T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/chartgen_api.py:146- Finding
Unrestricted Local File Upload to a Third-Party API
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but it can upload arbitrary readable local files to a third-party service and generates chart HTML with unsafe remote-controlled content handling.
Review this before installing if you handle private spreadsheets, customer data, source code, credentials, or regulated data. Only pass files you intentionally want to upload to ChartGen, avoid sensitive datasets, use a limited API key, and treat generated HTML reports as untrusted unless the publisher fixes file scoping and HTML escaping.
scripts/chartgen_api.py:146Unrestricted Local File Upload to a Third-Party API
scripts/data_visualization.py:165Remote Response Can Inject Executable Content into Generated Chart HTML
scripts/data_visualization.py:35Generated Reports Load a Mutable Third-Party JavaScript Dependency
The description claims a broader skill offering three major capabilities: analysis, interpretation, and visualization. However, the provided code only exposes a single interpretation workflow through data_interpretation.py. It parses input data from file or JSON and forwards the query/data to ChartGenAPI.interpret. There is no evidence in this chunk of statistical analysis, filtering, aggregation, calculations, or chart creation/plotting. The CHARTGEN_API_KEY prerequisite is consistent with the external API usage, but the functional scope represented by this code is materially narrower than the declared purpose. Therefore this is a description-behavior mismatch.
The description presents a broad 'data analysis pro' skill with three substantive functions: analysis, interpretation, and visualization. However, the provided code only implements visualization workflow. It parses input data references, sends the request to ChartGenAPI.visualize, extracts ECharts JSON from the response, and generates HTML for displaying charts. There is no code performing statistical analysis, filtering, aggregation, calculations, trend interpretation, pattern discovery, or report generation. The environment variable dependency on CHARTGEN_API_KEY aligns with the visualization portion of the description, but the overall declared scope materially overstates what this code chunk actually does. Therefore this is a description-to-behavior mismatch.
The skill declares access to environment variables and describes reading local files, writing chart output, and sending data to a remote API, but it does not declare any explicit tool scope or permissions boundaries. This is dangerous because users and hosting platforms cannot clearly constrain or review what capabilities the skill may exercise, increasing the chance of over-broad file and network access during execution.
The trigger keywords include generic phrases like 'calculate', 'visualize', and 'plot', which are common in ordinary conversations and can cause unintended invocation. In this skill's context, accidental activation is more dangerous because invocation may lead to local file handling and transmission of user data to an external API without the user intending to use this specific remote service.
The phrase 'automatically execute' indicates autonomous processing of user-supplied data and query interpretation, including generating SQL and sending content to a remote analytics service. In this context, autonomy increases risk because misinterpretation or silent execution could process or exfiltrate sensitive files without a deliberate review step by the user.
## Overview
This skill enables codeless data analysis through natural language interaction. It supports Text2SQL, Text2Data, and Text2Code analysis. Simply provide Excel/CSV files or JSON data to automatically execute data queries, data interpretation, and data visualization (ChatBI).
The skill will intelligently parse time, metrics, and analytical dimensions through conversational queries, then generate SQL queries for data, create interactive BI charts, structured analysis reports. Optimized for standardized vertical datasets, powered by enterprise-grade analytics engine for reliable results.
The code base64-encodes and uploads the entire contents of a local file to a third-party API service, but the method-level interface and behavior do not provide an explicit user-facing disclosure or consent step at the point of exfiltration. In a data-analysis skill, users may supply sensitive spreadsheets or CSVs, so silent remote transfer can expose confidential business or personal data to an external provider.
The client sends provided JSON data to a remote API endpoint without clearly documenting that this input leaves the local environment. Although transmitting JSON to a cloud analysis service is expected functionally, the lack of explicit disclosure can lead to accidental sharing of sensitive structured data such as customer records, metrics, or internal reports.
This code automatically creates /tmp/openclaw/charts/...html and writes rendered output when chart options are present, even if the user did not supply --output. Although it prints the saved path afterward, there is no prior warning in the CLI help or a confirmation before performing the file write.
No suspicious patterns detected.