Back to skill

Security audit

Csdn Publisher

Security checks for vulnerabilities and agentic risk

Overview

This CSDN publishing skill is mostly coherent, but it handles real account sessions and posting authority with weak containment and credential protection.

Install only if you are comfortable giving this skill access to a real CSDN account and related browser session state. Use a dedicated low-privilege account, avoid running as root, protect or clear the credential directory, treat Telegram bot tokens and CSDN cookies as secrets, and review the article before any final publish action. Enable Notion and Telegram only if you understand what data is sent to those services.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/login.py:198
Finding

Sensitive session and bot credentials are written without enforced restrictive permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/login.py:101
Finding

Remote web content is loaded in Chromium with the browser sandbox disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:193
Finding

Runtime dependencies are installed from mutable package indexes without version or integrity pinning

Content
View full analysis
/dev/null ``` The script documentation additionally identifies unpinned Python dependencies: ```text pip install playwright requests playwright install chromium ``` ### Technical Analysis The installation instructions resolve the current versions of `playwright`, `requests`, `ws`, and Chromium at installation time. The project supplies no Python constraints file, hash-locked requirements file, npm lockfile, or integrity verification procedure. Consequently, the audited source tree does not fully determine the code that will execute. A future compromised package release, registry account compromise, dependency-chain compromise, or unexpectedly incompatible update may introduce installation-time or runtime behavior that was not present during this audit. The use of `2>/dev/null` for npm installation also suppresses diagnostics that could reveal integrity failures, lifecycle-script errors, or registry problems. No evidence was found that the named packages or their current official releases are malicious. The risk arises from mutable and unverifiable dependency resolution. ### Attack Path 1. An operator follows the installation instructions. 2. `pip` or `npm` resolves the latest package versions from the configured registry. 3. A package release or transitive dependency has been compromised, replaced, or maliciously updated after the Skill audit. 4. Package installation executes package-controlled setup or lifecycle behavior, or the compromised code runs when imported. 5. The dependency executes with the privileges of the installing or Skill-running account. 6. It may read workspace file ...[truncated 691 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/notion-check-duplicate.sh:12
Finding

User-controlled title and URL values are inserted into a Notion JSON request without JSON escaping

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (36)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/login.py (reported line 53)May include surrounding context.

python
with open(config_path, 'r') as f:
            config = json.load(f)
        
        bot_token = config.get('bot_token')
        chat_id = config.get('chat_id')
        
        if not bot_token or not chat_id:
            print("⚠️ Telegram 配置不完整(需要 bot_token 和 chat_id)", file=sys.stderr)
            return False
        
        # 发送消息
        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        resp = requests.post(url, json={
            "chat_id": chat_id,
            "text": message,
            "parse_mode": "HTML"
        }, timeout=10)
        
        if resp.status_code == 200 and resp.json().get('ok'):
            print(f"📤 Telegram 通知已发送", file=sys.stderr)
            return True
        else:
            print(f"⚠️ Telegram 发送失败: {resp.text}", file=sys.stderr)
            return False
    except Exception as e:
        print(f"⚠️ Telegram 通知失败: {e}", file=sys.stderr)
        return Fa

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises automated publishing and Telegram-based QR delivery for login without warning about privacy, credential/session exposure, or the consequences of posting to a real CSDN account. This omission is dangerous because users may not realize that account authentication artifacts, article drafts, and publication actions are being routed through external services or automation with real-world account impact.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README suggests trigger phrases like '帮我写一篇关于 XXX 的文章发到 CSDN' and '发布这篇文章到 CSDN', which are broad, natural-language commands that can overlap with ordinary conversation. In an agent environment, overly broad triggers increase the chance of unintended invocation of a skill that performs account-impacting actions such as publishing content, especially when combined with browser automation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill requests or implies broad capabilities including shell, network, file read/write, environment access, and browser/session handling, but it does not declare any explicit tool scope or permission boundaries. This increases the blast radius of prompt injection or accidental invocation because the agent may perform sensitive filesystem, credential, network, and process actions without a constrained policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to match common writing or publishing requests, which can cause the skill to activate unexpectedly. Overbroad invocation is dangerous here because the skill can access files, network resources, browser sessions, and credentials, so accidental activation may lead to unintended side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The triggering conditions are vague and boundaryless, especially around any request involving topics, materials, or links. In a skill with automation, persistence, and external communications, ambiguous activation increases the chance of unintended execution against user content or stored sessions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description omits that it queries a Notion database for recent records during news deduplication. Undisclosed access to a third-party database is a security and privacy concern because users may not realize the skill reads potentially sensitive organizational content or uses API credentials beyond CSDN publishing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Using nohup to launch a background login flow creates a persistent process outside the immediate interaction lifecycle. While likely intended for reliability, detached session processes reduce visibility and control, and can leave login artifacts, logs, or browser state running longer than expected.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

