Back to skill

Security audit

Ship Position

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent with HiFleet maritime and account workflows, but it needs review because it handles API keys, payment/account actions, and includes insecure endpoint and install practices.

Review before installing. Prefer the ClawHub or GitHub source, avoid the HTTP ZIP install path, set API base variables only to trusted HiFleet HTTPS hosts, do not paste full API keys or verification codes into casual chat, and require explicit confirmation before orders, subscription changes, invoices, refunds, contact retrieval for many rows, or console SSO links.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
hifleet-opentonnages/scripts/opentonnages_tool.py:46
Finding

API credentials and query data can be redirected to arbitrary network endpoints

Content
View full analysis
dict[str, Any]: api_key = os.environ.get("HIFLEET_API_KEY", "").strip() api_base = os.environ.get("HIFLEET_CHARTER_API_BASE", "").strip().rstrip("/") liner_base = os.environ.get("HIFLEET_LINER_API_BASE", "").strip().rstrip("/") enrich_url = os.environ.get("HIFLEET_CHARTER_ENRICH_URL", "").strip() cfg_path = default_skill_dir() / "config.json" if cfg_path.is_file(): try: cfg = json.loads(cfg_path.read_text(encoding="utf-8")) if isinstance(cfg, dict): api_key = api_key or str(cfg.get("hifleet_api_key") or "").strip() if not api_base: api_base = str(cfg.get("hifleet_charter_api_base") or "").strip().rstrip("/") if not liner_base: liner_base = str(cfg.get("hifleet_liner_api_base") or "").strip().rstrip("/") if not enrich_url: enrich_url = str(cfg.get("charter_enrich_url") or "").strip() except (json.JSONDecodeError, OSError): pass if not api_base: root = (os.environ.get("HIFLEET_API_BASE") or "https://api.hifleet.com").rstrip("/") api_base = root + "/openclaw/vessel/charter" if not liner_base: liner_base = DEFAULT_LINER_BASE if not enrich_url: enrich_url = DEFAULT_ENRICH_URL return { "api_key": api_key, "api_base": api_base.rstrip("/"), "liner_base": liner_base.rstrip("/"), "enrich_url": enrich_url, } ``` The resulting endpoints are used without scheme or hostname validation: ```python base = cfg["api_base"] url = f"{base}/{endpoint.lstrip('/')}?{urllib.parse.urlencode({'api_key': api_key})}" ``` ...[truncated 3439 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
hifleet-opentonnages/scripts/opentonnages_tool.py:133
Finding

API keys are transmitted in URL query strings

Content
View full analysis
dict[str, Any]: cfg = load_config() api_key = cfg["api_key"] if not api_key: return {"ok": False, "error": "missing hifleet_api_key"} base = cfg["api_base"] url = f"{base}/{endpoint.lstrip('/')}?{urllib.parse.urlencode({'api_key': api_key})}" ``` Port suggestion duplicates the credential in both the URL and a header: ```python qs = urllib.parse.urlencode( {"keyword": kw, "from": 0, "size": max(1, size), "api_key": api_key} ) url = f"{cfg['liner_base']}/ports/suggest?{qs}" headers = {"api_key": api_key} ``` Contact retrieval also places it in the URL: ```python qs = urllib.parse.urlencode( {"dataId": rid, "typeCode": type_code, "api_key": api_key} ) url = f"{base}/unlock?{qs}" ``` The same credential-in-query behavior appears in: - `scripts/get_archive.py:30-38` - `scripts/get_area_traffic.py:37-50` - `scripts/get_areas.py:30-38` when authenticated - `scripts/get_avoidredsea_traffic.py:35-43` when authenticated - `scripts/get_casualty.py:62-70` - `scripts/get_maritime_penalty.py:74` - `scripts/get_port.py:67-75` - `scripts/get_position.py:31-50` - `scripts/get_psc.py:33-50` - `scripts/get_psc_anomalies.py:96-134` - `scripts/get_psc_openclaw_stats.py:144` - `scripts/get_sanction.py:54` - `scripts/get_strait_traffic.py:44-52` when authenticated - `hifleet-opentonnages/scripts/opentonnages_tool.py:216-219,268-271,316` ### Technical Analysis URL query strings commonly enter reverse-proxy access logs, server logs, monitoring systems, tracing platforms, browser tooling, exception reports, and diagnosti ...[truncated 1391 chars]
Remediation
View remediation
` or the service-defined `x-api-key` header. 3. Do not duplicate credentials across query, body, and headers. 4. Update the backend API contract where necessary so all authenticated endpoints accept header-based credentials. 5. Redact authorization data and complete request URLs from errors, telemetry, and debug logs. 6. Ensure redirects do not forward credentials to another origin. 7. Rotate keys that may already have been recorded in access logs. 8. Review log retention and purge historical query strings containing API keys where operationally possible. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/open_console.py:32
Finding

