Back to skill

Security audit

Onebot Adapter 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This QQ/OneBot skill is mostly coherent, but it exposes high-impact group moderation actions and logs private message data without enough safeguards or warning.

Install only if you intend to give the agent access to a OneBot server and are comfortable with it sending messages and potentially performing group administration through the bot account. Keep endpoints on localhost or protected TLS connections, use a narrowly scoped token where possible, avoid running the sample listener in production with full-event logging, and do not adopt the group-management example without explicit admin checks, approved group allowlists, confirmation, and audit logging.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/onebot_ws_listener.py:73
Finding

Unredacted Logging of Private OneBot Events and Message Content

Content
View full analysis
Remediation
View remediation
dict: return { "post_type": event.get("post_type"), "message_type": event.get("message_type"), "notice_type": event.get("notice_type"), } logger.debug("Received OneBot event: %s", summarize_event(event)) ``` ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/message-handling.md:76
Finding

Privileged Group-Management Example Omits Sender Authorization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/onebot_client.py:21
Finding

Bearer Credentials and QQ Data Can Be Transmitted over Plaintext Connections

Content
View full analysis
Dict[str, Any]: """Make HTTP request to OneBot API""" url = f"{self.base_url}{endpoint}" try: if method == "GET": resp = requests.get(url, headers=self.headers, timeout=10) else: resp = requests.post(url, headers=self.headers, json=data, timeout=10) ``` The WebSocket listener has the same behavior: ```python self.ws_url = ws_url or os.getenv("ONEBOT_WS_URL", "ws://127.0.0.1:3001") self.token = token or os.getenv("ONEBOT_TOKEN", "") ``` ```python headers = {} if self.token: headers["Authorization"] = f"Bearer {self.token}" while self.running: try: print(f"Connecting to {self.ws_url}...") async with websockets.connect(self.ws_url, extra_headers=headers) as ws: print("Connected to OneBot WebSocket server") ``` ### Technical Analysis The clients support `http://` and `ws://` endpoints and attach the authorization token regardless of whether transport encryption is present. Plain HTTP and WebSocket traffic provide no confidentiality against an a ...[truncated 2211 chars]
Remediation
View remediation
None: parsed = urlparse(url) host = parsed.hostname if parsed.scheme in secure_schemes: return try: is_loopback = ipaddress.ip_address(host).is_loopback except ValueError: is_loopback = host == "localhost" if not is_loopback: raise ValueError("TLS is required for non-loopback OneBot endpoints") ``` Use `{"https"}` for the HTTP client and `{"wss"}` for the WebSocket listener. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs users to use environment variables and make network connections to local WebSocket/HTTP OneBot endpoints, but it does not declare any tool scope such as permissions or allowed-tools. This creates a trust and containment gap: an agent may gain undeclared access to environment secrets and network endpoints, making the skill capable of interacting with local services or exfiltrating sensitive configuration without explicit authorization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file includes an example handler that removes a group member when a matching message is received, but the surrounding documentation does not warn that the pattern performs a destructive moderation action. For markdown files, examples that can affect user access or system integrity should disclose the impact so users understand the consequence before adopting the pattern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code automatically reads ONEBOT_TOKEN from the environment and attaches it to outbound requests, but there is no disclosure, consent flow, or trust restriction on the destination URL. If base_url is changed to an untrusted host, the bearer token will be transmitted to that host, potentially leaking credentials or authorizing unintended actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/onebot_client.py (reported line 39)May include surrounding context.

python
if method == "GET":
                resp = requests.get(url, headers=self.headers, timeout=10)
            else:
                resp = requests.post(url, headers=self.headers, json=data, timeout=10)
            
            resp.raise_for_status()
            return resp.json()

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The client exposes group-administration operations such as kicking users, banning users, and changing group metadata in a skill described primarily as QQ messaging integration. These capabilities materially expand the action surface from message transport into moderation and configuration, so a caller that gains access to this skill can perform destructive administrative actions not obviously required by the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Group moderation and configuration methods are present without clear justification from the stated 'sending/receiving QQ messages' purpose. This mismatch increases the risk of over-privileged use, where downstream agents or users may invoke administrative endpoints unintentionally or without understanding they can alter group state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides destructive moderation actions such as kicking and banning users with no confirmation, approval step, or safety interlock. In an agent context, this creates a direct path from prompt or automation mistakes to irreversible or harmful group-management actions against real users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The listener logs entire inbound events, which can include message contents, user IDs, group IDs, and other sensitive metadata. In a QQ/OneBot integration context, this can leak private communications and identifiers into console logs, process supervisors, or centralized log collectors, expanding data exposure well beyond the bot itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The private-message handler automatically responds via an API call when it receives a matching message. The code comments describe the action, but there is no clear user-facing warning that running this listener can cause automatic outbound messaging based on incoming private messages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example only responds to the Chinese trigger 帮助, which imposes a specific language expectation in natural-language behavior. Because no opt-in, alternative language handling, or locale-specific justification is provided, this may violate language/locale policy guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.