Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it also gives a remote service control over verbatim user-facing comment content and recommends mutable forced install commands.

Install only if you are comfortable sending Douyin or Xiaohongshu links to the publisher's hosted service. Review any generated comment suggestions carefully, because the skill is instructed to relay backend-provided comment text verbatim. Prefer a pinned, trusted install path over the documented npx clawhub@latest --force commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:119
Finding

Remote-Controlled Promotional Content Is Relayed Verbatim

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/update_local_skill.sh:11
Finding

Mutable Third-Party Installer Is Downloaded and Executed Without Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (22)

Tainted flow: 'req' from os.getenv (line 15, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/check_service_health.py (reported line 17)May include surrounding context.

python
url = f"{base_url}/health"
    req = request.Request(url, headers={"Accept": "application/json"}, method="GET")
    try:
        with request.urlopen(req, timeout=15) as resp:
            payload = json.loads(resp.read().decode("utf-8"))
    except error.HTTPError as exc:
        body = exc.read().decode("utf-8", errors="replace")

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is end-user functionality: transforming social media links into summaries, todo lists, and reminder times. The actual code chunk does none of that. It only checks whether the backend service is reachable and healthy by calling the /health endpoint. While such a script could be a supporting operational component of the overall system, this code chunk's behavior is materially different from the declared skill behavior and introduces an undeclared monitoring capability. Therefore this chunk does not accurately represent the described functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about end-user content processing of Douyin/Xiaohongshu links through a hosted service. The actual code does not process links, summarize content, generate todos, or recommend reminder times. Instead, it is an installer/update script for a local skill, invoking external package tooling and making filesystem changes. That is a materially different primary purpose and includes undeclared capabilities related to local installation and deletion.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
The public skill should not redirect normal end users to repository setup or local deployment by default.
The public skill should not implement its own reminder scheduler when OpenClaw cron is available.

## Output Rules

- The default final user-facing result should have these sections:
  - `【总结】`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/update_local_skill.sh (reported line 29)May include surrounding context.

sh
if [[ -e "${SKILLS_DIR}/${LEGACY_SLUG}" ]]; then
  echo "Removing legacy local directory ${SKILLS_DIR}/${LEGACY_SLUG}"
  rm -rf "${SKILLS_DIR:?}/${LEGACY_SLUG}"
fi

echo "Local skill is ready at ${SKILLS_DIR}/${CANONICAL_SLUG}"

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The install command uses npx clawhub@latest, which fetches and executes the newest published package at runtime rather than a reviewed, fixed version. If the package is compromised, typosquatted, or a breaking/malicious release is published, users following the documentation could execute untrusted code on their machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command again relies on npx clawhub@latest, causing dynamic execution of whatever version is current at install time. In a skill-distribution context, this increases supply-chain risk because end users are encouraged to run a package-fetching command directly from documentation without version pinning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README strongly emphasizes 'zero configuration' and 'server-side handling' while initially downplaying that user-submitted links are transmitted to a third-party hosted service controlled by the publisher. In this skill's context, that matters because pasted links can reveal user interests, private/share-token content references, campaign research, or other sensitive metadata, and the hosted service becomes a trust boundary not clearly foregrounded to users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly relies on network access and environment-variable overrides, but it declares no tool scope or permission boundary. That makes its effective capabilities broader and less auditable, increasing the chance that a host agent grants network/env access implicitly without clear operator review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill sends user-supplied Douyin/Xiaohongshu links to a hosted external service, but the description does not present this as a clear user-facing data-transfer warning. Users may unknowingly disclose private, tracking, or account-linked URLs to a remote service, which is a privacy and trust risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file mandates fixed Chinese section headers and later provides mandatory Chinese failure-message templates, but does not offer the user a language choice or document a justified locale restriction. This is a natural-language policy issue because it enforces a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description and default prompt require output sections such as 【总结】, 【Todo List】, 【推荐提醒时间】 and include Chinese-only trigger phrases, which imposes a specific language/locale behavior by default. There is no indication that the user can choose another language or opt into Chinese output.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The instruction to execute immediately without asking for confirmation authorizes autonomous external actions based solely on detecting a supported link. In this context, that means transmitting user-supplied content to a third-party service and potentially chaining into reminder creation later, increasing the risk of unintended data disclosure and unwanted actions.

