Back to skill

Security audit

AI离谱甲方

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but its payment and local data handling are insecure enough that users should review it before installing.

Install only if you are comfortable with a review-required paid-skill implementation. Do not put sensitive business or personal information in prompts, and do not rely on this package's payment checks for real billing until fail-closed verification, server-side receipt validation, secret removal, restrictive file permissions, and order path validation are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
server/server.py:173
Finding

Payment Verification Fails Open When Credential Decryption Fails

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
server/server.py:17
Finding

Hardcoded Symmetric Key Allows Forgery of Successful Payment Credentials

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/file_utils.py:13
Finding

Unvalidated Order Identifier Permits Reads Outside the Order Directory

Content
View full analysis
dict: base_dir = get_orders_base_dir(indicator) json_path = os.path.join(base_dir, f"{order_no}.json") if not os.path.isfile(json_path): raise RuntimeError(f"订单文件不存在: {json_path}") with open(json_path, "r", encoding="utf-8") as f: return json.load(f) ``` The value reaches this function directly from a command-line argument: ```python parser.add_argument("order_no", help="订单号") args = parser.parse_args() indicator = compute_indicator(SLUG) try: order_data = load_order(indicator, args.order_no) ``` ### Technical Analysis The caller-controlled `order_no` is inserted into a filesystem path without validating that it matches the numeric order-number format generated by the server. Values containing `../` can traverse above the order directory. On supported platforms, an absolute path can also cause `os.path.join()` to discard the intended base directory. The automatically appended `.json` extension limits targets to paths ending in that extension, and `json.load()` requires valid JSON. These restrictions do not prevent access to sensitive JSON configuration, credentials, or state files available to the process. After loading the unintended file, the script extracts `question` and `payCredential`. If those fields exist, their values are submitted to the local result service. ### Attack Path 1. Invoke `client_service.py` with an order identifier containing traversal segments or an absolute path. 2. The script appends `.json` and joins the value without canonicalization or containment verification. 3. The resulting path resolves outside `~/.openclaw/skills/orders//`. 4. If the target exists, is readable, and contains valid JSON, the script loads it. 5. If the JSON ...[truncated 688 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/file_utils.py:23
Finding

