Back to skill

Security audit

微博数据分析 SocialDataX 帖子详情

Security checks for vulnerabilities and agentic risk

Overview

The skill's Weibo lookup purpose is coherent, but it tells agents to run an unpinned npm package at runtime with an API key available.

Install only if you are comfortable with the agent downloading and executing the current npm release of `socialdatax-skills` when used. Prefer a pinned, reviewed package version, run it in a constrained environment, and expose only `SOCIALDATAX_API_KEY` rather than unrelated secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Execution of an Unpinned Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 6 and 27–35; related automatic-installation guidance at line 70
Vulnerability Type: Supply-chain risk caused by unpinned dependency retrieval and execution
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"📄","homepage":"https://socialdatax.com/ai?from=clawhub"}}
bash
npx -y socialdatax-skills@latest weibo detail \
  --post-id "<post_id>" --pretty --source-client socialdatax-skills \
  --source-platform clawhub --source-skill socialdatax-weibo-detail

npx -y socialdatax-skills@latest weibo detail \
  --post-url "<weibo_post_url_or_share_text>" --pretty \
  --source-client socialdatax-skills --source-platform clawhub \
  --source-skill socialdatax-weibo-detail

Related automatic-installation guidance:

text
If the current environment has permission, install or restore automatically.

Technical Analysis

The skill instructs the agent to retrieve and execute socialdatax-skills@latest through npx -y. The @latest selector does not identify an immutable, reviewed package version, while -y suppresses the normal installation confirmation. Consequently, the code executed during a future invocation can differ from the code that existed when this skill was audited.

The npm package implementation and its transitive dependencies are not included in the reviewed project, which contains only SKILL.md. The audit therefore cannot verify the external package's runtime behavior, network destinations, filesystem access, or handling of SOCIALDATAX_API_KEY. The issue is an unsafe supply-chain configuration rather than proof that the current package version is malicious.

Attack Path

  1. An attacker compromises the npm ...[truncated 1522 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace socialdatax-skills@latest with an exact, reviewed version such as socialdatax-skills@X.Y.Z.
  2. Commit a lockfile and use a reproducible installation workflow that verifies package integrity. Where supported, validate the expected registry tarball checksum before execution.
  3. Remove -y and automatic installation guidance, or require explicit user authorization before downloading and executing a package that is not already installed.
  4. Review the pinned package and relevant transitive dependencies before deployment. Re-run that review deliberately when upgrading versions.
  5. Configure npm to use an explicitly trusted registry and consider package provenance or signature verification.
  6. Run the CLI in a sandbox with minimal filesystem access, restricted outbound networking, no elevated privileges, and only the required environment variable.
  7. Avoid passing unrelated secrets or environment variables to the subprocess. Construct a minimal environment containing only SOCIALDATAX_API_KEY and essential runtime settings.
  8. Prefer shipping auditable, versioned implementation source with the skill, or provide a maintained wrapper that enforces version, integrity, environment, and permission restrictions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The activation text says to use this skill when the user wants 'content research' or 'a structured view of one Weibo post,' but 'content research' is a broad everyday request that could overlap with many non-Weibo tasks. The description does not provide negative examples or tighter trigger constraints to distinguish when this specific skill should and should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs the agent to execute npx -y socialdatax-skills@latest ..., which fetches and runs the latest package version at runtime without pinning to a reviewed release. This creates a supply-chain risk: if the package, a maintainer account, or a dependency is compromised, arbitrary code could execute in the agent environment with access to environment variables such as SOCIALDATAX_API_KEY.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This is a second runtime execution path using npx -y socialdatax-skills@latest, again allowing unreviewed code to be downloaded and executed on demand. Because the skill is designed to use an API key from the environment, a compromised package could exfiltrate secrets or run arbitrary commands under the agent's privileges.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The download-media example also uses npx -y socialdatax-skills@latest, so the same unpinned remote-code execution risk applies here. In addition, this command writes files locally, increasing the blast radius if a malicious package abuses filesystem access or manipulates output paths beyond the intended behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.