Back to skill

Security audit

Geo Cycle Autopilot

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent GEO automation helper, but it handles API keys, scheduled authenticated requests, local file writes, and remote-controlled fetch/export paths with insufficient scoping and safeguards.

Review before installing. This skill is not clearly malicious, but it should only be used if you trust the GEO SaaS account and service responses, accept daily unattended authenticated actions, and are comfortable with a plaintext local API key. Prefer a secure secret store or owner-only key file permissions, validate exported path components, and restrict web_fetch to trusted public HTTPS URLs before enabling scheduled use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:91
Finding

Remote-Controlled Source URLs Can Trigger Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:68
Finding

API-Controlled Brand and Product Names Permit Export Path Traversal

Content
View full analysis
" CYCLE= BRAND="" PRODUCT="" DIR="$HOME/.qclaw/geo-exports/${BRAND}_${PRODUCT}_C${CYCLE}/fanwen" mkdir -p "$DIR" curl -fsSL -o "$DIR/fanwen.zip" \ "$BASE/api/geo/optimization/$OPT_ID/cycles/$CYCLE/export/fanwen.zip" \ -H "Authorization: Bearer $GEO_KEY" ``` ```bash DIR_FX="$HOME/.qclaw/geo-exports/${BRAND}_${PRODUCT}_C${CYCLE}/fangxie" mkdir -p "$DIR_FX" curl -fsSL -o "$DIR_FX/fangxie.zip" \ "$BASE/api/geo/optimization/$OPT_ID/cycles/$CYCLE/export/fangxie.zip" \ -H "Authorization: Bearer $GEO_KEY" ``` `BRAND`, `PRODUCT`, and `CYCLE` originate from API response fields and are interpolated directly into local paths. ### Technical Analysis Shell quoting prevents word splitting and wildcard expansion, but it does not neutralize path separators or traversal components. Values containing sequences such as `../`, absolute-path-like components, or platform-specific separators can alter the normalized destination. The subsequent `mkdir -p` creates the attacker-influenced directory, and `curl -o` writes a fixed archive name beneath that directory. No canonicalization or containment check verifies that the final destination remains within `$HOME/.qclaw/geo-exports`. The same weakness exists independently in both the `fanwen` and `fangxie` export branches. ### Attack Path 1. An attacker compromises the GEO API response or gains the ability to create or modify task metadata. 2. The attacker places path traversal components in `brandName`, `productName`, or a malformed cycle value. 3. The skill copies the API values into `BRAND`, `PRODUCT`, and `CYCLE`. 4. The values are concatenated into `DIR` or `DIR_FX`. 5. `mkdir -p` resolves travers ...[truncated 851 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

API Key File Is Created Without Enforced Restrictive Permissions

Content
View full analysis
" > ~/.qclaw/geo-api-key ``` The command stores a bearer credential in a plaintext file but does not securely create the parent directory or explicitly enforce owner-only file permissions. ### Technical Analysis The effective permissions of a newly created file depend on the process umask. If the user's environment has a permissive umask, the key may be readable by other local users. If the file already exists, shell redirection truncates it while preserving its existing permissions, which may already be overly broad. The skill also supports reading a fallback credential from `~/.openclaw/geo-api-key`, but it does not require a permission check before using either file. Because the key is used as a bearer token in the `Authorization` header, possession of the file may be sufficient to authenticate to the GEO API. ### Attack Path 1. The user follows the documented command in an environment with a permissive umask, or the target file already exists with broad permissions. 2. The GEO API key is written to `~/.qclaw/geo-api-key` without correcting its ownership or mode. 3. Another local user or process reads the credential file. 4. The attacker submits the stolen bearer key to the GEO API. 5. The attacker obtains whatever task-reading, generation, export, or status-reporting capabilities are granted to that key. ### Impact Assessment This issue can expose the GEO bearer credential to other principals with local filesystem access. The resulting remote privileges are limited to those assigned to the stolen API key, but may include viewing optimization tasks, exporting generated content, initiating supported article workflows, and changing export-related status. The issue does not itself provide elevated operating-system privileges. ]]>
Remediation
View remediation
"$HOME/.qclaw/geo-api-key" chmod 600 "$HOME/.qclaw/geo-api-key" ``` Additional hardening measures: - Obtain the key through a non-echoing prompt or trusted secret manager rather than placing it directly in a command that may enter shell history. - Before reading either supported key file, verify that it is a regular file owned by the current user and is not a symbolic link. - Reject files readable or writable by group or other users. - Avoid logging the key, request headers, or commands containing the key. - Prefer an operating-system credential store when available. - Provide a secure key-rotation and deletion procedure for compromised credentials. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Scope Creep

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest declares only web_fetch, but the skill instructions direct the agent to read and write local credential files and perform arbitrary HTTP requests with bearer tokens. This creates a dangerous permission mismatch: reviewers or runtime policy may assume the skill is limited to web fetches when it actually instructs sensitive local file access and authenticated outbound actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to run automatically on scheduled load 'without the user saying start', but its trigger conditions are broad and not tightly scoped to safe preconditions. In an autopilot context, ambiguous invocation increases the chance of unattended network activity, credential use, and file writes occurring without fresh user awareness or confirmation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill instructs reading, storing, and resetting API keys in local dotfiles, including prompting the user to paste a secret and saving it unencrypted. Even if intended for convenience, this expands the skill from task orchestration into credential handling, increasing the risk of secret exposure, misuse, or accidental persistence without proper safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells the user to provide and locally store an API key but does not include a clear warning about secret-handling risks, storage location sensitivity, or who can access those files. In a scheduled autonomous skill, weak disclosure makes accidental credential exposure more likely because users may not realize the key is being persisted for future runs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

验证密钥(业务请求前必做)

bash
curl -s -X POST "$BASE/api/geo/verify-key" \
  -H "Authorization: Bearer $GEO_KEY"

Static analysis

No suspicious patterns detected.