Payment and Order Data Are Stored Without Explicit Restrictive Permissions

Content
View full analysis
str: base_dir = get_orders_base_dir(indicator) os.makedirs(base_dir, exist_ok=True) json_path = os.path.join(base_dir, f"{order_no}.json") with open(json_path, "w", encoding="utf-8") as f: json.dump(order_data, f, ensure_ascii=False, indent=2) return json_path ``` ### Technical Analysis The order directory and JSON files are created using default permissions derived from the process umask. The code does not explicitly require owner-only access. Order records contain user-supplied prompt content and payment metadata. The declared workflow also expects the payment process to place `payCredential` in the order file before the final service phase. Consequently, these files can become credential-bearing security assets. On a system with a permissive umask or shared home-directory access, files may be readable by other local users or processes. Existing files are also overwritten without checking ownership, file type, symlink status, or permissions. ### Attack Path 1. The Skill creates an order directory and JSON file under the user's OpenClaw directory. 2. The runtime environment applies a permissive umask, causing the directory or file to be group-readable or world-readable. 3. The payment workflow adds or stores sensitive payment credential data in the order record. 4. Another local user or process reads the file and obtains the prompt, payment metadata, or credential. 5. If an attacker can pre-position a symlink at the expected path, normal write behavior may also target an unintended file accessible to the process. ### Impact Assessment A local attacker may gain access to user prompts, order details, payment routing metadata, and payment credentials. The scope is lim ...[truncated 356 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A payment-gated service becomes security-relevant if access is granted when credential decryption or parsing fails. Fail-open payment verification lets attackers bypass the paywall and may also indicate unsafe handling of authentication material, undermining both revenue protection and trust in the credential-validation path.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A payment-gated service becomes security-relevant if access is granted when credential decryption or parsing fails. Fail-open payment verification lets attackers bypass the paywall and may also indicate unsafe handling of authentication material, undermining both revenue protection and trust in the credential-validation path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill description says payment verification is required before execution, but the code falls back to generate_local(question) whenever the backend request fails or verification cannot be completed. That means a user can still obtain the paid service output during backend outage, network failure, or by intentionally disrupting verification, which bypasses the paywall and undermines business controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The payment gate is enforced only by decrypting a client-supplied credential and checking whether the decrypted JSON says payStatus=SUCCESS. There is no signature, MAC, server-side receipt validation, or binding to the stored order, so anyone who can produce a locally decryptable blob can mark payment as successful and obtain the paid result without actually paying.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The payment gate is effectively bypassed because any credential decryption or parsing failure falls through to pay_status = "SUCCESS". An attacker can submit malformed or random credential data and still receive paid results, directly defeating the stated requirement that payment verification must occur before execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The core description is entirely in Chinese and presents the skill behavior and usage in that language, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking locale. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code transmits the user's question, order number, and payment credential to a backend over plain HTTP, which provides no transport encryption. On any non-localhost deployment, this would expose potentially sensitive data to interception or manipulation; even in local setups, the pattern is unsafe and can normalize insecure handling of credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file presents its purpose and user-facing interface entirely in Chinese, beginning with the module docstring on L02 and continuing through other user-facing strings. The policy requires avoiding a forced language/locale unless the skill offers user choice or clearly documents a justified region-specific constraint, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script transmits the user's question to a create-order API over plain HTTP, not HTTPS, and does so without an explicit privacy warning. This creates a real confidentiality risk because user-supplied text can be intercepted or modified by a local network attacker, proxy, or compromised host service, especially since the question may contain sensitive work details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script stores the user's free-form question in order records without any visible notice, minimization, or consent step. Because prompts may contain personal, proprietary, or sensitive business information, silent persistence increases privacy and data-retention risk if local storage is later accessed, exfiltrated, or reused beyond the user's expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Java code contains multiple fixed Chinese-language response messages and generated content, starting with the error text at L038-L039 and continuing throughout the controller. The file provides no indication that users can opt into Chinese or select another locale, which violates the language/locale policy criterion for natural-language content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The answer is generated from the question value supplied in the getResult request instead of the question originally stored with the order. This lets a user pay once, then submit different prompts at retrieval time, bypassing the intended binding between payment and purchased content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The response generator returns Chinese-language defaults, feedback text, reply text, internal monologue, and verdict strings regardless of the user's language preference. Because the file does not offer any locale selection or document a justified region-specific restriction, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's natural-language framing and responses are entirely Chinese and present the service as Chinese-language only, with no indication that users may choose another language or locale. This can violate the language/locale policy when a specific language is imposed without explicit opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code processes a user-supplied payment credential by decrypting it and interpreting payment status, but the file provides no user-facing disclosure, confirmation, or explanatory comment that sensitive payment data will be handled. For code files, handling sensitive credentials without any visible warning can qualify as missing user disclosure when the behavior is not surfaced to the user.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The inline 'simulation mode' behavior documents an intentional fallback that treats verification failure as payment success, which normalizes insecure behavior in production code. In the context of a paid service claiming mandatory payment verification, this materially increases the risk of unauthorized access and revenue loss.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The module docstring and CLI description present the script as simply generating absurd client feedback locally. In practice, the main behavior first performs order/payment-dependent backend retrieval, so the documentation omits and softens the payment-gated nature of the operation described by the manifest and implemented in code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring specifies the skill in Chinese and the program's user-facing strings are entirely Chinese, indicating a fixed language behavior. The file does not offer user language selection or explain that the skill is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The raised RuntimeError contains a Chinese-only message, which imposes a specific language on users without any opt-in or fallback. This is a natural-language policy concern because the file gives no indication that the skill is intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function creates directories and writes JSON order data to disk, which changes persistent user data. In this file there is no confirmation prompt, logging, print statement, or explanatory comment/docstring disclosing that the operation will create or overwrite files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.