Back to skill

Security audit

Acp

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real ACP messaging skill, but it installs mutable code, changes persistent OpenClaw configuration, exposes a generated password, publishes local profile data, and grants broad access by default.

Install only after reviewing the ACP plugin source and pinning a trusted revision. Do not leave allowFrom as ["*"] unless you intentionally want public inbound messages, do not share or paste seedPassword in chat/logs, preview any agent.md before upload, back up OpenClaw config before changes, and reduce operator scopes to the minimum needed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
resources/install.md:36
Finding

Unpinned Remote Plugin and Dependency Retrieval Can Execute Mutable External Code

Content
View full analysis

Vulnerability Details

File Location: resources/install.md, lines 36-43
Vulnerability Type: Mutable remote code retrieval and unsafe dependency installation
Risk Level: High

Vulnerable Snippet

bash
# Existing installation
cd ~/.openclaw/extensions/acp
git pull

# New installation sources
git clone https://github.com/coderXjeff/openclaw-acp-channel.git ~/.openclaw/extensions/acp

# Fallback source
git clone https://gitee.com/yi-kejing/openclaw-acp-channel.git ~/.openclaw/extensions/acp

# Dependency installation
cd ~/.openclaw/extensions/acp
npm install

Technical Analysis

The installation workflow retrieves the current contents of a mutable remote branch using git pull or git clone. It does not pin an audited commit, verify a signed release, or validate a checksum. Consequently, the effective plugin payload can change after this Skill has been reviewed.

The subsequent npm install operation may execute package lifecycle scripts, including preinstall, install, and postinstall. A malicious upstream commit or compromised dependency can therefore execute arbitrary code with the permissions of the OpenClaw user.

The fallback repository is hosted under a different account and no cryptographic equivalence or trust relationship with the primary repository is established.

Attack Path

  1. An attacker compromises the primary repository, fallback mirror, maintainer account, or an unpinned npm dependency.
  2. The attacker adds malicious plugin code or a dependency lifecycle script.
  3. A user follows the installation or update workflow.
  4. git pull or git clone retrieves the attacker-controlled revision.
  5. npm install executes the malicious lifecycle script, or OpenClaw loads the malicious plugin after restart.
  6. The payload executes under the OpenClaw user's local privileges.

Impact Assessment

Successful exploitation can provide arbitrary code execution ...[truncated 238 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin installation to a specific audited commit hash or signed release tag.
  2. Verify a published SHA-256 checksum or cryptographic release signature before installation.
  3. Commit and enforce a dependency lockfile, and use npm ci instead of npm install.
  4. Initially install dependencies with npm ci --ignore-scripts; explicitly review and allow only required lifecycle scripts.
  5. Remove the fallback mirror or independently verify that its selected commit exactly matches the trusted upstream commit.
  6. Run plugin installation and build operations in a sandbox with restricted filesystem and network access.
  7. Do not automatically restart or load the plugin until integrity verification succeeds.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
resources/multi-identity.md:229
Finding

ACP Identities Are Granted Excessive Operator Administration and Pairing Scopes

Content
View full analysis

Vulnerability Details

File Location: resources/multi-identity.md, lines 229-248
Vulnerability Type: Excessive privilege assignment
Risk Level: High

Vulnerable Snippet

json
{
  "id": "<NEW_UUID>",
  "label": "<agentId>",
  "role": "operator",
  "scopes": [
    "operator.admin",
    "operator.approvals",
    "operator.pairing"
  ],
  "isDefault": false,
  "createdAtMs": "<current timestamp in milliseconds>",
  "lastActiveAtMs": "<current timestamp in milliseconds>",
  "channels": ["acp"]
}

Technical Analysis

The identity-creation instructions assign operator.admin, operator.approvals, and operator.pairing to every newly created ACP identity. These permissions are substantially broader than the messaging and UI-display functions described by the workflow.

This violates least privilege because an identity intended to communicate over ACP receives gateway administration, approval, and device-pairing authority without a separate authorization decision. Merely setting isDefault to false does not reduce the granted scopes.

