Back to skill

Security audit

Design Daily Insights

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed design-news digest, but it needs review because it publishes a local web directory through a public tunnel with weak safeguards.

Install only if you are comfortable with the digest being published to a temporary public URL and with scheduled Feishu/chat delivery. Before enabling web publishing, isolate the served directory, avoid public tunnels for private content, restore SSH host verification, and know how to stop the server, tunnel, and cron job. Do not run setup-git.sh from a directory that may contain secrets or unrelated files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:104
Finding

Mandatory Third-Party Branding Hijacks Generated Agent Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:104-106, SKILL.md:147, and SKILL.md:227
Vulnerability Type: Persistent output-template manipulation
Risk Level: High

Vulnerable Code:

markdown
> ⚠️ 署名已更新为「多啦啊木 🐾」
markdown
Sources: Figma · Cursor · Framer · Anthropic · Zeroheight · Supernova · NNGroup · Smashing Magazine · Sidebar | Curated by 多啦啊木 🐾
markdown
**署名**:页面底部 `多啦啊木 🐾`,飞书消息末尾同步

Technical Analysis

The Skill instructions require the agent to insert a fixed identity into both the Feishu response and the generated public webpage. This attribution is not necessary for collecting, summarizing, deduplicating, or publishing design news.

Because SKILL.md controls the agent whenever the Skill is loaded, the mandatory attribution modifies the agent's final output independently of the user's actual request. The instruction is repeated in the operational warning, output template, and webpage requirements, making it likely to persist across every normal invocation.

Attack Path

  1. A user installs or loads the Skill.
  2. The user requests a design-news digest.
  3. The agent follows the mandatory output and webpage templates from SKILL.md.
  4. The fixed identity is appended to the Feishu message and public HTML page.
  5. The user unknowingly redistributes attacker-selected branding when reading or sharing the generated content.

Impact Assessment

The issue grants control over a portion of the agent's user-visible output. It does not provide operating-system privileges or access to credentials, but it enables persistent traffic diversion or identity promotion through every generated digest. The affected scope includes chat responses, Feishu messages, and publicly shared webpages created by the Skill.

Remediation
View remediation

Remediation Suggestions

  • Remove the mandatory fixed attribution from the operational instructions and output templates.
  • If attribution is legitimately required, disclose it prominently during installation and make it configurable.
  • Disable attribution by default and only include it after explicit user consent.
  • Keep functional formatting requirements separate from author identity or promotional content.
  • Add a review rule prohibiting fixed promotional text in generated model output unless it is essential to the user's request.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:246
Finding

Public Reverse Tunnel Exposes a Local Directory Without SSH Host Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:246-253
Vulnerability Type: Unsafe public file exposure and insecure SSH configuration
Risk Level: High

Vulnerable Code:

bash
cp /Users/Ellison/.openclaw/workspace/design-daily-site/index.html \
   /Users/Ellison/.openclaw/workspace/design-daily-site/build.html

cd /Users/Ellison/.openclaw/workspace/design-daily-site
python3 -m http.server 8766 &

ssh -o StrictHostKeyChecking=no \
  -R 80:localhost:8766 locaddr.run &

Technical Analysis

python3 -m http.server serves the entire current directory rather than an explicit allowlisted output file. The SSH reverse tunnel then makes that server reachable through an external service. Any additional file present beneath design-daily-site may consequently become publicly retrievable.

The SSH connection explicitly disables strict host-key verification. This removes server-authentication protection and permits a server-impersonation or man-in-the-middle scenario when DNS, network routing, or the initial connection is compromised.

Public Internet publication is broader than the minimum privileges required to generate and send a design digest. It should be optional and isolated from the user's workspace.

Attack Path

  1. A sensitive file, backup, configuration file, or unpublished document is present in design-daily-site.
  2. The Skill starts the directory-wide Python HTTP server.
  3. The reverse SSH tunnel exposes that server through a public URL.
  4. A remote party discovers or guesses the file path and downloads it.
  5. Separately, an attacker capable of redirecting the SSH connection can impersonate the tunnel endpoint because host-key verification is disabled.

