Back to skill

Security audit

Daily Deals 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

The skill’s daily deal reporting purpose is coherent, but its scheduled path embeds Feishu credentials and sends reports to a fixed recipient instead of the user-configured destination.

Review before installing. Do not run or schedule `scripts/daily-push.js` until the embedded Feishu credentials and recipient are removed, the exposed secret is rotated, and all destinations come only from user-controlled config or environment variables. Prefer a reviewed lockfile or pinned dependencies before running `npm install`.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/daily-push.js:11
Finding

Hard-Coded Feishu Application Credentials and Recipient

Content
View full analysis
{ const req = https.request( 'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', { method: 'POST', headers: { 'Content-Type': 'application/json', 'Content-Length': data.length } }, (res) => { let body = ''; res.on('data', chunk => body += chunk); res.on('end', () => { const result = JSON.parse(body); resolve(result.tenant_access_token); }); } ); req.on('error', reject); req.write(data); req.end(); }); } ``` The report is then sent to the embedded recipient: ```javascript const payload = { receive_id: FEISHU_CONFIG.receiveId, msg_type: 'text', content: JSON.stringify({ text: content }) }; ``` ### Technical Analysis A Feishu application ID, application secret, and recipient open ID are stored directly in source code. The application secret is an authentication credential used to obtain a tenant access token. Anyone who obtains a copy of the project can extract this credential and attempt to authenticate as the Feishu application. The main scheduled entry point, `scripts/daily-push.js`, does not use the destinations described by the configurable webhook mechanism ...[truncated 2055 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:21
Finding

Non-Reproducible Dependency Installation Without an Integrity Lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
0 8,20 * * * cd ~/.openclaw/skills/daily-deals-1.0.0 && node scripts/daily-push.js

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

3. 定时任务(推荐)

bash
crontab -e
# 每日 8:00 和 20:00 推送
0 8,20 * * * /home/gaof/.openclaw/workspace/skills/daily-push-cron.sh

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to place Feishu appId, appSecret, and receiveId into a config file but provides no guidance on secret storage, file permissions, or excluding the file from version control. This can lead to credential leakage through repos, backups, logs, or shared skill directories, enabling unauthorized use of the Feishu integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to configure webhook endpoints and push generated reports to third-party messaging services, but it does not clearly warn that data will leave the local environment and be transmitted externally. In an agent-skill context, undisclosed outbound delivery increases privacy and data-handling risk, especially if reports later include scraped content, user-specific interests, or operational metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Comments and all user-facing echo messages are in Chinese, which effectively forces a specific language experience. The file does not indicate that the skill is intentionally limited to a Chinese-speaking or region-specific audience, nor does it provide any opt-in or language selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script automatically retrieves a Feishu tenant token using embedded credentials and sends report contents to an external messaging API without any runtime confirmation or explicit user-facing disclosure. In a skill context, this outbound transmission can expose scraped content, operational metadata, and misuse hard-coded credentials if the script is run unexpectedly or repurposed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report explicitly states the data source is '实时抓取' (real-time scraping), but the scraper can silently fall back to hard-coded preset deals on parse failure or exceptions. This creates a data integrity issue: recipients may act on stale or fabricated content while believing it is live data, which is especially risky for automated notifications and trust-sensitive reporting.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script embeds a Feishu app ID, app secret, and recipient identifier directly in source code, then uses them to obtain an access token and send messages externally. Hardcoded secrets are dangerous because anyone with repository or artifact access can reuse them for unauthorized API access, message sending, and potential impersonation of the associated integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script accesses and stores sensitive messaging credentials and a fixed recipient identifier without adequate disclosure or separation of secrets from code. This increases the chance of accidental leakage, misuse by downstream users, and unnoticed use of privileged messaging capabilities in environments where the script may be run blindly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically transmits the generated report to Feishu at runtime without interactive confirmation, dry-run mode, or a clear opt-in gate. In an agent/skill context, silent outbound transmission increases the risk of unreviewed data exfiltration, especially if snapshots or generated content contain sensitive or unexpected information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Natural-language strings throughout the file indicate the skill is designed to operate only in Chinese, and line L003 explicitly labels it as such. Under the policy rule, forcing a specific language or locale without user opt-in is a policy violation unless the locale restriction is clearly justified or the user is offered a choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file is documented as a '报告生成器' (report generator), but its implementation shells out to another Node.js script and a Python parser using execSync. Spawning external processes is a materially broader capability than ordinary in-process report formatting and data aggregation, and there is no manifest purpose available to justify that elevated capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code invokes an external scraper to fetch remote web content and then processes the results, which is a network/data-transmission operation covered by the missing-warning rule for code files. Although there is console logging for progress, the messages do not disclose that the script will contact third-party sites or transmit request metadata to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code's natural-language content, including the file header comment and all console messages, is exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

All user-facing instructions in the README are presented in Chinese, and the document does not offer an alternative language or indicate that the skill is intentionally limited to a Chinese-speaking audience. This can violate a language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and examples are entirely in Chinese, and the file does not indicate that the skill is region-specific or provide an opt-in language choice. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script runs node scripts/daily-push.js, which is a subprocess execution in a code file. Although progress is logged, the user is not told what actions the child script may perform or whether it could write data or push content externally, so the safety-relevant behavior is not clearly disclosed here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description field is entirely in Chinese and presents the skill in a single language, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy requirements when a skill implicitly forces one locale without opt-in or justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"author": "OpenClaw",
  "license": "MIT",
  "dependencies": {
    "playwright": "^1.40.0"
  },
  "engines": {
    "node": ">=16.0.0"

Unverifiable Dependency: playwright has 1 known advisory(ies) (CVE-2025-59288 (Playwright downloads and installs browsers without verifying the authenticity of)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
82% confidence
Finding

The manifest depends on Playwright with a non-pinned version, while the package is noted as having a known advisory related to downloading/installing browsers without authenticity verification. In a scraping/automation skill that likely invokes Playwright, this increases supply-chain risk because installations may fetch browser binaries and the manifest does not ensure a known-safe version.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The scraper is invoked with an --html output path under /tmp, and the script then reads that file back. This is a file-write operation, but the surrounding comments and user-facing logs do not disclose that a local HTML artifact will be created on disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The report uses zh-CN locale formatting and fixed Chinese-language output strings, which forces a specific language/locale behavior. The policy allows this only when the user is given a choice or the locale restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script’s natural-language interface and generated content are written in Chinese, and it explicitly formats weekday output using the zh-CN locale. There is no visible opt-in, language selection, or documented justification that this skill is intended only for Chinese-language users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code explicitly formats dates using the zh-CN locale, which enforces a specific locale policy in output. Because there is no visible option for the user to choose another locale and no documented justification in this file, it falls under the language/locale policy check.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The module docstring presents the skill exclusively in Chinese, and the file contains no indication that this language choice is optional or limited to a justified region-specific context. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/daily-push-feishu.js:107

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/generate-report.js:39