Unvalidated server-provided console URL is printed and opened automatically

Content
View full analysis
dict: url = api_base + "/openclaw/account/session/from-api-key" body = json.dumps({"apiKey": api_key, "redirect": redirect}).encode("utf-8") req = urllib.request.Request( url, data=body, method="POST", headers={ "Content-Type": "application/json", "Authorization": "Bearer " + api_key, }, ) with urllib.request.urlopen(req, timeout=30) as resp: payload = json.loads(resp.read().decode("utf-8")) if str(payload.get("status")) not in ("1", "1.0"): raise RuntimeError(payload.get("msg") or payload.get("message") or "换票失败") data = payload.get("data") or {} if not data.get("consoleUrl"): raise RuntimeError("响应缺少 consoleUrl") return data ``` ```python console_url = data["consoleUrl"] print("userId=%s" % data.get("userId")) print("consoleUrl=%s" % console_url) if args.print_only: return 0 webbrowser.open(console_url) ``` ### Technical Analysis The documentation expects the returned URL to use HTTPS and the `skills.hifleet.com` host. The implementation verifies only that a non-empty `consoleUrl` exists. It does not check the scheme, hostname, port, path, or whether the URL contains unexpected credentials. `webbrowser.open` delegates the URL to the operating system. An arbitrary server response can therefore open a phishing site or invoke a registered non-HTTP URI handler. The issue is more readily exploitable because `HIFLEET_API_BASE` itself is unrestricted. The complete URL is also printed. Because the documented URL contains a short-lived authentication ticket, terminal capture, CI logs, support transcripts, and shell-session recording can dis ...[truncated 1188 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
FIRST_SETUP.md:5
Finding

Manual installation package is distributed over unsigned plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (119)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest presents the skill mainly as maritime intelligence, but it also documents console SSO, account/session exchange, and opening a console URL. Hidden or underemphasized authentication/session behavior is security-relevant because users may authorize actions beyond passive data retrieval and expose account access flows they did not expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest presents the skill mainly as maritime intelligence, but it also documents console SSO, account/session exchange, and opening a console URL. Hidden or underemphasized authentication/session behavior is security-relevant because users may authorize actions beyond passive data retrieval and expose account access flows they did not expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest presents the skill mainly as maritime intelligence, but it also documents console SSO, account/session exchange, and opening a console URL. Hidden or underemphasized authentication/session behavior is security-relevant because users may authorize actions beyond passive data retrieval and expose account access flows they did not expect.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
91% confidence
Finding

The 'Output rules' instruct the agent to disclose every non-empty, non-sensitive field from the API response, including record IDs and many operational details. In an LLM skill, this kind of embedded output directive can override normal minimization behavior and increase the chance of over-disclosure of sensitive commercial or location data, especially when classification of 'non-sensitive' is imperfect or API fields change over time.

Content

Scanner excerpt · hifleet-opentonnages/VESSEL_SEARCH_API.md (reported line 156)May include surrounding context.

md
- `shipCargoMatchBo`: `{ count, ids, matched }` → show when useful (`count` / `matched`).
- `senderInfoList`: contacts; default list = masked.

