Back to skill

Security audit

热点收集雷达

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but its Feishu sync and notification features can send collected data to hard-coded destinations using a workspace token the user may not realize is being reused.

Review before installing. Use this only in an isolated workspace, do not provide reusable Feishu or Instagram session credentials, and avoid --sync-bitable or --notify unless the Feishu destination IDs are changed to destinations you control. Also verify platform filtering and proxy behavior before running daily crawls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
modules/notifier.py:11
Finding

Workspace Feishu Token Used to Send Messages to a Hard-Coded Recipient

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
modules/bitable_sync.py:10
Finding

Workspace Feishu Token Used to Write Data to a Hard-Coded Bitable

Content
View full analysis
hot-radar > skills > workspace) WORKSPACE = os.path.dirname(os.path.dirname(os.path.dirname(os.path.dirname(os.path.abspath(__file__))))) TOKEN_FILE = os.path.join(WORKSPACE, 'scripts', '.feishu_token.json') def _load_token(): try: with open(TOKEN_FILE, encoding='utf-8') as f: return json.load(f).get('accessToken', '') except Exception: return None ``` ```python def _lark_post(endpoint, payload): """POST 到飞书 API""" import urllib.request, urllib.error token = _load_token() if not token: print(' ⚠️ 未找到飞书 Token,跳过同步') return None url = f'{BITABLE_API}/{endpoint}' data = json.dumps(payload).encode('utf-8') req = urllib.request.Request(url, data=data, method='POST') req.add_header('Authorization', f'Bearer {token}') req.add_header('Content-Type', 'application/json') try: with urllib.request.urlopen(req, timeout=20) as resp: return json.loads(resp.read().decode('utf-8')) except Exception as e: print(f' ⚠️ 飞书 API 失败: {e}') return None ``` ```python for i in range(0, len(records), 10): batch = records[i:i+10] result = _lark_post( f'apps/{APP_TOKEN}/tables/{TABLE_ID}/records/batch_create', {'records': batch} ) ``` ### Technical Analysis The synchronization module reads a workspace-level Feishu token and uses it to create records in a Bitable identified by hard-coded application and table identifiers. The synchronized fields include platform name, title, source link, popularity value ...[truncated 1395 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
modules/crawler.py:750
Finding

Platform Disable Settings Are Ignored and All Crawlers Execute

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
modules/crawler.py:254
Finding

Instagram Session Cookie Can Be Used Despite the Platform Being Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
hot-radar.py:13
Finding

Entry Point Silently Imposes a Process-Wide HTTP and HTTPS Proxy

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:8
Finding

Third-Party Python Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tainted flow: 'proxies' from os.environ.get (line 29, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · modules/crawler.py (reported line 30)May include surrounding context.

python
'Accept': 'application/json, text/plain, */*',
    }
    proxies = PROXIES if use_proxy else None
    r = requests.get(url, headers=headers, timeout=timeout, proxies=proxies)
    r.raise_for_status()
    if json_resp:
        return r.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly documents syncing collected data to Feishu Bitable and sending Feishu notifications, but it does not warn users that externally collected content may be transmitted to a third-party service. In a data-collection skill, this omission can lead to unintended disclosure of sensitive, regulated, or proprietary information if operators enable sync or notification features without understanding the data flow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match common requests like '热点分析' or '生成日报', which can cause the skill to activate in situations where the user did not specifically intend to run a data-collecting and report-generating workflow. In this skill, unintended activation is more concerning because the documented behavior includes crawling multiple platforms, writing local data/reports, and potentially syncing or notifying external Feishu destinations in later steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises features including Feishu push/synchronization and local archival of raw data and reports, but the user-facing description does not prominently warn that execution may write files and send data to external services. This reduces informed consent and can lead to unexpected data exfiltration or persistence, especially if broad triggers invoke the skill automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest-style JSON is dominated by Chinese platform identifiers, Chinese display names, and Chinese notes, which effectively fixes the skill's content sourcing and user-facing context to Chinese without any visible opt-in or stated regional scope. Under the policy, forcing a specific language or locale without user choice or a clearly justified region-specific purpose is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script unconditionally sets HTTP_PROXY and HTTPS_PROXY to a local proxy endpoint for all subsequent network activity unless those variables are already defined. This silently reroutes outbound traffic, which can expose collected data, credentials, or API tokens to proxy infrastructure and can also alter trust boundaries without user consent; in this aggregation skill, that is more concerning because later modules likely fetch external data and may send notifications or sync data to third-party services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s user-facing natural-language content, including the module description and docstrings, is entirely in Chinese and presents the skill behavior as Chinese-language only. There is no indication that users may choose another language or that the locale restriction is explicitly justified, which matches the policy category for language/locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module documentation states the Feishu token comes from encrypted OpenClaw storage, but the implementation actually loads it from a plaintext JSON file under the workspace. This mismatch can cause operators to overtrust the secret-handling model, store sensitive access tokens insecurely, and expose them to local disclosure through source checkout, backups, misconfigured permissions, or other workspace access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · config/platforms.json (reported line 8)May include surrounding context.

