Back to skill

Security audit

Content Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate social-media analysis skill, but it needs Review because unsafe URL handling and network configuration could let untrusted links trigger broader local or network access than users would expect.

Install only if you are comfortable with the skill running a local Python script, sending analyzed platform identifiers and searches to TikHub, and making outbound network requests. It should be reviewed or fixed first to use shell-free execution, strict URL and redirect validation, clear third-party data disclosure, and respect for configured proxies.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:14
Finding

Shell Command Injection Through User-Controlled URL Interpolation

Content
View full analysis
" \``` ``` The profile-analysis instructions use the same pattern: ```markdown For profile analysis with limited posts: \```text python3 ~/.openclaw/skills/content-analyzer/scripts/analyze.py "" --max 20 \``` ``` ### Technical Analysis The Skill instructs the agent to place a URL extracted from an untrusted user message directly inside a shell command. Double quotes do not provide reliable shell escaping when the inserted value can itself contain quotation marks, command substitutions, or other shell syntax. For example, a malicious input containing a value conceptually similar to: ```text https://xiaohongshu.com/explore/example"; id; # ``` could produce: ```sh python3 ~/.openclaw/skills/content-analyzer/scripts/analyze.py "https://xiaohongshu.com/explore/example"; id; #" ``` If the `exec` implementation passes this string to a shell, the injected command is interpreted separately from the intended Python invocation. The Python script's own URL parsing cannot prevent this issue because shell interpretation occurs before the script receives its arguments. Whether exploitation succeeds depends on the execution tool's argument semantics. An execution API that invokes a process directly without a shell would prevent shell metacharacter interpretation. The documented command-string pattern, however, does not require or enforce shell-free execution and therefore exposes an unsafe execution path. ### Attack Path 1. An attacker sends a messag ...[truncated 1244 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze.py:133
Finding

Server-Side Request Forgery in Short-Link Resolution

Content
View full analysis
str: """Follow redirects on short links to get the final URL.""" if not url.startswith("http"): url = "https://" + url async with httpx.AsyncClient( follow_redirects=True, timeout=15, headers={"User-Agent": USER_AGENT}, proxy=None, ) as client: resp = await client.get(url) return str(resp.url) async def parse_url(raw_url: str) -> ParsedURL | None: """Parse a URL into platform/kind/identifier, resolving short links.""" url = raw_url.strip() if not url: return None # Resolve short links first if _XHS_SHORT_RE.search(url) or _DOUYIN_SHORT_RE.search(url): try: url = await _resolve_short_link(url) except httpx.HTTPError: return None ``` ### Technical Analysis The short-link checks search the complete input for the substrings `xhslink.com/` and `v.douyin.com/`. They do not parse the URL or verify that the URL's actual hostname is an approved short-link domain. An attacker can therefore place an approved-domain string in another URL component, such as the path: ```text http://127.0.0.1/xhslink.com/ ``` The regular expression matches this input even though the destination host is `127.0.0.1`. `_resolve_short_link()` then issues a request to that attacker-selected destination. The HTTP client also enables `follow_redirects=True` without validating each redirect target. Even if the initial hostname were checked correctly, an approved or attacker-controlled external endpoint could redirect the request to a loopback, private, link- ...[truncated 1964 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyze.py:17
Finding

Forced Removal of Deployment Proxy and Egress-Control Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
## Response Language

Always respond in the same language as the user's message. If the user writes in Chinese, respond in Chinese.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to invoke a local Python script via exec, and the script’s purpose implies network access to TikHub and possible environment access, but the manifest does not declare any explicit tool scope or allowed-tools restriction. This creates an authorization gap: the runtime may permit broader-than-intended capabilities, making command execution and outbound access less auditable and easier to abuse if the skill is triggered on attacker-controlled URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Short-link resolution sends user-supplied URLs to external hosts and follows redirects before any user-visible disclosure or consent. In this skill context, users may provide creator/profile links expecting local analysis, but the tool immediately performs network requests that reveal their interest in specific content and can contact attacker-controlled redirectors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The API client transmits note IDs, user IDs, video IDs, and search terms to TikHub without explicit disclosure at runtime. In a social-media analysis skill, this creates a real privacy and data-sharing risk because analyzed profiles, posts, and identifiers may be sensitive and are exposed to a third-party service outside the immediate tool boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says the skill analyzes Douyin creator profiles, but the implementation handles profile URLs by running a general Douyin search using the profile's sec_uid as a keyword. That can return unrelated videos and then aggregates them as if they belong to the requested profile, so the actual behavior is not reliably profile-specific analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

These formatted summary strings are hard-coded in Chinese, which forces a specific language in output regardless of user preference. The file does not provide locale selection or document a justified region-specific language constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring says the handler uses 'user info from a video or search to gather posts,' suggesting multiple strategies, but the code only calls douyin_search with the sec_uid keyword and never fetches user info from a video. This is an active mismatch between the documented intent and the implemented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.