Back to skill

Security audit

Xhs Crafter

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Markdown-to-image purpose, but it needs review because its local renderer disables Chromium sandboxing and its image-download workflow is less restricted than claimed.

Install only after reviewing these risks. Prefer a pinned ClawHub installer version, use the skill on trusted Markdown and image inputs, avoid optional image search or AI generation for sensitive drafts, and enable Feishu upload only when you are comfortable sending the generated files to that cloud account.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
README.md:41
Finding

Mutable Package Execution Through Unpinned npx Installation Command

Content
View full analysis

Vulnerability Details

File Location: README.md:41
Vulnerability Type: Supply-chain exposure through mutable package execution
Risk Level: High

Vulnerable Code

bash
npx clawhub@latest install EdwardWason/xhs-crafter

Technical Analysis

The documented installation command instructs npx to retrieve and execute the package currently associated with the mutable latest tag. Neither an exact package version nor an integrity digest is specified.

Consequently, the code executed during installation is not limited to the package version covered by this audit. The effective installer can change after review if a new release is published or if the package registry account, package namespace, or dependency chain is compromised.

This is a supply-chain weakness rather than evidence that the currently audited repository contains an intentionally malicious dependency.

Attack Path

  1. An attacker compromises the clawhub package, its publishing account, or a transitive dependency used by a future release.
  2. The malicious release is assigned the latest distribution tag.
  3. A user follows the Quick Start command from the README.
  4. npx downloads the unaudited mutable release.
  5. The package's CLI, initialization logic, or dependency code executes with the privileges of the user running the command.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the malicious package could access user-readable files, environment variables, project credentials, network services, and writable application data.

The command does not itself request administrator privileges, so the direct scope is normally limited to the invoking user's permissions.

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed package version, for example clawhub@X.Y.Z.
  • Publish and document expected package integrity hashes or signed release artifacts.
  • Instruct users to verify the package publisher and release signature before installation.
  • Use a lockfile for development and deployment dependencies.
  • Avoid commands that automatically execute newly downloaded packages where a verified local installer or pinned package can be used.
  • Review each package update before changing the documented pinned version.

T09 · Insecure Skill Coding Practices

Error
Location
assets/screenshot.js:108
Finding

Chromium Sandbox Disabled While Rendering Generated HTML

Content
View full analysis

Vulnerability Details

File Location: assets/screenshot.js:108-117
Vulnerability Type: Unsafe browser isolation configuration
Risk Level: High

Vulnerable Code

javascript
const browser = await puppeteer.launch({
  executablePath: chromePath,
  headless: true,
  args: [
    '--no-sandbox',
    '--disable-setuid-sandbox',
    '--disable-cache',
    '--disable-application-cache',
    '--disable-offline-load-stale-cache',
  ],
});

Technical Analysis

The screenshot process explicitly disables both Chromium's general sandbox and setuid sandbox. The browser loads an index.html file assembled for the current project, including content and local assets derived from user input.

No HTML sanitizer, restrictive Content Security Policy, or Puppeteer request-interception policy is implemented in the screenshot script. Therefore, if active HTML, script-capable markup, or a malicious local asset reaches the generated page, it is processed by a browser running without its normal process-isolation boundary.

Disabling the browser sandbox does not by itself guarantee code execution. Exploitation would require active content to survive composition or a browser vulnerability. However, removing the sandbox materially increases the impact of any renderer compromise and exceeds the minimum privileges normally necessary for local screenshot generation.

Attack Path

  1. An attacker supplies crafted article content or an asset intended to introduce active browser content into the generated index.html.
  2. The composition process preserves or inserts the malicious content without sufficient sanitization.
  3. assets/screenshot.js launches Chromium with both sandbox mechanisms disabled.
  4. Puppeteer navigates to the generated page through the local HTTP server.
  5. Malicious page logic initiates network requests, or a browser vulnerability is triggered.
  6. A successful renderer compromise runs wi ...[truncated 661 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove --no-sandbox and --disable-setuid-sandbox.
  • If sandboxed Chromium cannot run in the target environment, perform rendering inside a dedicated container, virtual machine, or low-privilege operating-system account with no sensitive mounts.
  • Sanitize all article-derived HTML before inserting it into the template.
  • Encode user text according to its HTML context rather than copying raw markup.
  • Add a restrictive Content Security Policy that blocks scripts, plugins, remote connections, frames, and navigation.
  • Enable Puppeteer request interception and permit only the selected loopback origin and expected local assets.
  • Reject remote URLs and active elements such as scripts, iframes, objects, embeds, forms, event-handler attributes, and javascript: URLs.
  • Use an up-to-date, explicitly supported Chromium build and regularly apply browser security updates.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:153
Finding

Redirect-Following Image Downloads Do Not Enforce the Documented Host Allowlist

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:153-166
Vulnerability Type: Unrestricted redirected download and potential server-side request forgery
Risk Level: Medium

Vulnerable Code

bash
curl.exe -L -o "assets/cover.jpg" "URL"

The same unrestricted download pattern is repeated for locally stored background images:

bash
curl.exe -L -o "assets/cover.jpg" "URL"

Technical Analysis

The primary Skill workflow instructs the Agent to run curl.exe against a dynamically selected URL and enables redirect following with -L. This command does not enforce the documented ALLOWED_HOSTS restriction and does not validate redirect destinations.

