Back to skill

Security audit

Geo Mass Publish Check

Security checks for vulnerabilities and agentic risk

Overview

The skill’s stated workflow is coherent, but it automatically uses a local API key and writes downloaded ZIPs to paths built from remote task metadata without validation.

Review this before installing, especially for scheduled runs. Only use it with a GEO service and API key you trust, and prefer a version that sanitizes brand/product/cycle path components, verifies the final path stays under ~/.qclaw/geo-exports, avoids overwriting existing ZIPs unexpectedly, and builds JSON with a serializer.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:53
Finding

Unvalidated Remote Metadata Allows Path Traversal and Unintended File Writes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 53-60
Vulnerability Type: Path traversal, unsafe file-path construction, and unsafe JSON construction
Risk Level: Medium

bash
DIR="$HOME/.qclaw/geo-exports/${BRAND}_${PRODUCT}_C${CYCLE}/fanwen"
mkdir -p "$DIR"
curl -fsSL -o "$DIR/fanwen.zip" \
  "$BASE/api/geo/optimization/$OPT_ID/cycles/$CYCLE/export/fanwen.zip" \
  -H "Authorization: Bearer $GEO_KEY"
curl -s -X POST "$BASE/api/geo/optimization/$OPT_ID/cycles/$CYCLE/mass-publish-export" \
  -H "Authorization: Bearer $GEO_KEY" -H "Content-Type: application/json" \
  -d "{\"branch\":\"fanwen\",\"local_path_hint\":\"$DIR\"}"

Technical Analysis

The export directory incorporates BRAND, PRODUCT, and CYCLE, which are derived from task metadata returned by the remote service. The Skill does not require these values to be validated, sanitized, or canonicalized before using them as filesystem path components.

Shell quoting prevents the expanded values from being reinterpreted as shell commands, but it does not prevent path traversal. Values containing /, ../, or similar path components can cause the resolved directory to escape $HOME/.qclaw/geo-exports. The subsequent mkdir -p and curl -o operations would then create directories and write fanwen.zip at an unintended user-writable location.

The same path is inserted into a JSON body through manual string interpolation. If remote metadata contains quotation marks, backslashes, or control characters, the resulting body may be malformed or may change the structure or values of the JSON request.

Attack Path

  1. An attacker gains control of, or compromises, task metadata returned by the configured GEO API.
  2. The attacker supplies a crafted brand, product, or cycle value containing traversal components, such as ../../target.
  3. The Agent constructs DIR directly from the malicious value without validation.
  4. mkdir -p "$DIR" creates the attacker-selected directory ...[truncated 990 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use a trusted immutable task identifier for directory names instead of human-readable remote metadata where possible.
  2. Validate every path component against a strict allowlist, such as ^[A-Za-z0-9._-]+$.
  3. Explicitly reject path separators, .., control characters, empty values, and absolute paths.
  4. Canonicalize the final destination and verify that it remains beneath $HOME/.qclaw/geo-exports before creating directories or downloading files.
  5. Refuse to overwrite an existing ZIP unless replacement is explicitly intended and authorized.
  6. Construct the request body with a JSON serializer rather than manual interpolation. For example:
bash
payload=$(jq -n \
  --arg branch "fanwen" \
  --arg local_path_hint "$DIR" \
  '{branch: $branch, local_path_hint: $local_path_hint}')

curl -s -X POST \
  "$BASE/api/geo/optimization/$OPT_ID/cycles/$CYCLE/mass-publish-export" \
  -H "Authorization: Bearer $GEO_KEY" \
  -H "Content-Type: application/json" \
  --data-binary "$payload"
  1. Apply the same validation and containment checks to both the fanwen and fangxie export flows.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to read an API key from local credential files and download ZIP files onto the user's machine, but it does not require explicit user consent or warn about the privacy and filesystem impact. In an agent context, silent credential access plus local file writes can surprise users, leak sensitive business data into local storage, and expand the blast radius if the skill is installed broadly or runs on a schedule.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill downloads remote ZIP content to the local machine and then reports export state back to the external service using an authenticated request. While this aligns with the stated business workflow, it still performs external transmission and local persistence of potentially sensitive business assets without integrity checks, content validation, or strong user approval boundaries.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
CYCLE=<latestCycle.cycleNumber>
DIR="$HOME/.qclaw/geo-exports/${BRAND}_${PRODUCT}_C${CYCLE}/fanwen"
mkdir -p "$DIR"
curl -fsSL -o "$DIR/fanwen.zip" \
  "$BASE/api/geo/optimization/$OPT_ID/cycles/$CYCLE/export/fanwen.zip" \
  -H "Authorization: Bearer $GEO_KEY"
curl -s -X POST "$BASE/api/geo/optimization/$OPT_ID/cycles/$CYCLE/mass-publish-export" \

Static analysis

No suspicious patterns detected.