T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:43- Finding
Private note operations rely on optional sender authorization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This note-taking skill is mostly coherent, but it handles private notes and long-lived credentials with several under-scoped safeguards that users should review before installing.
Install only if you are comfortable granting this skill access to your private Get笔记 notes. Configure GETNOTE_OWNER_ID before using it in shared or group chats, avoid using the helper scripts with sensitive local paths, treat OAuth output as secret, and prefer ClawHub installation over the README's raw GitHub curl method.
SKILL.md:43Private note operations rely on optional sender authorization
scripts/oauth_poll.py:97OAuth API key is exposed through process standard output
scripts/upload_image.py:53Image uploader can transmit arbitrary local files to an unvalidated server-provided host
README.md:111Manual installation retrieves mutable Skill instructions without integrity verification
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The README presents all user prompts, examples, and operational instructions exclusively in Chinese, with no indication that language choice is optional. This can amount to a language-policy violation if the skill expects or defaults to a specific language without offering user choice or documenting a justified locale restriction.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/workspace/skills/getnote
cd ~/.openclaw/workspace/skills/getnote
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/SKILL.md -o SKILL.md
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/package.json -o package.json
The skill advertises very broad natural-language triggers such as generic save/search/manage-note phrasing, which can cause the agent to invoke the skill on ambiguous user messages without clear intent confirmation. For a note-taking integration that can store private content and retrieve personal notes, overbroad activation increases the chance of unintended data disclosure or unintended writes.
The skill declares network, environment-variable, and shell-like capabilities but does not constrain them with an explicit tool/permission allowlist. In an agent setting, missing scope boundaries can let the skill invoke more powerful primitives than users would reasonably expect, increasing the blast radius for prompt injection, data exfiltration, or unintended side effects.
The trigger phrases for invoking the skill are overly broad, including common conversational words like '保存' or '收藏'. In an agent environment, this can cause accidental invocation on unrelated user messages, leading to unintended network calls, storage of private content, or note operations the user did not mean to perform.
The file states that the agent should verify sender_id against GETNOTE_OWNER_ID before operating on private notes, but this protection is only documented and not enforced in executable logic here. If the runtime does not independently implement that check, another user in a shared context could trigger read/write operations against the owner's private notes.
The natural-language router uses single characters and very common verbs such as '记', '存', '搜', and '看看' as dispatch triggers without robust boundaries. This makes false positives likely and increases the chance of unauthorized or privacy-impacting actions being taken from ordinary conversation, especially in multi-turn or shared-chat contexts.
The package description includes very broad natural-language trigger phrases such as '说「记一下」就能存,说「搜一下」就能找', which can overlap with ordinary user conversation and cause unintended invocation. In a note-taking skill, accidental activation is risky because it may capture, store, or search private user content without sufficiently explicit intent.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. 获取上传凭证
curl 'https://openapi.biji.com/open/api/v1/resource/image/upload_token?mime_type=jpg&count=1' \
-H 'X-Client-ID: {client_id}' \
-H 'Authorization: {api_key}'
The documentation includes a delete-note operation but does not require any explicit user-facing confirmation or warning before performing a destructive action. In an agent context, this increases the chance that ambiguous user input, prompt injection, or UI misunderstanding could cause unintended note deletion, even if the API only moves items to trash.
The skill instructs the agent to automatically initiate OAuth Device Flow before every API call whenever $GETNOTE_API_KEY is absent, even if the user did not explicitly request account linking. That creates an overly broad auth trigger that can surprise users, condition them to approve authorization prompts in unrelated contexts, and potentially cause unintended account connection or consent fatigue.
This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. The policy requires flagging forced language or locale behavior when no opt-in or justification is provided.
The trigger examples for global search are broad conversational phrases like “搜一下” and “找找我哪些笔记提到了 XX”, which can overlap with ordinary user requests that do not clearly intend to query a personal note store. In a note-management skill, this can cause unintended retrieval of private notebook content and unnecessary data exposure if the agent invokes the search API without explicit user confirmation or namespace grounding.
The module docstring, usage instructions, and runtime messages are entirely in Chinese, which imposes a specific language on all users. Under the policy, locale or language restrictions should either provide user opt-in/choice or be clearly justified as region-specific; neither is present here.
This Python code reads a user-supplied local image file and transmits both the file contents and API credentials to remote endpoints. Although the script prints progress messages, it does not clearly warn the user that local data will be uploaded to an external service, which is the kind of disclosure SQP-2 expects for network transmission of user data.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
print(f"访问 URL: {image_url}")
print()
print("💡 创建图片笔记:")
print(f' curl -X POST "https://openapi.biji.com/open/api/v1/resource/note/save?task_id=..."')
print(f' -H "Authorization: $GETNOTE_API_KEY"')
print(f' -H "Content-Type: application/json"')
print(f' -d \'{{"type":"img_text","image_urls":["{image_url}"]}}\'')
文件中的触发短语、指令示例和固定回复语均以中文为唯一语言呈现,例如“不匹配时回复‘抱歉,笔记是私密的,我无法操作’”。这会形成默认语言约束,但文档未说明可根据用户语言偏好切换,也未提供显式语言选择。
The manifest describes the skill as saving, searching, and managing personal notes and knowledge bases, but the documented command set also includes deleting notes, blogger subscriptions, live subscriptions, and credential configuration flows. These are broader operational capabilities than the short manifest description suggests, even though they appear intentionally supported by the skill.
The file title and all surrounding instructional text are presented in Chinese, which effectively forces a specific language for users consuming this skill documentation. Under the policy, language constraints should either provide user choice or be clearly justified as region-specific.
This markdown file describes an operation to remove notes from a knowledge base, but the section provides no user-facing warning about the action affecting stored organization of user data or whether the removal is reversible. Under the markdown-specific warning rule, destructive or data-affecting behavior should be disclosed clearly in the skill description.
整个技能说明与示例对话均固定为中文表达,未说明是否支持按用户偏好切换语言或 locale。按规则,若技能在自然语言层面强制单一语言且无用户选择机制,可能构成语言/locale 政策风险。
The knowledge-base search guidance says it applies when the user says “在我的 XX 知识库搜一下 XX”, but it does not define how confidently the agent must map a natural-language name to a specific topic_id or what to do when multiple matches exist. This ambiguity can lead to searching the wrong knowledge base, causing minor privacy leakage across a user’s own collections or returning misleading results.
This markdown file documents POST actions that add and delete note tags, which are user-data modifications. While the file explains request/response details and notes that system tags cannot be deleted, it does not explicitly warn users that invoking these operations will change note metadata.
The script's docstrings, help text, and console messages are presented in Chinese, which imposes a specific language on users without any choice or documented locale constraint. Under SQP-3, forcing a language/locale without opt-in is a natural-language policy concern.
No suspicious patterns detected.