A safer allowlist-based Node.js example appears in references/image-sources.md, but it is documentation only and is not invoked by the operative workflow. The primary Skill and references/workflow.md continue to direct the Agent to use unrestricted curl.

User consent to perform image search authorizes the intended external image service; it does not safely authorize requests to arbitrary redirect destinations or internal network addresses.

Attack Path

  1. The user explicitly approves an external image-search capability.
  2. A compromised image API, manipulated response, malicious CDN endpoint, or altered redirect returns an attacker-controlled location.
  3. The Agent passes that URL to curl.exe -L.
  4. curl follows one or more redirects without checking the destination hostname or resolved address.
  5. The request reaches a non-approved external host or an address accessible only from the user's environment.
  6. The response is written to assets/cover.jpg and may subsequently be processed by Chromium as an image asset.

Impact Assessment

The request may expose network reachability and request metadata to an unintended destination. It could also be used to probe services reachable from the user's machine, including internal ...[truncated 550 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the manual unrestricted curl.exe -L workflow.
  • Implement and commit a single downloader that validates both the initial URL and every redirect destination.
  • Permit HTTPS only.
  • Restrict hostnames to an explicit allowlist such as the required Pexels and Unsplash image hosts.
  • Resolve each hostname and reject loopback, private, link-local, multicast, reserved, and cloud-metadata address ranges.
  • Revalidate the hostname and resolved address after every redirect.
  • Set strict redirect-count, connection-timeout, response-size, and download-time limits.
  • Validate HTTP status codes and accepted image content types before saving.
  • Verify image signatures rather than relying only on file extensions or response headers.
  • Write to a temporary file and atomically rename it only after successful validation.
  • Keep downloaded content in a per-run output directory instead of modifying the packaged Skill assets.
  • Make the primary SKILL.md and references/workflow.md call the hardened downloader so the documented allowlist is actually enforced.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes a Markdown-to-image rendering pipeline with local HTTP serving, Puppeteer screenshots, optional image search, AI image generation, and Feishu upload, but the detected implementation apparently does not match those behaviors. This mismatch is dangerous because users and reviewers cannot accurately assess what the skill truly does, which undermines trust boundaries and can conceal unexpected processing, missing controls, or substituted logic.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
27.0.0.1`(本地回环 HTTP server,截图用);`node assets/screenshot.js`(Puppeteer 截图);`node assets/validate.js`(自动验证);`curl.exe`(可选,下载外部图片);`explorer.exe`(打开交付文件夹) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
27.0.0.1`(本地回环 HTTP server,截图用);`node assets/screenshot.js`(Puppeteer 截图);`node assets/validate.js`(自动验证);`curl.exe`(可选,下载外部图片);`explorer.exe`(打开交付文件夹) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
27.0.0.1`(本地回环 HTTP server,截图用);`node assets/screenshot.js`(Puppeteer 截图);`node assets/validate.js`(自动验证);`curl.exe`(可选,下载外部图片);`explorer.exe`(打开交付文件夹) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 270)May include surrounding context.

md
| `references/layout-recipes.md` | 28种布局模板(M01-M16+S01-S12) |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/template-editorial-card.html (reported line 8)May include surrounding context.

html
<meta name="viewport" content="width=1080">
<title>Editorial Magazine x E-ink — Seed Template</title>

<!-- ──────────────────────────────────────────────
     Local Font Stack — No External Network Calls
     v7.6: Removed Google Fonts CDN links to eliminate
     external network dependency (privacy + offline safety).

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/template-swiss-card.html (reported line 8)May include surrounding context.

html
<meta name="viewport" content="width=1080">
<title>Swiss International — 3:4 Social Card</title>

<!-- ── Local Font Stack (v7.6: Google Fonts CDN removed for offline safety) ── -->
<!-- Font variables fall back to system fonts: Inter→system-ui, Noto Sans SC→PingFang SC, IBM Plex Mono→Consolas -->

<style>

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/category-cookbook.md (reported line 86)May include surrounding context.

md
- **Content shape**: 5-7 pages. Cover (title + year + 1-line take) → 1-2 scene captures → director-quote/theme pullquote → verdict ledger
- **Pitfalls**:
  1. Fake film-festival typography (adding fake awards badges). Don't
  2. Spoiler in title without warning. Mark `剧透` in kicker if needed

---

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/portrait-fill.md (reported line 111)May include surrounding context.