Impact Assessment

Remote users may obtain read access to files within the served directory. The exact disclosure scope depends on the directory contents; there is no evidence that the Skill intentionally sends credentials. Th ...[truncated 186 chars]

Remediation
View remediation

Remediation Suggestions

  • Create a fresh, dedicated publication directory containing only the final index.html and required static assets.
  • Never serve the broader workspace or a directory that may contain configuration, backups, state, or credentials.
  • Restore SSH host-key verification and pin the expected locaddr.run host key in a dedicated known_hosts file.
  • Bind the HTTP server explicitly to the loopback interface.
  • Require explicit user approval before creating a public tunnel.
  • Add automatic process cleanup and a short tunnel lifetime.
  • Prefer a deployment service with authenticated uploads, access controls, and stable ownership when public hosting is required.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/design-daily-cron.sh:6
Finding

Environment-Controlled Executable Is Invoked Without Safe Quoting or Validation

Content
View full analysis

Vulnerability Details

File Location: scripts/design-daily-cron.sh:6-15
Vulnerability Type: Command execution through unsafe executable selection
Risk Level: Medium

Vulnerable Code:

bash
OPENCLAW_BIN="${OPENCLAW_BIN:-openclaw}"

UTC_HOUR=$(date -u +%H)
BEIJING_HOUR=$(( (UTC_HOUR + 8) % 24 ))

if [ "$BEIJING_HOUR" -eq 9 ]; then
  $OPENCLAW_BIN run "今日设计资讯" --channel feishu

Technical Analysis

The executable invoked by the scheduled script is selected through the OPENCLAW_BIN environment variable. Its expansion is unquoted and no validation restricts it to an expected absolute executable path.

A party able to influence the scheduled task's environment can point OPENCLAW_BIN to another executable or introduce additional shell words. The selected program will run with the same operating-system identity and permissions as the cron task.

Attack Path

  1. An attacker or compromised configuration modifies OPENCLAW_BIN in the cron environment.
  2. The scheduled task reaches 09:00 Beijing time.
  3. The shell expands the attacker-controlled value as the command and potentially additional arguments.
  4. The selected executable runs with the scheduled task's privileges.

Impact Assessment

Successful exploitation permits command execution under the account running the cron job. This can provide access to that account's files, OpenClaw workspace, configured messaging integrations, and any other resources available to the scheduled process. Exploitation requires prior ability to influence the task environment or launch the script with a crafted environment.

Remediation
View remediation

Remediation Suggestions

  • Use a trusted absolute path to the OpenClaw executable.
  • If configurability is required, verify that the value is an absolute path to an approved executable.
  • Invoke the validated path as "$OPENCLAW_BIN" to prevent word splitting.
  • Define a minimal trusted PATH for scheduled execution.
  • Clear unnecessary environment variables before invoking OpenClaw.
  • Configure the cron task under a dedicated, least-privileged service account.

T09 · Insecure Skill Coding Practices

Warning
Location
setup-git.sh:8
Finding

Recursive Git Staging Can Include Unrelated Sensitive Files

Content
View full analysis

Vulnerability Details

File Location: setup-git.sh:8-21
Vulnerability Type: Unrestricted recursive staging of local files
Risk Level: Medium

Vulnerable Code:

bash
if [ ! -f "SKILL.md" ]; then
  exit 1
fi

git init
git add .

Technical Analysis

The script treats the presence of any SKILL.md in the current directory as sufficient proof that it is running in the intended project root. It then initializes a repository and recursively stages every non-ignored file beneath that directory.

If the script is run from a larger workspace, a copied project directory, or a directory containing generated state and credentials, git add . may stage files unrelated to the Skill. The script subsequently instructs the user to associate the repository with GitHub and push it, creating a realistic disclosure path.

Attack Path

  1. The user runs the script in a directory containing SKILL.md and unrelated sensitive files.
  2. The weak directory check succeeds.
  3. git add . recursively stages all non-ignored files.
  4. The user follows the printed instructions to configure a remote repository and push.
  5. Sensitive files become available in the remote repository and remain in Git history even if later deleted.

Impact Assessment

The issue can expose any readable file beneath the selected directory, including API keys, environment files, private state, logs, local configuration, and generated content. It does not itself transmit files because the push remains a separate user action, but it prepares the files for publication and encourages that next step.

