T09 · Insecure Skill Coding Practices
- Location
scripts/login.py:198- Finding
Sensitive session and bot credentials are written without enforced restrictive permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This CSDN publishing skill is mostly coherent, but it handles real account sessions and posting authority with weak containment and credential protection.
Install only if you are comfortable giving this skill access to a real CSDN account and related browser session state. Use a dedicated low-privilege account, avoid running as root, protect or clear the credential directory, treat Telegram bot tokens and CSDN cookies as secrets, and review the article before any final publish action. Enable Notion and Telegram only if you understand what data is sent to those services.
scripts/login.py:198Sensitive session and bot credentials are written without enforced restrictive permissions
scripts/login.py:101Remote web content is loaded in Chromium with the browser sandbox disabled
SKILL.md:193Runtime dependencies are installed from mutable package indexes without version or integrity pinning
scripts/notion-check-duplicate.sh:12User-controlled title and URL values are inserted into a Notion JSON request without JSON escaping
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
with open(config_path, 'r') as f:
config = json.load(f)
bot_token = config.get('bot_token')
chat_id = config.get('chat_id')
if not bot_token or not chat_id:
print("⚠️ Telegram 配置不完整(需要 bot_token 和 chat_id)", file=sys.stderr)
return False
# 发送消息
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
resp = requests.post(url, json={
"chat_id": chat_id,
"text": message,
"parse_mode": "HTML"
}, timeout=10)
if resp.status_code == 200 and resp.json().get('ok'):
print(f"📤 Telegram 通知已发送", file=sys.stderr)
return True
else:
print(f"⚠️ Telegram 发送失败: {resp.text}", file=sys.stderr)
return False
except Exception as e:
print(f"⚠️ Telegram 通知失败: {e}", file=sys.stderr)
return Fa
The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.
The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.
The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.
The declared purpose suggests CSDN-focused automation, while parts of the documented behavior center on querying external data sources and local state management instead of only publishing. Such mismatch weakens reviewability and may hide unexpected data flows, especially where credentials, proxies, or API access are involved.
The README advertises automated publishing and Telegram-based QR delivery for login without warning about privacy, credential/session exposure, or the consequences of posting to a real CSDN account. This omission is dangerous because users may not realize that account authentication artifacts, article drafts, and publication actions are being routed through external services or automation with real-world account impact.
The README suggests trigger phrases like '帮我写一篇关于 XXX 的文章发到 CSDN' and '发布这篇文章到 CSDN', which are broad, natural-language commands that can overlap with ordinary conversation. In an agent environment, overly broad triggers increase the chance of unintended invocation of a skill that performs account-impacting actions such as publishing content, especially when combined with browser automation.
The skill requests or implies broad capabilities including shell, network, file read/write, environment access, and browser/session handling, but it does not declare any explicit tool scope or permission boundaries. This increases the blast radius of prompt injection or accidental invocation because the agent may perform sensitive filesystem, credential, network, and process actions without a constrained policy.
The trigger phrases are broad enough to match common writing or publishing requests, which can cause the skill to activate unexpectedly. Overbroad invocation is dangerous here because the skill can access files, network resources, browser sessions, and credentials, so accidental activation may lead to unintended side effects.
The triggering conditions are vague and boundaryless, especially around any request involving topics, materials, or links. In a skill with automation, persistence, and external communications, ambiguous activation increases the chance of unintended execution against user content or stored sessions.
The skill description omits that it queries a Notion database for recent records during news deduplication. Undisclosed access to a third-party database is a security and privacy concern because users may not realize the skill reads potentially sensitive organizational content or uses API credentials beyond CSDN publishing.
Using nohup to launch a background login flow creates a persistent process outside the immediate interaction lifecycle. While likely intended for reliability, detached session processes reduce visibility and control, and can leave login artifacts, logs, or browser state running longer than expected.
cd /root/.openclaw/workspace/skills/csdn-publisher
nohup python scripts/login.py login --timeout 300 > /tmp/csdn-login.log 2>&1 &
The skill instructs sending a login QR code through Telegram without warning about privacy and interception risks. Login QR artifacts can expose account access workflows and user identifiers to a third-party messaging service, which is especially sensitive when combined with persistent browser sessions and cookie storage.
The workflow requires saving full article content and publish status to local disk but does not warn users that their content will be persistently stored. This is risky because drafts may contain proprietary, personal, or embargoed material, and predictable paths under /tmp can increase unauthorized access exposure in shared environments.
The skill documents persistent storage of cookies and browser login state without prominently warning about credential theft or session hijacking risk. Stored cookies and user-data directories can grant durable access to the user's CSDN account, making compromise of the host or workspace especially damaging.
The skill includes Telegram bot notification setup requiring bot token and chat ID, which are unrelated to the core task unless clearly justified and consented to. Collecting extra credentials expands the attack surface and creates a risk of credential leakage or abuse for messaging actions outside the user's expectations.
The notification-enabled login flow also uses nohup, again creating a detached persistent process with access to login state and messaging configuration. In combination with saved cookies and Telegram settings, this can prolong exposure of sensitive artifacts beyond the user's active session.
nohup python scripts/login.py login --timeout 300 --notify > /tmp/csdn-login.log 2>&1 &
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
return False
# 发送消息
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
resp = requests.post(url, json={
"chat_id": chat_id,
"text": message,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 发送消息
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
resp = requests.post(url, json={
"chat_id": chat_id,
"text": message,
"parse_mode": "HTML"
The setup-notify command stores sensitive Telegram bot credentials to disk in plaintext without an explicit warning or permission hardening. If another local user or process can read the file, they can abuse the bot token to send messages or interact with the bot as that identity.
The manifest describes a skill for writing and publishing articles to CSDN via browser automation and Telegram-assisted login. This script instead queries a Notion database to detect duplicate 'news' entries by title or URL, which is a separate content-management/information-tracking capability not described in the manifest.
Accessing a Notion database using an API key is not an obvious requirement for writing and publishing posts to CSDN, especially when the manifest only mentions browser automation, QR-code login via Telegram, and a blog-writing methodology. This introduces an additional third-party data access capability outside the stated scope.
The Notion API endpoint itself confirms data leaves the local environment for a third-party service. While the destination is legitimate, the risk comes from hidden or unnecessary transmission in the context of an automation skill, especially if users do not expect their article metadata to be checked against a remote database.
)
fi
RESULT=$(curl -s -X POST "https://api.notion.com/v1/databases/$DATABASE_ID/query" \
-H "Authorization: Bearer $NOTION_KEY" \
-H "Notion-Version: 2022-06-28" \
-H "Content-Type: application/json" \
The Notion API endpoint itself confirms data leaves the local environment for a third-party service. While the destination is legitimate, the risk comes from hidden or unnecessary transmission in the context of an automation skill, especially if users do not expect their article metadata to be checked against a remote database.
)
fi
RESULT=$(curl -s -X POST "https://api.notion.com/v1/databases/$DATABASE_ID/query" \
-H "Authorization: Bearer $NOTION_KEY" \
-H "Notion-Version: 2022-06-28" \
-H "Content-Type: application/json" \
The script silently transmits user-supplied title/URL metadata and a bearer-authenticated query to Notion without any user-facing disclosure or consent at execution time. In an agent skill context, undisclosed external transmission increases privacy risk because user content and linked sources may be sent to a third party unexpectedly.
No suspicious patterns detected.