Implementation:

html
<!-- Light page (default theme) -->
<section class="poster xhs" id="xhs-01">
  <div class="paper-wash"></div>
  <div class="grain"></div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- 拷贝种子模板:Editorial→ `assets/template-editorial-card.html`;Swiss→ `assets/template-swiss-card.html`
- 设置 `data-theme` 或 `data-accent` 属性切换主题
- 在 `<!-- POSTERS_HERE -->` 处添加页面
- 满铺图页遵循 `references/image-overlay.md`
- 密度保障:每页活跃构图≥78%画布高度
- 节奏保障:暗色页插入、氛围强弱交替、版式不重复

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/template-editorial-card.html (reported line 666)May include surrounding context.

html
- 拷贝种子模板:Editorial→ `assets/template-editorial-card.html`;Swiss→ `assets/template-swiss-card.html`
- 设置 `data-theme` 或 `data-accent` 属性切换主题
- 在 `<!-- POSTERS_HERE -->` 处添加页面
- 满铺图页遵循 `references/image-overlay.md`
- 密度保障:每页活跃构图≥78%画布高度
- 节奏保障:暗色页插入、氛围强弱交替、版式不重复

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/template-swiss-card.html (reported line 597)May include surrounding context.

html
- 拷贝种子模板:Editorial→ `assets/template-editorial-card.html`;Swiss→ `assets/template-swiss-card.html`
- 设置 `data-theme` 或 `data-accent` 属性切换主题
- 在 `<!-- POSTERS_HERE -->` 处添加页面
- 满铺图页遵循 `references/image-overlay.md`
- 密度保障:每页活跃构图≥78%画布高度
- 节奏保障:暗色页插入、氛围强弱交替、版式不重复

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/workflow.md (reported line 36)May include surrounding context.

md
- 拷贝种子模板:Editorial→ `assets/template-editorial-card.html`;Swiss→ `assets/template-swiss-card.html`
- 设置 `data-theme` 或 `data-accent` 属性切换主题
- 在 `<!-- POSTERS_HERE -->` 处添加页面
- 满铺图页遵循 `references/image-overlay.md`
- 密度保障:每页活跃构图≥78%画布高度
- 节奏保障:暗色页插入、氛围强弱交替、版式不重复

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains substantive operational and audit information in Chinese, and the file does not state that Chinese is optional, user-selected, or required for a region-specific purpose. Under the language/locale policy rule, forcing or assuming a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to run npx clawhub@latest install ..., which pulls and executes the latest remote package version at install time. This creates a supply-chain risk: if the package is compromised or a breaking/malicious version is published, users may execute unreviewed code immediately on their machine.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 145)May include surrounding context.

md
**Core capability is local processing**: MD text → HTML assembly → PNG screenshot → local folder delivery. Article content, image assets, and generated artifacts are processed locally by default and never uploaded to any external service.

**Optional external capabilities** (require explicit user consent, never auto-executed):
- **Image search**: Calls Pexels/Pixabay API to search free stock photos. ⚠️ Only search keywords and image downloads are sent to Pexels/Pixabay servers — **article content is never uploaded**
- **Feishu cloud-drive sync**: Uploads generated PNGs + text drafts to user's Feishu cloud drive. ⚠️ Uploading means content leaves the local machine — do not enable if the article contains unpublished/sensitive/proprietary material

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This is the duplicated English installation instruction using npx clawhub@latest, carrying the same supply-chain execution risk as the earlier occurrence. Because npx may download and run code on demand, leaving the version unpinned exposes users to unexpected or malicious upstream changes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill declares broad capabilities including environment-variable access, subprocess execution, network use, and file operations, but it does not define an explicit tool scope such as permissions or allowed-tools. Without an enforceable scope boundary, an agent may invoke more powerful tools than users expect, increasing the risk of unintended data access, local command execution, or external exfiltration when processing sensitive Markdown content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L003 presents the specification in Chinese and there is no indication elsewhere in the file that users may choose another language or that the skill is intentionally limited to a Chinese-speaking/regional context. This is a natural-language locale policy concern because it imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file presents many section headings, instructions, and content patterns in Chinese alongside English, which can implicitly force a bilingual/Chinese-oriented output style for users who did not opt into that locale. The file does not state that the skill is region-specific or that users may choose their preferred language, so it risks violating language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown specification defines title-length rules exclusively for Chinese text under 'Chinese Title Length Bands' and pairs key typography classes with Chinese-specific assumptions, but it does not offer any user choice or note that the guidance is limited to Chinese-language outputs. Because this is natural-language guidance in a shared components spec rather than a clearly justified region-specific compliance requirement, it risks forcing a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations in natural-language content. Lines L062-L068 present the recommended hook patterns only in Chinese, which can effectively force a specific language/locale without user opt-in, and the document does not state that the skill is intentionally limited to a Chinese-language workflow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/image-sources.md (reported line 37)May include surrounding context.

bash
# 用 curl.exe(非 PowerShell 别名)下载搜索结果
curl.exe -s -H "Authorization: $env:PEXELS_API_KEY" \
  "https://api.pexels.com/v1/search?query=<keyword>&per_page=5"

响应关键字段(用于提取图片 CDN URL):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/image-sources.md (reported line 77)May include surrounding context.

bash
curl.exe -s -H "Authorization: Client-ID <ACCESS_KEY>" \
  "https://api.unsplash.com/search/photos?query=<keyword>&per_page=5"

响应关键字段:

Static analysis

No suspicious patterns detected.