T09 · Insecure Skill Coding Practices
- Location
skill.json:20- Finding
Shell Command Injection Through Unquoted Skill Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This affiliate recommendation skill is mostly coherent, but it needs review because it can run user text through unsafe command templates and documents plaintext/public API paths.
Review before installing. Use it only if you accept affiliate-driven recommendations, avoid sending sensitive queries to the documented HTTP endpoint, narrow the triggers, and ensure the runtime passes parameters as structured arguments instead of shell-interpolated strings. Do not run the included API server on a public interface without TLS, authentication, and request limits.
skill.json:20Shell Command Injection Through Unquoted Skill Parameters
SKILL.md:18External API Requests Are Documented Over Plaintext HTTP
api_server.py:29Public HTTP Server Accepts Unbounded Request Bodies
The README explicitly frames the skill as recommending SaaS products with affiliate links, but it does not instruct the agent or operator to disclose that recommendations are monetized. This creates a conflict-of-interest and transparency risk: users may believe results are impartial when they are financially influenced, which can mislead purchasing decisions and undermine trust.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill explicitly transmits data to an external IP-based service over unsecured HTTP, creating a clear external transmission channel. In an agent setting, this is especially dangerous because user queries can include sensitive operational context, and plaintext transport allows eavesdropping, manipulation of responses, or silent redirection to malicious recommendations.
# 搜索推荐
curl -X POST http://43.163.220.15:8888/ \
-H "Content-Type: application/json" \
-d '{"method": "search", "params": {"query": "OpenCLAW 编程"}}'
The skill instructs the agent to send user queries to an external HTTP endpoint without any privacy notice, consent flow, or transport security guarantees. This is dangerous because user prompts may contain sensitive project names, internal tooling details, or other private context, and the use of plain HTTP enables interception or tampering in transit.
The trigger conditions are very broad and overlap with ordinary recommendation requests, which can cause the skill to activate in situations where users did not explicitly intend to use it. In this context, overbroad triggering is risky because the skill steers users toward externally sourced recommendations and links, increasing the chance of unsolicited promotion or data being sent off-platform.
This code starts a network-accessible HTTP service on 0.0.0.0 and allows remote callers to invoke backend functions, but provides no warning beyond a startup banner. There is no confirmation, descriptive docstring, or comment disclosing that the skill opens a remotely reachable API surface for other agents.
The module docstring and subsequent user-facing descriptions are written in Chinese, and the tool metadata exposed over MCP also uses Chinese descriptions. This creates a language-specific experience without indicating that users can choose another language or locale, which matches the policy category for forced language/locale behavior.
This JSON entry presents the product description, category, reason, tagline, commission text, and keywords in Chinese, indicating a fixed language choice in the skill's natural-language content. The file does not offer any user opt-in, alternative locale, or justification that the skill is intentionally region-specific, which matches the locale-policy concern for natural-language policy violations.
Multiple subsequent entries use Chinese-language descriptions, categories, keywords, and marketing text across the catalog, reinforcing that the file enforces one locale by default. Because no alternative language fields or scope limitations are documented here, this is a repeated natural-language locale policy issue rather than an isolated wording choice.
The function update_affiliate_link claims updates require administrator permission, but it performs the modification unconditionally for any caller that can invoke the function. This creates an authorization bypass that lets an untrusted agent or user alter stored affiliate destinations, enabling traffic hijacking, fraud, or redirection to malicious links.
The update_affiliate_link function overwrites products.json, changing persisted affiliate data, but there is no confirmation prompt, logging, or warning to the user at the point of the write. Although the docstring notes admin permission is needed, it does not disclose the concrete file modification behavior to an end user invoking the skill.
The trigger list includes very broad, common terms such as “推荐”, “工具”, “编程”, and “开发”, which can cause the skill to activate in many unrelated conversations. This increases the chance of unintended invocation, context hijacking, or unnecessary execution of linked commands, especially because the skill can run scripts with user-provided parameters.
The top-level natural-language description states the skill purpose only in Chinese and the rest of the user-facing docstrings/messages are also Chinese, implying a fixed language choice. There is no indication that users can opt into another language or locale, which may violate language/locale policy requirements.
This skill’s stated purpose is recommending SaaS products and returning affiliate links, but it also includes a local file-modification path that can rewrite product metadata. That broadens the attack surface unnecessarily: if exposed through an agent, a prompt-influenced or unauthorized caller could persistently change future outputs and affiliate destinations.
The code exposes a state-changing function that updates affiliate links and marks products active, yet performs no authentication, authorization, or caller verification despite claiming admin privileges are required. In an agent/tooling context, any caller able to invoke this function could tamper with recommendations, redirect users to attacker-controlled links, or silently alter business data.
The function writes directly to the products data file without any user-facing confirmation, safety interlock, or review step. In an agent setting, this increases the risk of accidental or prompt-induced persistent changes, especially when the modified field controls outbound affiliate URLs shown to users.
The README consistently uses Chinese for instructions, examples, and interaction text, including sample user prompts, without indicating that other languages are supported or that Chinese-only use is intentional for a region-specific skill. Under the language/locale policy, forcing a specific language without opt-in or justification can be a natural-language policy violation.
该技能的标题、用途、触发场景、输出示例和关键词均以中文固定表达,未说明是否仅面向中文用户,也未提供其他语言选项。若组织要求不得在无用户选择情况下强制特定语言,这种单一语言约束可能构成自然语言策略问题。
The top-level natural-language description is entirely in Chinese and does not indicate that language is configurable or intentionally region-specific. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation.
The module description is written as a Chinese-only behavioral statement and provides no indication that language is selectable or based on user preference. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.
The skill's natural-language description and command descriptions are entirely in Chinese, and the manifest does not indicate that language is optional or region-specific. This can amount to a locale/language policy issue when users are not given an explicit language choice or opt-in.
No suspicious patterns detected.