Attack Path

  1. A new ACP identity is created using the documented procedure.
  2. The procedure writes broad operator scopes into the device identity file.
  3. The identity's credentials, session, routing context, or associated agent is compromised.
  4. The attacker invokes functionality allowed by operator.admin, operator.approvals, or operator.pairing.
  5. The attacker administers gateway functions, approves protected actions, or pairs additional devices, subject to the enforcement behavior of the host platform.

Impact Assessment

A compromised identity may obtain administrative access beyond ACP messaging, approve sensitive operations, or authorize additional device pairing. The scope can extend from one communication identity to broader control of the OpenClaw gateway and its configured agents.

Remediation
View remediation

Remediation Suggestions

  1. Define and assign a minimal ACP-specific scope that permits only required messaging and identity-list operations.
  2. Do not grant operator.admin, operator.approvals, or operator.pairing by default.
  3. Require explicit, separate user confirmation for each privileged scope.
  4. Separate communication identities from gateway administrative identities.
  5. Validate the resulting identity file and reject unexpected privileged scopes.
  6. Document a scope-revocation and credential-rotation procedure for existing identities.
  7. Audit all previously created ACP identities and remove unnecessary permissions.

T09 · Insecure Skill Coding Practices

Warning
Location
resources/multi-identity.md:209
Finding

Generated ACP Seed Password Is Printed and Included in the Final Report

Content
View full analysis

Vulnerability Details

File Location: resources/multi-identity.md, lines 209-211; resources/install.md, lines 245-252
Vulnerability Type: Sensitive credential exposure through terminal and agent output
Risk Level: Medium

Vulnerable Snippets

bash
# Generate seedPassword
SEED=$(openssl rand -hex 16)
echo "seedPassword: $SEED"

The required completion report also includes the generated value:

text
Automatically generated:
- seedPassword: {SEED_PASSWORD}
- allowFrom: ["*"]
- displayName: {displayName}

Technical Analysis

The password is cryptographically generated, but the workflow immediately writes it to standard output and requires the agent to reproduce it in the final completion report. Terminal output, shell transcripts, API conversation logs, observability systems, and support records are commonly retained longer and exposed more broadly than credential stores.

This changes a locally generated secret into transcript data. The documentation also states that the seed password is used to protect ACP identity key material, increasing the sensitivity of the exposed value.

Attack Path

  1. The installation process generates a seed password.
  2. echo prints the plaintext value to terminal output.
  3. The agent repeats the plaintext value in its final report.
  4. A terminal recorder, conversation logger, monitoring system, support export, or unauthorized reader accesses the retained output.
  5. The reader recovers the ACP seed password and attempts to use it with the associated identity or encrypted key material.

Impact Assessment

Exposure can compromise the confidentiality of the ACP identity credential and weaken protection of associated private-key material. The precise ability to impersonate the identity depends on what additional certificate or local key material the attacker can access, but the disclosed password materially reduces the identity's security.

Remediation
View remediation

Remediation Suggestions

  1. Remove the echo command and never place the seed password in the final agent response.
  2. Write the secret directly to the protected configuration or credential store.
  3. Restrict configuration and key files to the owning user, such as mode 0600, and verify permissions after writing.
  4. Redact the value in logs and reports, displaying only a non-sensitive status such as “generated and stored.”
  5. Avoid passing the secret through command-line arguments or environment variables that may be observable by other processes.
  6. Provide credential rotation and identity recovery procedures.
  7. Warn existing users to rotate seed passwords that may already have been captured in transcripts.

T09 · Insecure Skill Coding Practices

Warning
Location
resources/install.md:103
Finding

ACP Messaging Is Configured to Accept Unsolicited Input from Every Sender by Default

Content
View full analysis

Vulnerability Details

File Location: resources/install.md, lines 103-104 and 122-124
Vulnerability Type: Unsafe network-facing access-control default
Risk Level: Medium

Vulnerable Snippets

text
- SEED_PASSWORD: generate 32 hexadecimal characters using crypto.randomBytes(16)
- allowFrom: ["*"]
- displayName: convert agentName to spaces and capitalize the first letter
text
- seedPassword: {SEED_PASSWORD}
- ownerAid: {OWNER_AID}
- allowFrom: ["*"]

The access-control meaning is documented in resources/permissions.md, lines 8-14:

text
["*"] — accept messages from everyone by default.
A list of specific AIDs — accept messages only from listed senders.
Messages from non-allowed AIDs are silently rejected and logged.