Content

Scanner excerpt · agents/openai.yaml (reported line 4)May include surrounding context.

yaml
interface:
  display_name: "Link Transcriber"
  short_description: "转写后输出总结、Todo 和推荐提醒时间"
  default_prompt: "Use $link-transcriber to process a Douyin or Xiaohongshu link through https://linktranscriber.store. The publisher-operated hosted service handles required platform access on the server side. Use the public contract `POST /public/transcriptions` and `GET /public/transcriptions/{task_id}` only. For normal use, do not redirect users to GitHub repositories, local deployment, Python, ffmpeg, credential setup, or backend project installation. If the user already provided a supported link, execute immediately without asking for confirmation. Prefer the bundled Python script in the installed skill directory over ad-hoc curl commands. When the script is invoked without flags, it already renders the final user-facing sections; prefer relaying that rendered output instead of rebuilding the response from JSON fields. By default, return `【总结】`, `【Todo List】`, and `【推荐提醒时间】`. If the completed result contains non-empty `comment_candidates`, also append a `【评论参考】` section and return those backend-provided candidates as-is; do not shorten candidates with ellipses such as `……`; treat them as real-user comments addressed to everyone reading the Xiaohongshu comment section, not as assistant replies to the current user; preserve the Xiaohongshu group invite paragraph exactly when it appears in backend-provided candidates. Keep the todo items concrete and action-oriented, preserve explicit source constraints such as durations, wait times, ordered steps, and named checkpoints, and recommend at least one specific reminder datetime. If the source clearly implies a delayed review rhythm, the reminder recommendation may include a same-day first step plus a follow-up review time. When the user explicitly asks for a Xiaohongshu comment version, comment copy, 引流版, 适合发评论区, or 帮我写评论, switch to comment-only mode instead of the default structure. In comment-only mode, do not improvise from `
...[truncated 25 chars]

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill enables implicit invocation with no visible trigger constraints beyond a broad default prompt, which can cause the agent to send user-provided links to an external hosted service without sufficiently explicit user intent. Because the service processes third-party social links server-side, unintended activation can leak user data or cause unanticipated network actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file contains hardcoded Chinese-language user-facing messages such as "未知错误" and additional Chinese output strings elsewhere, indicating the skill enforces a specific language for results and errors. There is no visible option for users to choose their preferred language or locale, which creates a language-policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends the user-provided link to a remote third-party service (/public/transcriptions) without any explicit disclosure, confirmation, or warning at the point of use. Because Douyin/Xiaohongshu links can embed personal, private, or account-associated content, silent transmission can cause privacy and data-handling risks, especially since the skill’s core function depends on server-side access outside the user’s local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The script executes npx clawhub@latest, which fetches and runs the newest published package version at install time rather than a reviewed, pinned release. This creates a supply-chain risk: if the package is compromised, unpublished/replaced, or a breaking/malicious update is released, anyone running the updater will execute attacker-controlled code locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Natural-language instructions, examples, and operational guidance are written exclusively in Chinese, and the file does not indicate that the skill is region-specific or that users may choose another language. Under the language/locale policy, forcing a single language without opt-in can be a policy concern unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, which can constitute a language/locale policy violation when no opt-in or alternative language is provided. The file does not indicate that the skill is intentionally region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The deployment guide discloses developer-local filesystem paths unrelated to safe public deployment of the skill. While the paths do not by themselves grant access, they leak internal usernames, directory structure, project names, and likely repository layout, which can aid targeted phishing, social engineering, or follow-on attacks against the maintainer environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.