Back to skill

Security audit

Data Analysis Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it can upload arbitrary readable local files to a third-party service and generates chart HTML with unsafe remote-controlled content handling.

Review this before installing if you handle private spreadsheets, customer data, source code, credentials, or regulated data. Only pass files you intentionally want to upload to ChartGen, avoid sensitive datasets, use a limited API key, and treat generated HTML reports as untrusted unless the publisher fixes file scoping and HTML escaping.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/chartgen_api.py:146
Finding

Unrestricted Local File Upload to a Third-Party API

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/data_visualization.py:165
Finding

Remote Response Can Inject Executable Content into Generated Chart HTML

Content
View full analysis
{title}
''' ``` Remote response values are then interpolated into the HTML and executable script: ```python for i, option in enumerate(options): # Get chart title chart_title = option.get('title', {}).get('text', f'Chart {i+1}') charts_html.append(CHART_ITEM_TEMPLATE.format( title=chart_title, i=i )) scripts.append(CHART_SCRIPT_TEMPLATE.format( i=i, option=json.dumps(option, ensure_ascii=False, indent=12) )) ``` The generated JavaScript template places the serialized value directly inside a script element: ```python CHART_SCRIPT_TEMPLATE = ''' (function() {{ var chart{i} = echarts.init(document.getElementById('chart{i}')); var option{i} = {option}; chart{i}.setOption(option{i}); window.addEventListener('resize', function() {{ chart{i}.resize(); }}); }})(); ''' ``` ### Technical Analysis The ECharts option object originates from the remote API response. Its `title.text` value is inserted into an HTML element without HTML escaping, allowing markup injection. The complete option object is serialized with `json.dumps()` and inserted inside a `` can terminate the surrounding script element at the HTML parser level, even if that sequence occurs inside a JavaScript string literal. An attacker can then append a new HTML or script element. Consequently, a malicious, c ...[truncated 1534 chars]
Remediation
View remediation
` element or a separate JSON file. 4. Before embedding JSON in HTML, safely encode at least `<`, `>`, `&`, U+2028, and U+2029. 5. Read the protected text content and parse it using `JSON.parse()` at runtime. 6. Validate the API response against a strict ECharts option schema and reject unexpected types or properties. 7. Add a restrictive Content Security Policy that prohibits inline and unapproved scripts. 8. Where possible, render charts in a sandboxed environment without access to sensitive application origins. 9. Add tests containing payloads such as HTML tags, event handlers, and `` sequences to verify that generated output remains inert. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/data_visualization.py:35
Finding

Generated Reports Load a Mutable Third-Party JavaScript Dependency

Content
View full analysis
``` ### Technical Analysis Every generated chart loads executable JavaScript from jsDelivr when opened. The dependency is specified using the mutable major-version range `echarts@5`, rather than an exact immutable version. The script element also lacks a Subresource Integrity hash. As a result, the code executed by previously generated reports can change after the Skill itself has been audited. The effective payload depends on package resolution and CDN content at viewing time. HTTPS protects transport against ordinary network modification, but it does not protect against compromise of the package publisher, package registry, CDN infrastructure, or release process. ### Attack Path 1. The Skill generates an HTML chart containing the remote script reference. 2. The user opens the generated file while connected to the network. 3. The browser resolves `echarts@5` and downloads the currently served artifact from jsDelivr. 4. The upstream package, CDN, account, or release process is compromised, or an unsafe version is served within the allowed range. 5. The browser executes the altered JavaScript as part of the generated chart page. ### Impact Assessment A compromised dependency can execute arbitrary JavaScript in every generated report that loads it. Potential effects include: - Manipulation or falsification of displayed analytics. - Exfiltration of data included in the chart page. - Phishing or deceptive user-interface changes. - Requests to attacker-controlled or browser-reachable services. - Continued compromise of old reports because they resolve the remote dependency when opened. The impact remains within the browser execution context unle ...[truncated 59 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims a broader skill offering three major capabilities: analysis, interpretation, and visualization. However, the provided code only exposes a single interpretation workflow through data_interpretation.py. It parses input data from file or JSON and forwards the query/data to ChartGenAPI.interpret. There is no evidence in this chunk of statistical analysis, filtering, aggregation, calculations, or chart creation/plotting. The CHARTGEN_API_KEY prerequisite is consistent with the external API usage, but the functional scope represented by this code is materially narrower than the declared purpose. Therefore this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a broad 'data analysis pro' skill with three substantive functions: analysis, interpretation, and visualization. However, the provided code only implements visualization workflow. It parses input data references, sends the request to ChartGenAPI.visualize, extracts ECharts JSON from the response, and generates HTML for displaying charts. There is no code performing statistical analysis, filtering, aggregation, calculations, trend interpretation, pattern discovery, or report generation. The environment variable dependency on CHARTGEN_API_KEY aligns with the visualization portion of the description, but the overall declared scope materially overstates what this code chunk actually does. Therefore this is a description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares access to environment variables and describes reading local files, writing chart output, and sending data to a remote API, but it does not declare any explicit tool scope or permissions boundaries. This is dangerous because users and hosting platforms cannot clearly constrain or review what capabilities the skill may exercise, increasing the chance of over-broad file and network access during execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger keywords include generic phrases like 'calculate', 'visualize', and 'plot', which are common in ordinary conversations and can cause unintended invocation. In this skill's context, accidental activation is more dangerous because invocation may lead to local file handling and transmission of user data to an external API without the user intending to use this specific remote service.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
81% confidence
Finding

The phrase 'automatically execute' indicates autonomous processing of user-supplied data and query interpretation, including generating SQL and sending content to a remote analytics service. In this context, autonomy increases risk because misinterpretation or silent execution could process or exfiltrate sensitive files without a deliberate review step by the user.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
## Overview

This skill enables codeless data analysis through natural language interaction. It supports Text2SQL, Text2Data, and Text2Code analysis. Simply provide Excel/CSV files or JSON data to automatically execute data queries, data interpretation, and data visualization (ChatBI).

The skill will intelligently parse time, metrics, and analytical dimensions through conversational queries, then generate SQL queries for data, create interactive BI charts, structured analysis reports. Optimized for standardized vertical datasets, powered by enterprise-grade analytics engine for reliable results.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code base64-encodes and uploads the entire contents of a local file to a third-party API service, but the method-level interface and behavior do not provide an explicit user-facing disclosure or consent step at the point of exfiltration. In a data-analysis skill, users may supply sensitive spreadsheets or CSVs, so silent remote transfer can expose confidential business or personal data to an external provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The client sends provided JSON data to a remote API endpoint without clearly documenting that this input leaves the local environment. Although transmitting JSON to a cloud analysis service is expected functionally, the lack of explicit disclosure can lead to accidental sharing of sensitive structured data such as customer records, metrics, or internal reports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code automatically creates /tmp/openclaw/charts/...html and writes rendered output when chart options are present, even if the user did not supply --output. Although it prints the saved path afterward, there is no prior warning in the CLI help or a confirmation before performing the file write.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.