Technical Analysis

The installation procedure enables a network-facing communication channel with a wildcard sender allowlist. Any ACP identity can therefore initiate sessions and provide attacker-controlled text to the agent.

External senders are documented as conversation-only and restricted from direct file operations, configuration changes, and commands. Those restrictions reduce direct privilege, but they do not eliminate model-level prompt injection, social engineering, session flooding, unwanted contact creation, or resource exhaustion. The wildcard is an unsafe default because trust is granted before sender review.

Attack Path

  1. A user installs the plugin using the default allowFrom: ["*"] configuration.
  2. An attacker discovers or already knows the public AID.
  3. The attacker sends crafted ACP messages or opens many sessions.
  4. The messages enter the model's conversational context and the sender is automatically added as a contact.
  5. The attacker attempts prompt injection, deceptive requests, repeated session creation, or resource consumption.
  6. Any weakness in downstream instruction separation or authorization checks may ...[truncated 378 chars]
Remediation
View remediation

Remediation Suggestions

  1. Default allowFrom to an empty list rather than ["*"].
  2. Require explicit approval before adding each remote AID.
  3. Provide an interactive review step that explains the consequences of wildcard access.
  4. Apply per-sender and global rate limits, session quotas, message-size limits, and abuse throttling.
  5. Keep external messages explicitly labeled as untrusted data in the model context.
  6. Ensure external messages cannot change authorization state, configuration, identity files, memory, or workspace instructions.
  7. Log rejected and rate-limited attempts without recording unnecessary message contents or secrets.

T09 · Insecure Skill Coding Practices

Warning
Location
resources/agent-md.md:98
Finding

Workspace Operational Metadata Is Automatically Included in a Public Agent Profile

Content
View full analysis

Vulnerability Details

File Location: resources/agent-md.md, lines 98-112
Vulnerability Type: Excessive collection and automatic publication of local metadata
Risk Level: Medium

Vulnerable Snippet

text
Workspace source        Extracted content
----------------------  -----------------------------------------
IDENTITY.md             name, emoji, creature, and vibe
SOUL.md                 description and aboutMe
AGENTS.md               capabilities
TOOLS.md                tool information
HEARTBEAT.md            active-task metrics
USER.md                 timezone and language
workspace/skills        skill summaries

The publication behavior is documented at resources/agent-md.md, lines 61-77:

text
ACP automatically uploads agent.md when a connection is established.
After upload, it is accessible at:
https://{agentName}.agentcp.io/agent.md

Technical Analysis

Workspace mode automatically builds agent.md from multiple local files. Some sources are reasonably related to public identity, but tool information, active-task metrics, locale information, and installed skill summaries reveal operational details beyond the minimum identity-card fields.

Because synchronization is automatic and the resulting profile is publicly accessible, users may not receive a field-level review opportunity before local metadata is published. Hash-based change detection prevents redundant uploads but does not provide confidentiality or consent controls.

Attack Path

  1. A user enables ACP while operating in workspace mode.
  2. The plugin reads identity, behavior, tool, heartbeat, user-locale, and skill metadata.
  3. The plugin generates an agent.md profile from those sources.
  4. Connection establishment triggers automatic upload.
  5. An external party retrieves the public profile URL.
  6. The party uses disclosed tools, capabilities, activity patterns, locale, or installed skills ...[truncated 495 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit opt-in for each workspace source and each published field.
  2. Limit default profile generation to a strict public allowlist such as name, description, type, version, and user-approved tags.
  3. Exclude TOOLS.md, HEARTBEAT.md, USER.md, and skill inventories by default.
  4. Display a complete preview and require confirmation before the first upload.
  5. Detect and redact secrets, local paths, internal hostnames, task details, and unique identifiers.
  6. Provide a dry-run mode and a clear mechanism to disable automatic synchronization.
  7. Warn users that the generated file is publicly accessible and provide deletion and cache-invalidation procedures.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
- **[多身份模式](./resources/multi-identity.md)** — 多 Agent 多 AID 架构,agents.list 定义、identity 绑定、人格隔离、workspace 配置、身份创建/删除全流程。

