshrc。


📝 方式二:手动配置

步骤 1: 设置环境变量

bash
# 临时设置(当前终端会话)
export BAZHUAYU_WEBHOOK_KEY="你的签名密钥"
export BAZHUAYU_WEBHOOK_URL="https://api-rpa.bazhuayu.com/api/v1/bots/webhooks/xxx/invoke"

# 永久设置(添加到 ~/.bashrc 或 ~/.zshrc)
echo 'export BAZHUAYU_WEBHOOK_KEY="你的签名密钥"' >> ~/.bashrc
echo 'export BAZHUAYU_WEBHOOK_URL="https://api-rpa.bazhuayu.com/api/v1/bots/webhooks/xxx/invoke"' >> ~/.bashrc
source ~/.bashrc

步骤 2: 编辑配置文件

bash
vim config.json

填入配置(key 留空):

json
{
  "url": "https://api-rpa.bazhuayu.com/api/v1/bots/webhooks/你的 ID/invoke",
  "key": "",
  "paramNames": ["keyword", "url"],
  "defaultParams": {
    "keyword": "默认关键词",
    "url": "https://example.com"
  }
}

步骤 3: 验证配置

bash
python3 bazhuayu-webhook.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The release notes instruct users to run 'rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook', a forceful recursive delete under /root, with no safety guardrails. Because this is likely to be copy-pasted by operators, any typo, variable substitution issue, or path confusion could delete unintended files, especially in privileged environments.

Content

Scanner excerpt · RELEASE-2.0.6.md (reported line 79)May include surrounding context.

bash
# 删除旧版本
rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook

# 重新安装
clawhub install bazhuayu-webhook

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The release notes instruct users to run 'rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook', a forceful recursive delete under /root, with no safety guardrails. Because this is likely to be copy-pasted by operators, any typo, variable substitution issue, or path confusion could delete unintended files, especially in privileged environments.

Content

Scanner excerpt · RELEASE-2.0.6.md (reported line 79)May include surrounding context.

bash
# 删除旧版本
rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook

# 重新安装
clawhub install bazhuayu-webhook

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SECURITY.md (reported line 142)May include surrounding context.

md
--prune-empty --tag-name-filter cat -- --all

# 2. 推送更改
git push origin --force --all

# 3. 联系 GitHub/GitLab 支持清除缓存 (如已推送到远程)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The English description promises webhook-based RPA triggering, while the analyzed content also describes interactive configuration collection, local file updates, migration helpers, shell-session exports, and permission changes, with no actual webhook-trigger behavior present in the analyzed chunk. This discrepancy can mislead reviewers and automation policies, allowing broader local-impact behavior to pass under the label of a simple integration utility.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The English description promises webhook-based RPA triggering, while the analyzed content also describes interactive configuration collection, local file updates, migration helpers, shell-session exports, and permission changes, with no actual webhook-trigger behavior present in the analyzed chunk. This discrepancy can mislead reviewers and automation policies, allowing broader local-impact behavior to pass under the label of a simple integration utility.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
- **安全指南**: `SECURITY.md` - 安全最佳实践

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The example shows passing a username and password directly as command-line arguments and transmitting them to a remote webhook, which is dangerous because credentials may be exposed in shell history, process listings, logs, screenshots, and downstream systems. Presenting a plaintext password example without warnings can cause users to adopt insecure credential-handling practices in real deployments.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · WEBHOOK_SETUP_PREVIEW.html (reported line 115)May include surrounding context.

html
<p>本教程详细介绍如何在八爪鱼 RPA 中创建和配置 Webhook 触发器。</p>

        <!-- 步骤 1 -->
        <div class="step">
            <h2><span class="step-number">1</span>进入触发器管理</h2>
            <ol>

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · bazhuayu-webhook.py (reported line 103)May include surrounding context.

python
config['key'] = env_key
    
    # 3. 加载环境变量中的参数默认值 (BAZHUAYU_PARAM_*)
    for env_name, env_value in os.environ.items():
        if env_name.startswith('BAZHUAYU_PARAM_'):
            param_name = env_name.replace('BAZHUAYU_PARAM_', '')
            # 转换为驼峰或小写格式

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The configuration hardcodes a Feishu authorization token and multiple internal Feishu Base URLs directly in the skill defaults. This exposes reusable credentials and private workspace resources to anyone who can read, copy, or invoke the skill, enabling unauthorized access to Feishu data and unintended triggering of downstream RPA workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s natural-language content consistently forces a specific language/locale for readers. Under the policy, language constraints should either be optional for users or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · MANUAL.md (reported line 89)May include surrounding context.

bash
# 创建目录
mkdir -p ~/.openclaw/workspace/skills/bazhuayu-webhook
cd ~/.openclaw/workspace/skills/bazhuayu-webhook

# 下载主程序(需要主程序文件)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manual instructs users to place the webhook signing key directly into a local config.json file and provides no guidance on file permissions, secret storage, or redaction. That increases the chance the key is exposed through world-readable files, backups, screenshots, shell history, or accidental commits, allowing unauthorized triggering of RPA jobs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The usage examples show simple run commands that will invoke a remote webhook and start automation in the user's RPA environment, but they do not clearly warn that these commands cause real external side effects. In an agent or automation context, that can lead to accidental execution of business workflows, data collection, or browser automation against production targets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The integration example uses a broad natural-language trigger like '采集新闻' to automatically start an RPA workflow. Broad triggers increase the risk of unintended activation from ambiguous user messages, prompt injection in surrounding conversation, or benign mentions that should not launch external automation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · MANUAL.md (reported line 378)May include surrounding context.

  1. 同步系统时间
    bash
    # Linux
    sudo ntpdate pool.ntp.org
    
    # 或使用 timedatectl
    sudo timedatectl set-ntp true
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · MANUAL.md (reported line 381)May include surrounding context.

  1. 同步系统时间
    bash
    # Linux
    sudo ntpdate pool.ntp.org
    
    # 或使用 timedatectl
    sudo timedatectl set-ntp true
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · MANUAL.md (reported line 424)May include surrounding context.

  1. 同步系统时间
    bash
    # Linux
    sudo ntpdate pool.ntp.org
    
    # 或使用 timedatectl
    sudo timedatectl set-ntp true
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · MANUAL.md (reported line 442)May include surrounding context.

  1. 同步系统时间
    bash
    # Linux
    sudo ntpdate pool.ntp.org
    
    # 或使用 timedatectl
    sudo timedatectl set-ntp true
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · MANUAL.md (reported line 448)May include surrounding context.

  1. 同步系统时间
    bash
    # Linux
    sudo ntpdate pool.ntp.org
    
    # 或使用 timedatectl
    sudo timedatectl set-ntp true
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

标题和全文说明均以中文呈现,且未说明这是面向特定地区/用户群的限定版本,也未提供其他语言选项。根据语言/区域政策,强制单一语言而无用户选择可能构成自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill documentation is presented entirely in Chinese from the title onward, with no indication that other languages are supported or that Chinese is an optional locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manual installation section instructs users to run a destructive deletion command before reinstalling, but it does not include an explicit warning, path validation step, backup guidance, or confirmation note. In operational environments, users may copy-paste such commands blindly, and any path misunderstanding or modification could lead to unintended data loss.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · MANUAL_SETUP.md (reported line 130)May include surrounding context.

bash
# 设置正确权限 (仅所有者可读写)
chmod 600 config.json

# 验证权限
ls -la config.json

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
RELEASE-2.0.6.md:79