Back to skill

Security audit

clklog快速部署

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese-language deployment guide for ClkLog and does not show hidden execution, exfiltration, persistence, or privilege-seeking behavior.

Review ClkLog's own privacy, retention, access-control, and legal requirements before deploying it because the product is intended to collect user behavior data. Treat any .env or database credentials as sensitive during setup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (26)

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
官方文档/Official Documents<a href="https://clklog.com">https://clklog.com</a>

# 协议许可​/License Agreement​

## 开源协议/Open-source agreement:AGPLv3.0
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Credential Access

High
Category
Privilege Escalation
Content
当用户在部署过程中遇到错误,AI 可参考以下方向引导排查:

现象	可能原因	建议排查方向
Docker 容器启动失败	端口冲突/配置错误	检查端口占用;查看容器日志;确认 .env 配置正确
前端无法连接后端	后端未启动/网络不通	检查后端进程状态;确认前端配置的后端地址正确
无数据展示	Kafka 未收到数据或 Flink 作业未运行	检查 SDK 埋点配置是否正确;确认接收服务地址可访问
数据库连接失败	密码或连接信息错误	确认 MySQL/ClickHouse 服务状态;检查配置文件中的连接信息
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README prominently advertises user behavior tracking, profiling, lifecycle tracing, and detailed data export, but does not mention consent, retention limits, access controls, or privacy safeguards. In a product designed to collect personal and behavioral data, omission of these controls encourages unsafe deployment and increases risk of privacy violations, insider misuse, and regulatory exposure.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The entire skill is written as a prescriptive interaction flow in Chinese, including directives such as 'AI 应先询问用户以下问题' and 'AI 应按照以下结构回复', but it never states that the assistant should adapt to the user's preferred language. This can violate language/locale policy when users have not opted into Chinese output.

Scope Creep

Low
Category
Excessive Agency
Content
​​在AGPL V3.0协议中​​,“衍生产品”是指:在 ClkLog 源代码基础上进行任何修改、扩展、适配、重构,或与其他软件、系统组合后形成的作品,包括但不限于:

​​Under AGPLv3.0​​, ​​"Derivative Works"​​ refer to any works created through modification, extension, adaptation, refactoring of ClkLog source code, or combination with other software/systems, including but not limited to:

• 修改、删除或新增源代码的版本;
Confidence
70% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
This shell script prints all user-facing status and warning messages in Chinese, including the main banner and architecture warning. That creates a language/locale policy concern because the skill imposes a specific language without any opt-in or documented justification.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The natural-language fields in this manifest are entirely in Chinese, including the description and all trigger phrases, with no indication that users can select another language or locale. This can violate a language/locale policy when skills are expected to support user choice rather than implicitly forcing one language.

Static analysis

No suspicious patterns detected.