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly generate a seedPassword, persist it into configuration, and later require reporting it back in the completion summary. That exposes a credential in plaintext through agent output, logs, chat history, or screenshots, increasing the chance of account takeover or unauthorized ACP identity use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs editing agent.md and then syncing it to the ACP network, where it becomes outward-facing profile data, but it gives no privacy or disclosure warning. Users may unintentionally publish sensitive information such as personal identifiers, capabilities, internal metadata, or operational details to an external network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the agent to edit ~/.openclaw/openclaw.json, including permission-related fields such as ownerAid and allowFrom, and says changes take effect after restart, but it does not require an explicit user confirmation or warn that this modifies persistent local system state. That creates a real risk of unauthorized or unsafe configuration changes, especially because permissive values like allowFrom: ["*"] could broaden who can interact with the agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document states that agent.md is automatically uploaded when an ACP connection is established, but it does not clearly warn users that profile data may be transmitted externally by default. Because agent.md can contain identifying metadata and is published at a public URL, users may unintentionally expose personal or operational information without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workspace mode section explains that agent.md is auto-generated from multiple local workspace files and then uploaded, but it does not prominently warn that local content from files like IDENTITY.md, SOUL.md, AGENTS.md, TOOLS.md, HEARTBEAT.md, and skill summaries may be derived and published. Even with partial privacy filtering for USER.md, this behavior can disclose sensitive metadata, capabilities, tasks, or organizational context if users do not realize the upload is automatic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation presents security-sensitive fields such as seedPassword, ownerAid, and especially permissive allowFrom behavior including ['*'] without clearly warning about the security consequences. In a configuration reference for a messaging/channel plugin, this can normalize insecure defaults or examples and lead users to grant overly broad access or mishandle credentials, increasing the chance of unauthorized interaction or account compromise.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · resources/config-reference.md (reported line 163)May include surrounding context.

md
| `PREFLIGHT_FAIL` + `is used by another user` | AID 被占用 | 更换 `agentName` |
| `PREFLIGHT_FAIL` + `signIn` | AID 已存在但密码不匹配 | 使用正确 `seedPassword` 或更换 `agentName` |
| `PREFLIGHT_FAIL` + `TIMEOUT` | 网络不可达 | 检查网络/代理 |
| `/acp` skill 不可用 | 插件未启用或 skill 未加载 | 检查 `plugins.entries.acp.enabled` 与 `skill/acp/SKILL.md` |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · resources/install.md (reported line 218)May include surrounding context.

