T05 · Unauthorized Access and Privilege Escalation
- Location
auto_enrich.py:24- Finding
Global OpenClaw Credential Extraction and Transmission to MiniMax
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a dialect dictionary, but it also includes credential use, cloud syncing, local state changes, and contaminated data that need careful review before installation.
Review before installing. At minimum, remove the /root/.openclaw/openclaw.json API-key fallback, set cloud_share.enabled to false by default, remove or isolate the hardcoded task-queue helper, purge prompt-like rows from the corpus, replace executable incremental SQL with parameterized imports, and add backups or confirmation before database rebuilds.
auto_enrich.py:24Global OpenClaw Credential Extraction and Transmission to MiniMax
sync_from_cloud.py:137Untrusted Cloud Records Are Persisted in Agent Memory
add_word.py:67Persistent SQL Injection Through Incremental Vocabulary Entries
submit-fangyan-sync.sh:13External Task Submission Uses Hardcoded Personal and Application Identities
data/config.yaml:5Cloud Sharing Is Enabled by Default Contrary to the Documented Opt-In Model
init_db.py:43Database Initialization Silently Deletes Existing Local Data
The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.
The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.
The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.
The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.
The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.
The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.
The skill includes writing to Feishu cloud tables, reading local config with app credentials, calling external APIs for tokens and bot metadata, and modifying config.yaml to cache bot_name, none of which are obvious from the benign lookup framing. This is dangerous because it mixes credentialed network operations and local configuration mutation into a skill users may trust as read-only.
Referenced artifact was not completely inspected
| data/dialect_data.sql | 方言数据 SQL(init_db.py 使用) |
The file materially expands scope from a passive dialect lookup skill into an autonomous data-generation and remote-sync workflow. That increases risk because running the skill can cause unsupervised outbound API calls, database mutation, and cloud writes that users may not expect from the advertised functionality.
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
method="POST"
)
with urllib.request.urlopen(req, timeout=30) as r:
resp = json.loads(r.read())
text = ""
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
data=data,
headers={"Content-Type": "application/json"}
)
with urllib.request.urlopen(req) as r:
resp = json.loads(r.read())
return resp.get("tenant_access_token", "")
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
data=data,
headers={"Content-Type": "application/json"}
)
with urllib.request.urlopen(req) as r:
resp = json.loads(r.read())
return resp.get("tenant_access_token", "")
A row at this location contains prompt-like or chain-of-thought style control text embedded as data, which can act as semantic prompt injection if the skill retrieves and feeds corpus entries into an LLM. In a dialect lookup skill, users and the model expect lexical mappings, so hidden model-directed instructions are especially dangerous because they can override output behavior or suppress safeguards.
Natural-language assistant-control text embedded inside a lookup corpus is a classic prompt-injection pattern. If an agent concatenates retrieved rows into an LLM prompt, this content can instruct the model to ignore prior policy, reveal reasoning style, or change output format in ways the user did not request.
This repeated control phrase reinforces that the corpus contains active model-steering instructions rather than passive dialect data. Repetition increases the chance that retrieval surfaces the payload and that an LLM overweights it relative to the system or task prompt.
These rows appear to be generation residue and formatting artifacts rather than genuine dialect mappings, which means the dataset is contaminated with model-control or transcript fragments. If surfaced during retrieval, they can poison prompts, degrade tool reliability, and potentially steer LLM responses away from intended behavior.
The content around these lines appears to preserve hidden output-control instructions inside corpus rows, which can act as second-order prompt injection. In a translation/dialect skill, such payloads are likely to be retrieved in response to user text and then interpreted by the model as higher-priority behavioral guidance.
This script performs an external side effect unrelated to the declared skill purpose: it submits a cloud sync job to a task queue and can direct notifications to a user or group. In a dialect lookup skill, this hidden operational capability creates a covert execution and messaging path that could be abused for unauthorized job submission, data movement, or off-platform actions without user awareness.
The code can enqueue external tasks and target arbitrary recipients via receive-id and receive-id-type, which gives the skill a messaging/automation capability beyond simple query functionality. In this context, that mismatch is dangerous because a seemingly harmless language skill could be used as a delivery mechanism for unauthorized workflows, spam, social engineering, or concealed backend actions.
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
"https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal",
data=data, headers={"Content-Type": "application/json"}
)
with urllib.request.urlopen(req) as r:
resp = json.loads(r.read())
if resp.get('code') != 0:
raise Exception("获取token失败: " + str(resp))
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
"https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal",
data=data, headers={"Content-Type": "application/json"}
)
with urllib.request.urlopen(req) as r:
resp = json.loads(r.read())
if resp.get('code') != 0:
raise Exception("获取token失败: " + str(resp))
The skill is presented as a dialect lookup/query tool, but this file performs outbound writes to Feishu Bitable and also mutates local configuration by persisting bot_name. That hidden state change and remote synchronization exceed the stated capability and make the skill materially more dangerous because users would not reasonably expect their interactions to be written to cloud storage.
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
data=data, headers={'Content-Type': 'application/json'}
)
with urllib.request.urlopen(req) as r:
token = json.loads(r.read())['tenant_access_token']
# 获取 bot 信息
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
data=data, headers={'Content-Type': 'application/json'}
)
with urllib.request.urlopen(req) as r:
token = json.loads(r.read())['tenant_access_token']
# 获取 bot 信息
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal',
data=data, headers={'Content-Type': 'application/json'}
)
with urllib.request.urlopen(req) as r:
token = json.loads(r.read())['tenant_access_token']
# 获取 bot 信息
No suspicious patterns detected.