Back to skill

Security audit

analyze video by qwen

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real Qwen video-analysis skill, but it includes overbroad local agent permissions that preapprove arbitrary Python and chmod commands.

Review before installing. Remove or narrow the bundled .claude shell permissions, especially Bash(python3:*) and Bash(chmod:*), pin dashscope to a reviewed version, and only submit videos you are allowed to send to Alibaba Cloud Qwen/DashScope. Protect the DashScope API key in ~/.openclaw/openclaw.json and avoid sharing logs or screenshots that include it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned DashScope Dependency Permits Unreviewed Supply-Chain Changes

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

text
dashscope

Technical Analysis

The project declares dashscope without an exact version constraint or package integrity hash. Consequently, each installation may retrieve a different package release from the configured Python package index. The installed code can therefore differ from the dependency version evaluated during this audit.

Python packages can execute code during installation and are imported with the privileges of the user running scripts/analyze.py. If a future DashScope release, its publishing account, or the configured package index is compromised, malicious package code could execute during installation or when this Skill imports dashscope.

This finding concerns the absence of dependency pinning and integrity verification. The audited files contain no evidence that the current dashscope package itself is malicious.

Attack Path

  1. An attacker compromises the dependency publisher, package distribution channel, or a future package release.
  2. The attacker publishes a malicious or compromised dashscope version.
  3. A user installs the project dependencies using requirements.txt.
  4. Because no version or hash is enforced, the package manager retrieves the attacker-controlled release.
  5. Malicious code executes during package installation or when scripts/analyze.py imports dashscope.
  6. The code operates with the filesystem, network, environment, and account privileges of the user running the installation or Skill.

Impact Assessment

Successful exploitation could allow arbitrary code execution under the installing or executing user's account. Depending on that account's permissions, an attacker could access local files and credentials, including the DashScope API key stored in ~/.openclaw/openclaw.json, send network requests, alter project f ...[truncated 138 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin dashscope to a specifically reviewed version using an exact version constraint, for example:

    text
    dashscope==REVIEWED_VERSION
    
  2. Generate a locked dependency file containing cryptographic hashes for all direct and transitive dependencies.

  3. Install dependencies with hash enforcement, such as:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Use a trusted package index or an internally controlled dependency mirror.

  5. Run dependency vulnerability and provenance checks in CI before accepting updates.

  6. Review and test dependency upgrades explicitly rather than allowing installation-time resolution to select an arbitrary newer version.

  7. Install and execute the Skill in an isolated, least-privileged environment without access to unrelated user credentials or sensitive files.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
.claude/settings.local.json:1
Finding

Overly Broad Preapproved Shell Permissions Enable Arbitrary Python Execution and Permission Changes

Content
View full analysis

Vulnerability Details

File Location: .claude/settings.local.json:1-8
Vulnerability Type: Excessive command authorization
Risk Level: High

Vulnerable Code

json
{
  "permissions": {
    "allow": [
      "Bash(chmod:*)",
      "Bash(python3:*)"
    ]
  }
}

Technical Analysis

The local agent configuration preapproves every python3 invocation and every chmod invocation through wildcard command patterns. The documented Skill workflow only requires running the specific analyzer script; it does not require unrestricted Python execution or any use of chmod.

Bash(python3:*) can authorize substantially more than execution of scripts/analyze.py. Python supports inline code through python3 -c, execution of arbitrary files, module execution, filesystem operations, subprocess creation, and network access. As a result, this permission can function as a general-purpose local code-execution capability.

Bash(chmod:*) permits arbitrary changes to file permission bits within the authority of the current user. It could make files executable, remove protections, or change access to user-owned files. Although chmod alone does not grant operating-system privileges the current user does not already possess, it unnecessarily expands the set of actions that may occur without an additional approval boundary.

Attack Path

  1. An attacker introduces malicious instructions into content available to the agent, or otherwise causes the agent to formulate an unsafe command.
  2. The agent invokes python3 -c with attacker-controlled code or runs an attacker-controlled Python file.
  3. The wildcard Bash(python3:*) rule treats the invocation as preapproved, bypassing a command-specific approval opportunity.
  4. The Python process reads or modifies files, accesses credentials available to the user, starts subprocesses, or communicates over the network.
  5. If useful to the attack, the agent invokes chmod to make another file executable or a ...[truncated 783 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unused Bash(chmod:*) permission.
  2. Replace Bash(python3:*) with the narrowest supported authorization for the exact analyzer entry point and expected arguments.
  3. Require explicit interactive approval for inline Python, module execution, arbitrary script paths, and all permission-changing commands.
  4. If precise argument restrictions are unavailable, do not preapprove Python execution; require approval for each invocation.
  5. Run the analyzer in a sandbox or container with:
    • Read-only access to the project where practical.
    • Access only to the selected video file.
    • No access to unrelated home-directory files.
    • Restricted outbound networking limited to the documented DashScope endpoint.
  6. Keep API credentials in a dedicated secret mechanism and expose them only to the analyzer process.
  7. Add automated checks that reject wildcard shell permissions unless they are explicitly justified and security-reviewed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documentation indicates capabilities to read local files and fetch remote URLs, but it does not declare any explicit tool scope or permission boundary. This can cause the agent or user to invoke the skill without clear visibility into file and network access, increasing the risk of unintended local file exposure or outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and usage guidance are presented in Chinese, while the file title and metadata do not state that the skill is intended only for Chinese-speaking users or a China-specific environment. This can violate language/locale policy when a specific language is effectively forced without user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill supports analyzing remote video URLs but does not warn that the video content may be transmitted to an external third-party model service. Users may mistakenly assume processing is local and submit sensitive or copyrighted video content, creating privacy, confidentiality, and compliance risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s docstrings, CLI description, status/error messages, and default analysis prompt are all hard-coded in Chinese, which imposes a specific language on users without opt-in. The policy explicitly calls out language or locale constraints as violations unless the skill offers a language choice or clearly documents a justified regional limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation tells users where to store the API key but does not include guidance on secure credential handling. This increases the chance that users will place secrets in insecure files, share config snippets, or commit credentials to version control.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified without a version pin, which allows future installs to resolve to different package versions over time. This creates a supply-chain risk: a malicious or breaking upstream release of dashscope could be pulled automatically, leading to unexpected behavior or compromise during installation or runtime.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
dashscope

Static analysis

No suspicious patterns detected.