md
| `PREFLIGHT_FAIL` + `is used by another user` | AID 被占用 | 更换 `agentName` |
| `PREFLIGHT_FAIL` + `signIn` | AID 已存在但密码不匹配 | 使用正确 `seedPassword` 或更换 `agentName` |
| `PREFLIGHT_FAIL` + `TIMEOUT` | 网络不可达 | 检查网络/代理 |
| `/acp` skill 不可用 | 插件未启用或 skill 未加载 | 检查 `plugins.entries.acp.enabled` 与 `skill/acp/SKILL.md` |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that receiving a message from a new AID will automatically create a contact record and initialize trust metadata without any explicit warning, consent, or mention of user-visible controls. Because the same document also describes automatic appending of AI-generated session summaries to contact notes, the skill normalizes silent state changes to user data based on untrusted inbound activity, which can lead to unwanted persistence, privacy issues, and contact-list poisoning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that pulled group messages are automatically persisted locally in a JSONL file, but it does not clearly warn users that potentially sensitive chat content will be stored on disk. In a messaging/group-chat context, silent local retention increases the risk of unintended disclosure through shared machines, backups, endpoint compromise, or operators assuming messages are only transient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The dissolve_group operation is documented as a normal action without emphasizing that it is destructive and may be irreversible. In a group-management tool, lack of a clear warning can lead to accidental deletion of group state, loss of access or coordination, and administrative misuse by users who do not appreciate the consequence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installation flow instructs cloning remote repositories, running npm install, and later performing an ACP network precheck, but it does not provide an upfront warning that outbound network access will occur. This matters because it causes code retrieval and dependency resolution from external sources, which may disclose environment metadata and introduce supply-chain risk without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill directs the agent to back up and modify ~/.openclaw/openclaw.json and create agent.md under the user's home directory without an upfront warning that local files will be changed. In an agentic setting, undisclosed filesystem writes can violate user expectations, overwrite sensitive configuration, or make recovery harder if the merge/restore logic fails.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The completion template includes 'seedPassword: {SEED_PASSWORD}', which instructs the agent to reveal a generated secret directly to the user in plaintext. Even if intended for convenience, plaintext secret disclosure is dangerous because agent conversations are often retained in logs, memory, or shared transcripts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file presents all user-facing instructions in Chinese and does not indicate that the language is optional, configurable, or limited to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document says multi-identity mode achieves '完全独立' across three layers and specifically describes personality isolation as each identity being bound to one agent/workspace. However, L0406-L0408 states the ACP plugin supports per-identity agent.md overrides from workspace/identities/{identityId}/IDENTITY.md, which means identity presentation can vary within a shared workspace and is not purely enforced by separate workspaces as earlier described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to generate and echo the seedPassword directly to the terminal, which risks exposing a credential used to encrypt or unlock AID private key material. Terminal output may be captured in scrollback, shell logging, screen recording, remote support sessions, or operational notes, increasing the chance of secret disclosure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · resources/multi-identity.md (reported line 270)May include surrounding context.

bash
# 方式 A:使用 agents.list[].workspace 配置的自定义路径
WORKSPACE_DIR=~/.openclaw/workspace-funny-bot
mkdir -p "$WORKSPACE_DIR"

# 方式 B:省略 workspace 配置,核心代码自动分配
# 非默认 Agent 的默认路径为 ~/.openclaw/workspace-{agentId}

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · resources/multi-identity.md (reported line 270)May include surrounding context.

bash
# 方式 A:使用 agents.list[].workspace 配置的自定义路径
WORKSPACE_DIR=~/.openclaw/workspace-funny-bot
mkdir -p "$WORKSPACE_DIR"

# 方式 B:省略 workspace 配置,核心代码自动分配
# 非默认 Agent 的默认路径为 ~/.openclaw/workspace-{agentId}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown describes deleting agent definitions, identity mappings, and the workspace directory, which can permanently remove persona and configuration data. Although it mentions asking before restart and notes some files are not auto-deleted, it does not clearly warn that these deletions are destructive and should be backed up or confirmed before proceeding.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broad enough to trigger on generic mentions of ACP data, rankings, search, or agent profiles, which can cause the agent to invoke this skill unexpectedly. Because the skill directs use of external network requests via curl, an accidental invocation can send user-derived queries to a third-party service without sufficiently narrow intent matching.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · resources/rank.md (reported line 293)May include surrounding context.

bash
# GET
curl -s "https://agentunion.net/search/text?q=助手&tags=assistant,chat&page=1&page_size=10"
# POST
curl -s -X POST "https://agentunion.net/search/text" \
  -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · resources/rank.md (reported line 332)May include surrounding context.

bash
# GET
curl -s "https://agentunion.net/search/vector?q=我需要写代码的助手&limit=10"
# POST
curl -s -X POST "https://agentunion.net/search/vector" \
  -H "Content-Type: application/json" \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The operational instructions are presented entirely in Chinese, which can impose a fixed language on users without documented opt-in. The file does not indicate that Chinese is required for a region-specific reason or provide an alternative language option.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.