  1. 启动登录脚本
bash
cd /root/.openclaw/workspace/skills/csdn-publisher
nohup python scripts/login.py login --timeout 300 > /tmp/csdn-login.log 2>&1 &
  1. 等待二维码生成(约 10-15 秒)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs sending a login QR code through Telegram without warning about privacy and interception risks. Login QR artifacts can expose account access workflows and user identifiers to a third-party messaging service, which is especially sensitive when combined with persistent browser sessions and cookie storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow requires saving full article content and publish status to local disk but does not warn users that their content will be persistently stored. This is risky because drafts may contain proprietary, personal, or embargoed material, and predictable paths under /tmp can increase unauthorized access exposure in shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents persistent storage of cookies and browser login state without prominently warning about credential theft or session hijacking risk. Stored cookies and user-data directories can grant durable access to the user's CSDN account, making compromise of the host or workspace especially damaging.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill includes Telegram bot notification setup requiring bot token and chat ID, which are unrelated to the core task unless clearly justified and consented to. Collecting extra credentials expands the attack surface and creates a risk of credential leakage or abuse for messaging actions outside the user's expectations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The notification-enabled login flow also uses nohup, again creating a detached persistent process with access to login state and messaging configuration. In combination with saved cookies and Telegram settings, this can prolong exposure of sensitive artifacts beyond the user's active session.

Content

Scanner excerpt · SKILL.md (reported line 504)May include surrounding context.

启动带通知的登录

bash
nohup python scripts/login.py login --timeout 300 --notify > /tmp/csdn-login.log 2>&1 &

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/login.py (reported line 53)May include surrounding context.

python
return False
        
        # 发送消息
        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        resp = requests.post(url, json={
            "chat_id": chat_id,
            "text": message,

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/login.py (reported line 54)May include surrounding context.

python
# 发送消息
        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        resp = requests.post(url, json={
            "chat_id": chat_id,
            "text": message,
            "parse_mode": "HTML"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup-notify command stores sensitive Telegram bot credentials to disk in plaintext without an explicit warning or permission hardening. If another local user or process can read the file, they can abuse the bot token to send messages or interact with the bot as that identity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a skill for writing and publishing articles to CSDN via browser automation and Telegram-assisted login. This script instead queries a Notion database to detect duplicate 'news' entries by title or URL, which is a separate content-management/information-tracking capability not described in the manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Accessing a Notion database using an API key is not an obvious requirement for writing and publishing posts to CSDN, especially when the manifest only mentions browser automation, QR-code login via Telegram, and a blog-writing methodology. This introduces an additional third-party data access capability outside the stated scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The Notion API endpoint itself confirms data leaves the local environment for a third-party service. While the destination is legitimate, the risk comes from hidden or unnecessary transmission in the context of an automation skill, especially if users do not expect their article metadata to be checked against a remote database.

Content

Scanner excerpt · scripts/notion-check-duplicate.sh (reported line 42)May include surrounding context.

sh
)
fi

RESULT=$(curl -s -X POST "https://api.notion.com/v1/databases/$DATABASE_ID/query" \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2022-06-28" \
  -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The Notion API endpoint itself confirms data leaves the local environment for a third-party service. While the destination is legitimate, the risk comes from hidden or unnecessary transmission in the context of an automation skill, especially if users do not expect their article metadata to be checked against a remote database.

Content

Scanner excerpt · scripts/notion-check-duplicate.sh (reported line 42)May include surrounding context.

sh
)
fi

RESULT=$(curl -s -X POST "https://api.notion.com/v1/databases/$DATABASE_ID/query" \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2022-06-28" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script silently transmits user-supplied title/URL metadata and a bearer-authenticated query to Notion without any user-facing disclosure or consent at execution time. In an agent skill context, undisclosed external transmission increases privacy risk because user content and linked sources may be sent to a third party unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.