Back to skill

Security audit

股票投资智投顾问

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stock-analysis purpose, but it can automatically put potentially sensitive investment analysis into a Feishu cloud document without a clear consent gate.

Install only if you are comfortable with stock names, screenshots, holdings details, and generated analysis being used with external data providers and possibly Feishu. Ask the agent to confirm before creating any Feishu document, avoid entering account credentials or private portfolio details unless needed, and prefer pinned or already-installed ClawHub tooling over the unpinned npx command.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:35
Finding

Unpinned Package Retrieval and Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 35-42
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

bash
### Method Two: Install Using ClawHub

If this skill has been published to ClawHub:

```bash
# Install the skill
npx clawhub install stock-investment-advisor

# Or from OpenClaw
clawhub install stock-investment-advisor
text

### Technical Analysis

The documentation instructs users to run `npx clawhub` without specifying a reviewed package version, integrity hash, lockfile, or verified package source. If `clawhub` is not already available locally, `npx` can retrieve the current package from the configured package registry and immediately execute its command-line entry point.

Consequently, the code that executes can differ from the code reviewed when this skill was published. Registry compromise, package-owner compromise, dependency compromise, or unexpected changes in a newer release could introduce arbitrary code into the installation process.

The alternative `clawhub` command is also not tied to a documented binary location or verified version, although it is less directly indicative of on-demand retrieval.

### Attack Path

1. An attacker compromises the package, package publisher, registry account, or a transitive dependency used by the retrieved `clawhub` release.
2. The attacker publishes a malicious or altered release that is selected by the unpinned command.
3. A user follows the installation instructions and runs `npx clawhub install stock-investment-advisor`.
4. `npx` retrieves the mutable package content from the configured registry.
5. The retrieved command-line package executes with the privileges of the invoking user.
6. Malicious code can access or modify any resources available to that user.

### Impact Assessment

Successful exploitation permits arbitrary code execution under the account that runs the installation c
...[truncated 411 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an explicitly reviewed version rather than allowing the registry to select the current release.
  2. Document the official package registry, publisher identity, and source repository.
  3. Verify package integrity using a lockfile and registry integrity metadata or a separately published cryptographic checksum.
  4. Prefer a previously installed and verified ClawHub binary instead of retrieving executable code through npx during installation.
  5. Review both direct and transitive dependencies before recommending a release.
  6. Avoid running installation commands with elevated privileges.
  7. Document a secure update process so that new versions are reviewed before the pinned version is changed.

T07 · Tool Hijacking and Spoofing

Warning
Location
README.md:25
Finding

Working-Directory-Relative Execution of an Absent Restart Script

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 25-30
Vulnerability Type: T07: Tool Hijacking and Spoofing
Risk Level: Medium

Vulnerable Code

bash
# 2. Restart OpenClaw
openclaw gateway restart
# or
sh scripts/restart.sh

Technical Analysis

The documentation presents sh scripts/restart.sh as a restart alternative, but the audited project does not contain scripts/restart.sh. The shell therefore resolves the path relative to the user's current working directory rather than to a validated script bundled with the skill.

If a file exists at that relative path in the current directory, sh executes it without verifying its origin, ownership, integrity, or relationship to this project. An attacker who can influence the directory contents could place a malicious script at the expected path and rely on the legitimate-looking documentation to induce its execution.

If no such file exists, the command only fails. Exploitation therefore requires an attacker-controlled or otherwise untrusted scripts/restart.sh to be present in the directory from which the user runs the command.

Attack Path

  1. An attacker gains the ability to place files in, distribute, or otherwise influence a directory from which the victim may follow the installation instructions.
  2. The attacker creates scripts/restart.sh in that directory and inserts arbitrary shell commands.
  3. The victim follows the documented restart procedure and selects the fallback command.
  4. The shell resolves scripts/restart.sh against the victim's current working directory.
  5. sh executes the attacker-controlled file with the victim's permissions.

Impact Assessment

Successful exploitation results in arbitrary shell command execution with the privileges of the user following the instructions. An attacker could modify user files, alter OpenClaw configuration, replace installed skills or tools, read user-accessible data ...[truncated 205 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the sh scripts/restart.sh fallback because that file is not included in the project.
  2. Prefer the explicit openclaw gateway restart command when it is the supported restart mechanism.
  3. If a restart script is required, include it in the package and subject it to the same security review as the other project files.
  4. Resolve the script from a validated absolute skill-installation directory rather than from the current working directory.
  5. Before execution, verify that the script is a regular file, is owned by the expected user or administrator, is not a symbolic link, and matches a published integrity checksum.
  6. Clearly instruct users not to run restart or installation commands from untrusted or attacker-writable directories.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises external market-data retrieval and Feishu cloud document generation but does not clearly warn users that prompts, stock selections, screenshots, or generated analysis may be transmitted to third-party services. In a finance-oriented skill, this creates privacy and data-governance risk because users may share sensitive portfolio interests or proprietary research without realizing it will leave the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are very broad conversational stock-analysis requests, which increases the chance of unintentional activation during normal discussion. In a skill that performs external data access and report generation, ambiguous activation boundaries can cause unintended tool use, data fetching, or document creation without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to create a Feishu cloud document containing the investment analysis, but it does not require obtaining user consent or warning that the report content may be sent to a third-party cloud service. Because the workflow may include user-provided holdings, screenshots, and derived financial analysis, this can cause unintended external disclosure of sensitive personal or proprietary data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.