T05 · Unauthorized Access and Privilege Escalation
- Location
modules/notifier.py:11- Finding
Workspace Feishu Token Used to Send Messages to a Hard-Coded Recipient
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but its Feishu sync and notification features can send collected data to hard-coded destinations using a workspace token the user may not realize is being reused.
Review before installing. Use this only in an isolated workspace, do not provide reusable Feishu or Instagram session credentials, and avoid --sync-bitable or --notify unless the Feishu destination IDs are changed to destinations you control. Also verify platform filtering and proxy behavior before running daily crawls.
modules/notifier.py:11Workspace Feishu Token Used to Send Messages to a Hard-Coded Recipient
modules/bitable_sync.py:10Workspace Feishu Token Used to Write Data to a Hard-Coded Bitable
modules/crawler.py:750Platform Disable Settings Are Ignored and All Crawlers Execute
modules/crawler.py:254Instagram Session Cookie Can Be Used Despite the Platform Being Disabled
hot-radar.py:13Entry Point Silently Imposes a Process-Wide HTTP and HTTPS Proxy
README.md:8Third-Party Python Dependencies Are Installed Without Version or Integrity Pinning
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
'Accept': 'application/json, text/plain, */*',
}
proxies = PROXIES if use_proxy else None
r = requests.get(url, headers=headers, timeout=timeout, proxies=proxies)
r.raise_for_status()
if json_resp:
return r.json()
The README explicitly documents syncing collected data to Feishu Bitable and sending Feishu notifications, but it does not warn users that externally collected content may be transmitted to a third-party service. In a data-collection skill, this omission can lead to unintended disclosure of sensitive, regulated, or proprietary information if operators enable sync or notification features without understanding the data flow.
The trigger phrases are broad enough to match common requests like '热点分析' or '生成日报', which can cause the skill to activate in situations where the user did not specifically intend to run a data-collecting and report-generating workflow. In this skill, unintended activation is more concerning because the documented behavior includes crawling multiple platforms, writing local data/reports, and potentially syncing or notifying external Feishu destinations in later steps.
The skill advertises features including Feishu push/synchronization and local archival of raw data and reports, but the user-facing description does not prominently warn that execution may write files and send data to external services. This reduces informed consent and can lead to unexpected data exfiltration or persistence, especially if broad triggers invoke the skill automatically.
This manifest-style JSON is dominated by Chinese platform identifiers, Chinese display names, and Chinese notes, which effectively fixes the skill's content sourcing and user-facing context to Chinese without any visible opt-in or stated regional scope. Under the policy, forcing a specific language or locale without user choice or a clearly justified region-specific purpose is a natural-language policy violation.
The script unconditionally sets HTTP_PROXY and HTTPS_PROXY to a local proxy endpoint for all subsequent network activity unless those variables are already defined. This silently reroutes outbound traffic, which can expose collected data, credentials, or API tokens to proxy infrastructure and can also alter trust boundaries without user consent; in this aggregation skill, that is more concerning because later modules likely fetch external data and may send notifications or sync data to third-party services.
The file’s user-facing natural-language content, including the module description and docstrings, is entirely in Chinese and presents the skill behavior as Chinese-language only. There is no indication that users may choose another language or that the locale restriction is explicitly justified, which matches the policy category for language/locale constraints without opt-in.
The module documentation states the Feishu token comes from encrypted OpenClaw storage, but the implementation actually loads it from a plaintext JSON file under the workspace. This mismatch can cause operators to overtrust the secret-handling model, store sensitive access tokens insecurely, and expose them to local disclosure through source checkout, backups, misconfigured permissions, or other workspace access.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""知乎热榜"""
try:
data = _get(
'https://api.zhihu.com/topstory/hot-lists/total?limit=50&desktop=true',
headers={
'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36',
'Referer': 'https://www.zhihu.com/',
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""知乎热榜"""
try:
data = _get(
'https://api.zhihu.com/topstory/hot-lists/total?limit=50&desktop=true',
headers={
'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36',
'Referer': 'https://www.zhihu.com/',
This request forces zh-CN/CN locale settings in the feed URL, which constrains results to a specific language/region without user opt-in. Similar hard-coded locale choices appear elsewhere in the file, indicating a policy-level language/locale restriction embedded in the skill behavior.
This request forces zh-CN/CN locale settings in the feed URL, which constrains results to a specific language/region without user opt-in. Similar hard-coded locale choices appear elsewhere in the file, indicating a policy-level language/locale restriction embedded in the skill behavior.
The crawler loads a sensitive Instagram session cookie from local config and sends it to Instagram in an automated request. Even though it is sent to the intended service over HTTPS, this still exposes a live authenticated session to code paths that may run without explicit user awareness, increasing the chance of account misuse, logging leakage, or unintended authenticated actions if the environment is shared or compromised.
This request forces zh-CN/CN locale settings in the feed URL, which constrains results to a specific language/region without user opt-in. Similar hard-coded locale choices appear elsewhere in the file, indicating a policy-level language/locale restriction embedded in the skill behavior.
These feed queries explicitly pin language and region to Chinese/China and use only Chinese search terms, enforcing a locale-specific behavior without a user-selectable option. That creates a natural-language policy issue because the skill effectively forces a specific language/locale by design.
The Feishu post payload is explicitly constructed under the zh_cn locale, and the surrounding user-facing strings throughout the file are also Chinese-only. This forces a specific language/locale without any opt-in or documented region-specific justification, which matches the language/locale policy violation criteria.
This Python file is a code file, so SQP-3 applies to its natural-language strings. The module docstring explicitly states the report is generated in Markdown using Chinese headings/content, and the rest of the file hard-codes Chinese section titles and labels, with no indication that users can opt into another language or that the skill is region-specific.
This markdown file contains user-facing natural language exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this locale. Per the policy, forcing a specific language without user choice is a natural-language policy violation.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file forces Chinese-language output throughout the document, and there is no indication that the user opted into Chinese or that the report is intentionally limited to a Chinese-speaking or region-specific audience.
The code extracts a JavaScript URL from untrusted HTML returned by https://tophub.today/ and then fetches it directly with requests.get(app_js). If the page is compromised or returns an absolute, attacker-controlled URL, this creates a server-side request forgery style sink that can trigger unintended outbound requests, potentially to internal services or malicious hosts.
app_js = [j for j in js_files if 'app' in j.lower()][0]
print(f'App JS: {app_js}')
j = requests.get(app_js, timeout=10)
text = j.text
# 找所有 URL 或路径字符串
The README is entirely in Chinese and all examples, labels, and operational descriptions assume Chinese-language use, with no indication that users may choose another language or that the locale restriction is intentional. SQP-3 covers language or locale policy violations when a specific language is imposed without user opt-in.
The file header names the skill in both English and Chinese, and the Chinese title suggests a locale-specific presentation without any accompanying note that language choice is optional or region-specific. The stated policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.
This JSON file contains only Chinese-language platform keys and Chinese localized content fields/titles, such as 微博、抖音、知乎 and numerous Chinese-only titles/excerpts. For the policy category in scope for all file types, this indicates a locale/language constraint presented without any documented user choice, opt-in, or justification.
This JSON dataset contains natural-language content exclusively in Chinese across platform names, titles, and excerpts, but does not document that the content is China-specific or that users can opt into this locale. Under the policy rule for language or locale constraints, this can be interpreted as forcing a specific language without explicit user choice.
The file stores all entries under Chinese-language keys and titles across the dataset, which implies a fixed language/locale behavior if used directly by a skill. The policy requires flagging cases where a skill forces a specific language without offering choice or documenting the constraint.
No suspicious patterns detected.