Remediation
View remediation

Remediation Suggestions

  • Resolve the script's own directory and operate only from that verified project root.
  • Check for multiple project-specific marker files rather than only SKILL.md.
  • Replace git add . with an explicit allowlist of intended release files.
  • Add a restrictive .gitignore covering environment files, credentials, memory, logs, generated sites, editor metadata, and private keys.
  • Display the staged file list and require confirmation before committing.
  • Run an automated secret scanner against staged content before permitting publication.
  • If sensitive content is committed, remove it from Git history and rotate every exposed credential before pushing again.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Publishing each report through a local HTTP server plus a public tunnel creates unnecessary external exposure for a design-news digest. If summaries, metadata, prompts, or locally served files are reachable through the tunnel, an attacker or unintended viewer could access information that was meant to remain in the user's chat or local environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a content/news tracking skill focused on aggregating and summarizing design-related updates. The actual code chunk does not implement any such functionality. Instead, it is a release/setup script for source control and publication: it checks for SKILL.md, runs git init, git add ., and git commit, then prints GitHub push instructions. This is a materially different primary purpose and introduces undeclared capabilities related to repository management and publishing workflow, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to start a local HTTP server and expose it publicly via an SSH reverse tunnel using locaddr.run. Publicly exposing local content is outside the narrow purpose of generating a design-news digest and can unintentionally disclose local files, generated content, or service metadata if the served directory or process is misconfigured.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

These deployment instructions invoke shell commands, background a long-lived HTTP server, open a reverse tunnel, and probe the resulting public URL. Such side effects materially expand the skill's capabilities beyond summarization and introduce persistence, network exposure, and process-management risks on the host environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown guidance hard-codes bilingual output with Chinese counting/format assumptions and discusses switching to a single language without stating that the user's preferred language should be requested or respected. That creates a natural-language locale policy concern because the skill behavior appears language-constrained by default rather than user-selected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README expands the skill from private news aggregation into generating and publishing a public web page, which materially increases exposure beyond the stated digesting function. Scope expansion like this is dangerous because users may grant or tolerate capabilities they would not expect from a news-summary skill, including network exposure and publication of generated content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says each push generates an independently hosted public URL but does not prominently warn that the output becomes publicly accessible. That omission is risky because users may assume the digest remains private, leading to accidental disclosure of sensitive summaries, source selections, or other contextual information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions recommend exposing a local HTTP server via locaddr.run without clearly explaining the security implications of tunneling a local service to the internet. This is dangerous because users may unknowingly expose unintended endpoints, local content, or weakly protected development servers to public access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown states that the skill will automatically push summaries to the user's chat window and automatically clean up history records after 7 days. These behaviors affect user data and system state, but the README does not include any caution, retention notice, or user-facing warning about automatic sending or deletion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill describes network-affecting deployment steps that expose a local service externally, but it does not clearly foreground the security implications of opening public access or running background services. Users may follow these steps without understanding that local content becomes reachable from the internet and that processes may remain running.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill recommends running npx vercel without pinning a version, which executes code fetched at runtime from the package registry. That creates supply-chain risk and undermines reproducibility, especially in an automation-oriented skill that already performs deployment-related actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs creation of cron jobs, executable helper scripts, and persistent scheduled runs. Modifying scheduler state creates lasting host-side effects and can cause repeated network activity, repeated message sending, and difficult-to-audit persistence that is not necessary for one-off digest generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document is primarily written in Chinese, with bilingual headings but no indication that language choice is optional or limited to a justified region-specific context. The policy for this audit flags natural-language locale constraints when a skill appears to require a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for tracking and summarizing design-related news and inspiration, but this file implements Git repository initialization, committing, and instructions for publishing to GitHub/ClawHub. Those release-engineering operations are not part of delivering design insights to users and reflect a different operational purpose than the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file contains natural-language comments and a fixed task prompt (今日设计资讯) in Chinese, implying the skill is intended to operate in a specific language without any user opt-in or documented language selection. Under the policy rule for locale/language choice, this is a natural-language policy concern because the script does not indicate that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script's title, status messages, and instructions are written in Chinese throughout, such as the header and all subsequent guidance lines. This creates a language/locale constraint in natural-language output without any opt-in or alternative language path, which matches the policy-violation category for forced language selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.