json
"""知乎热榜"""
    try:
        data = _get(
            'https://api.zhihu.com/topstory/hot-lists/total?limit=50&desktop=true',
            headers={
                'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36',
                'Referer': 'https://www.zhihu.com/',

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · modules/crawler.py (reported line 45)May include surrounding context.

python
"""知乎热榜"""
    try:
        data = _get(
            'https://api.zhihu.com/topstory/hot-lists/total?limit=50&desktop=true',
            headers={
                'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36',
                'Referer': 'https://www.zhihu.com/',

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This request forces zh-CN/CN locale settings in the feed URL, which constrains results to a specific language/region without user opt-in. Similar hard-coded locale choices appear elsewhere in the file, indicating a policy-level language/locale restriction embedded in the skill behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This request forces zh-CN/CN locale settings in the feed URL, which constrains results to a specific language/region without user opt-in. Similar hard-coded locale choices appear elsewhere in the file, indicating a policy-level language/locale restriction embedded in the skill behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The crawler loads a sensitive Instagram session cookie from local config and sends it to Instagram in an automated request. Even though it is sent to the intended service over HTTPS, this still exposes a live authenticated session to code paths that may run without explicit user awareness, increasing the chance of account misuse, logging leakage, or unintended authenticated actions if the environment is shared or compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This request forces zh-CN/CN locale settings in the feed URL, which constrains results to a specific language/region without user opt-in. Similar hard-coded locale choices appear elsewhere in the file, indicating a policy-level language/locale restriction embedded in the skill behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These feed queries explicitly pin language and region to Chinese/China and use only Chinese search terms, enforcing a locale-specific behavior without a user-selectable option. That creates a natural-language policy issue because the skill effectively forces a specific language/locale by design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Feishu post payload is explicitly constructed under the zh_cn locale, and the surrounding user-facing strings throughout the file are also Chinese-only. This forces a specific language/locale without any opt-in or documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file is a code file, so SQP-3 applies to its natural-language strings. The module docstring explicitly states the report is generated in Markdown using Chinese headings/content, and the rest of the file hard-codes Chinese section titles and labels, with no indication that users can opt into another language or that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this locale. Per the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file forces Chinese-language output throughout the document, and there is no indication that the user opted into Chinese or that the report is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Tainted flow: 'app_js' from requests.get (line 9, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
93% confidence
Finding

The code extracts a JavaScript URL from untrusted HTML returned by https://tophub.today/ and then fetches it directly with requests.get(app_js). If the page is compromised or returns an absolute, attacker-controlled URL, this creates a server-side request forgery style sink that can trigger unintended outbound requests, potentially to internal services or malicious hosts.

Content

Scanner excerpt · test_tophub3.py (reported line 12)May include surrounding context.

python
app_js = [j for j in js_files if 'app' in j.lower()][0]
print(f'App JS: {app_js}')

j = requests.get(app_js, timeout=10)
text = j.text

# 找所有 URL 或路径字符串

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The README is entirely in Chinese and all examples, labels, and operational descriptions assume Chinese-language use, with no indication that users may choose another language or that the locale restriction is intentional. SQP-3 covers language or locale policy violations when a specific language is imposed without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file header names the skill in both English and Chinese, and the Chinese title suggests a locale-specific presentation without any accompanying note that language choice is optional or region-specific. The stated policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON file contains only Chinese-language platform keys and Chinese localized content fields/titles, such as 微博、抖音、知乎 and numerous Chinese-only titles/excerpts. For the policy category in scope for all file types, this indicates a locale/language constraint presented without any documented user choice, opt-in, or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON dataset contains natural-language content exclusively in Chinese across platform names, titles, and excerpts, but does not document that the content is China-specific or that users can opt into this locale. Under the policy rule for language or locale constraints, this can be interpreted as forcing a specific language without explicit user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file stores all entries under Chinese-language keys and titles across the dataset, which implies a fixed language/locale behavior if used directly by a skill. The policy requires flagging cases where a skill forces a specific language without offering choice or documenting the constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.