Back to skill

Security audit

Ai Dev Tools

Security checks for vulnerabilities and agentic risk

Overview

This affiliate recommendation skill is mostly coherent, but it needs review because it can run user text through unsafe command templates and documents plaintext/public API paths.

Review before installing. Use it only if you accept affiliate-driven recommendations, avoid sending sensitive queries to the documented HTTP endpoint, narrow the triggers, and ensure the runtime passes parameters as structured arguments instead of shell-interpolated strings. Do not run the included API server on a public interface without TLS, authentication, and request limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skill.json:20
Finding

Shell Command Injection Through Unquoted Skill Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:18
Finding

External API Requests Are Documented Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api_server.py:29
Finding

Public HTTP Server Accepts Unbounded Request Bodies

Content
View full analysis
Remediation
View remediation
MAX_BODY_SIZE: self.send_error(413, "Request body too large") return ``` - Configure read and idle timeouts so slow clients cannot hold a connection indefinitely. - Place externally reachable deployments behind a hardened reverse proxy that provides TLS, authentication, request-size limits, connection limits, and rate limiting. - Use a concurrency-capable production server where appropriate, while retaining strict global resource limits so concurrency does not amplify exhaustion. - Return appropriate client error responses for malformed JSON and unsupported media types rather than exposing internal exception text. - Run the service with minimal operating-system privileges and container memory limits. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly frames the skill as recommending SaaS products with affiliate links, but it does not instruct the agent or operator to disclose that recommendations are monetized. This creates a conflict-of-interest and transparency risk: users may believe results are impartial when they are financially influenced, which can mislead purchasing decisions and undermine trust.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The skill explicitly transmits data to an external IP-based service over unsecured HTTP, creating a clear external transmission channel. In an agent setting, this is especially dangerous because user queries can include sensitive operational context, and plaintext transport allows eavesdropping, manipulation of responses, or silent redirection to malicious recommendations.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

bash
# 搜索推荐
curl -X POST http://43.163.220.15:8888/ \
  -H "Content-Type: application/json" \
  -d '{"method": "search", "params": {"query": "OpenCLAW 编程"}}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to send user queries to an external HTTP endpoint without any privacy notice, consent flow, or transport security guarantees. This is dangerous because user prompts may contain sensitive project names, internal tooling details, or other private context, and the use of plain HTTP enables interception or tampering in transit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are very broad and overlap with ordinary recommendation requests, which can cause the skill to activate in situations where users did not explicitly intend to use it. In this context, overbroad triggering is risky because the skill steers users toward externally sourced recommendations and links, increasing the chance of unsolicited promotion or data being sent off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code starts a network-accessible HTTP service on 0.0.0.0 and allows remote callers to invoke backend functions, but provides no warning beyond a startup banner. There is no confirmation, descriptive docstring, or comment disclosing that the skill opens a remotely reachable API surface for other agents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and subsequent user-facing descriptions are written in Chinese, and the tool metadata exposed over MCP also uses Chinese descriptions. This creates a language-specific experience without indicating that users can choose another language or locale, which matches the policy category for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON entry presents the product description, category, reason, tagline, commission text, and keywords in Chinese, indicating a fixed language choice in the skill's natural-language content. The file does not offer any user opt-in, alternative locale, or justification that the skill is intentionally region-specific, which matches the locale-policy concern for natural-language policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Multiple subsequent entries use Chinese-language descriptions, categories, keywords, and marketing text across the catalog, reinforcing that the file enforces one locale by default. Because no alternative language fields or scope limitations are documented here, this is a repeated natural-language locale policy issue rather than an isolated wording choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function update_affiliate_link claims updates require administrator permission, but it performs the modification unconditionally for any caller that can invoke the function. This creates an authorization bypass that lets an untrusted agent or user alter stored affiliate destinations, enabling traffic hijacking, fraud, or redirection to malicious links.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The update_affiliate_link function overwrites products.json, changing persisted affiliate data, but there is no confirmation prompt, logging, or warning to the user at the point of the write. Although the docstring notes admin permission is needed, it does not disclose the concrete file modification behavior to an end user invoking the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very broad, common terms such as “推荐”, “工具”, “编程”, and “开发”, which can cause the skill to activate in many unrelated conversations. This increases the chance of unintended invocation, context hijacking, or unnecessary execution of linked commands, especially because the skill can run scripts with user-provided parameters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level natural-language description states the skill purpose only in Chinese and the rest of the user-facing docstrings/messages are also Chinese, implying a fixed language choice. There is no indication that users can opt into another language or locale, which may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill’s stated purpose is recommending SaaS products and returning affiliate links, but it also includes a local file-modification path that can rewrite product metadata. That broadens the attack surface unnecessarily: if exposed through an agent, a prompt-influenced or unauthorized caller could persistently change future outputs and affiliate destinations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code exposes a state-changing function that updates affiliate links and marks products active, yet performs no authentication, authorization, or caller verification despite claiming admin privileges are required. In an agent/tooling context, any caller able to invoke this function could tamper with recommendations, redirect users to attacker-controlled links, or silently alter business data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function writes directly to the products data file without any user-facing confirmation, safety interlock, or review step. In an agent setting, this increases the risk of accidental or prompt-induced persistent changes, especially when the modified field controls outbound affiliate URLs shown to users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README consistently uses Chinese for instructions, examples, and interaction text, including sample user prompts, without indicating that other languages are supported or that Chinese-only use is intentional for a region-specific skill. Under the language/locale policy, forcing a specific language without opt-in or justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

该技能的标题、用途、触发场景、输出示例和关键词均以中文固定表达,未说明是否仅面向中文用户,也未提供其他语言选项。若组织要求不得在无用户选择情况下强制特定语言,这种单一语言约束可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level natural-language description is entirely in Chinese and does not indicate that language is configurable or intentionally region-specific. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module description is written as a Chinese-only behavioral statement and provides no indication that language is selectable or based on user preference. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill's natural-language description and command descriptions are entirely in Chinese, and the manifest does not indicate that language is optional or region-specific. This can amount to a locale/language policy issue when users are not given an explicit language choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.