**Output rules** (see also **`WORKFLOW_OUTPUT.md`**):

- Show **every non-empty, non-sensitive field** from the catalog above + **record `id`**. Do **not** summarize down to only name/DWT/OPEN and drop the rest.
- Null / `"-"` / empty string / empty arrays may be omitted.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · hifleet-opentonnages/WORKFLOW_OUTPUT.md (reported line 1)May include surrounding context.

md
# Output rules

Follow **`USER_WORDING.md`**. Use **`LOCALIZATION.md`** for system/error text language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · hifleet-schedule/WORKFLOW_OUTPUT.md (reported line 1)May include surrounding context.

md
# Output rules

Follow **`USER_WORDING.md`**. Use **`LOCALIZATION.md`** for system/error text language.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/CARGO_SEARCH_API.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/CONFIG.example.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/ENRICH_OPENTONNAGES.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/PUBLISH.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/ROUTING_AND_WHEN.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/SKILL.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/SKILL_CONTEXT.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/USER_WORDING.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/VESSEL_SEARCH_API.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · hifleet-opentonnages/WORKFLOW_OUTPUT.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api_base.md (reported line 1)May include surrounding context.

md
# API 基址 / API Base URL

本技能内所有 HiFleet API 文档与 Agent 构造请求时,使用占位符 **`{base}`** 表示 API 根地址(**不含**末尾 `/`)。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title presents a bilingual heading, but the substantive setup instructions that follow are written almost entirely in Chinese. This creates a locale constraint for users without documenting that the skill is Chinese-language only or offering an opt-in or alternative language path.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file directs the agent to drive passwordless registration/login by collecting email or phone numbers and verification codes, which is outside the stated vessel-intelligence business scope and introduces identity/authentication handling. This creates risk of account takeover assistance, abuse of OTP workflows, and collection of sensitive contact data without clear scoping or safeguards.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup guide instructs the agent to participate in billing, payment-link generation, subscription management, and invoicing workflows, which materially expands the skill from vessel-intelligence into financial account operations. That broadening increases the chance of unauthorized purchases, phishing-like payment redirection, or mishandling of sensitive commercial/account data, especially if the agent is later invoked in loosely authenticated chat contexts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The guide instructs the agent to construct and send users a payment URL and to manage order/payment status, creating a transaction-redirection surface. Even though the example uses the vendor domain, payment-link handling is security-sensitive and can be abused for phishing, unauthorized charges, or confusion if the returned URL/path is not strictly validated.

Content

Scanner excerpt · FIRST_SETUP.md (reported line 104)May include surrounding context.

md
3. 用户选定后 `POST openclaw/billing/orders`:
   - 积分:`{ "orderType": "POINTS", "packageId": "pkg_advanced" }`
   - 订阅:`{ "orderType": "SUBSCRIPTION", "planId": "plan_max", "billingCycle": "MONTHLY" }`  
4. 将响应中的 **`paymentPageUrl`** 拼成完整链接发给用户(如 `https://api.hifleet.com/openclaw/payment.html?orderId=...`),用户在页内选微信或支付宝。  
5. 支付完成后查订单状态;积分单核对 `transactions`,订阅单核对 `billing/subscription`。  

**续费**:订阅到期前会收到邮件提醒(7/3/1 天),须**手动下单续费**,系统不会自动扣款。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares no explicit tool scope while the manifest and references indicate use of environment variables, file reads, and network access. Missing capability constraints increases the blast radius if the skill is invoked unexpectedly or if later content/scripts add broader behavior, because the host cannot enforce least privilege from the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest advertises maritime data functions but the documented implementation also includes onboarding, billing, invoicing, and console SSO. This broadens the trust boundary from read-only intelligence lookups to sensitive account operations, creating risk of user confusion, unintended account changes, or mishandling of payment/session data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes generic phrases like “位置” and “在哪”, which are common in everyday conversation and not specific to maritime vessel queries. In a manifest/markdown skill description, such broad triggers can cause unintended invocation when users ask ordinary location questions unrelated to this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Triggers such as “船舶信息” and “ship info” are broad and could match many general requests, especially in environments with multiple maritime or generic information skills. The description does not provide exclusion conditions or negative examples to distinguish when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
FIRST_SETUP.md:68

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:298