Back to skill

Security audit

Aloudata CAN SKILLS - metric-query

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Aloudata metric-query helper that uses a user-provided API key to call a whitelisted analytics gateway, with some privacy and credential-handling caveats but no hidden or destructive behavior found.

Install only if you trust Aloudata's Gateway with the metric names, dimension values, filters, and query bodies you ask the agent to use. Configure CAN_API_KEY as a dedicated, least-privilege key, prefer the X-API-Key header only, and avoid putting secrets or highly sensitive business identifiers into prompts unless they are intended for that Gateway.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:38
Finding

API Key May Be Transmitted Through a URL Query Parameter

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 38
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code Snippet

markdown
**认证方式**:所有请求必须携带 API Key,通过请求头 `X-API-Key` 传递(也可通过 `?apikey=` 查询参数传递)。**返回格式为纯文本**,非 JSON。

The instruction states that the API key may be supplied through the apikey URL query parameter, even though header-based authentication is available.

Technical Analysis

Secrets transmitted in URL query strings are more likely to be retained outside the intended authentication boundary. The complete URL may be recorded by gateway and reverse-proxy access logs, observability platforms, request traces, shell history, debugging output, and intermediary infrastructure.

This behavior is not required for the Skill's declared functionality because the same API supports the X-API-Key header, which the remainder of the Skill already uses. Permitting query-string authentication therefore exceeds the minimum credential exposure necessary to execute metric searches and queries.

No hardcoded key was found. The Skill otherwise reads only the dedicated CAN_API_KEY environment variable and restricts declared outbound access to gateway.can.aloudata.com.

Attack Path

  1. An agent or user follows the documented ?apikey= authentication option.
  2. The shell expands or otherwise inserts the CAN_API_KEY value into the request URL.
  3. The complete URL is retained in local command history, gateway logs, proxy logs, monitoring telemetry, or request traces.
  4. A party with access to one of those records extracts the API key.
  5. The exposed key is replayed against gateway.can.aloudata.com.
  6. The attacker performs metric searches, dimension discovery, or authenticated metric queries within the permissions granted to the compromised key.

Impact Assessment

Successful exploitation grants the attacker the same gateway privileges as the exposed API key. Depending on the ...[truncated 425 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the documented ?apikey= authentication option.
  2. Require authentication exclusively through the X-API-Key request header.
  3. Preserve the existing environment-variable approach and never place the expanded key directly in a command-line URL.
  4. Ensure diagnostic output, traces, and error reports redact X-API-Key values.
  5. Avoid displaying commands after shell expansion or enabling execution tracing while authenticated requests run.
  6. Configure the gateway and intermediary infrastructure to reject query-string API keys.
  7. Review available access, proxy, and observability logs for previously recorded apikey parameters; redact or delete affected records according to retention policy.
  8. Rotate any key that may previously have been transmitted in a URL.
  9. Apply least-privilege server-side scopes, expiration, and rotation policies to CAN_API_KEY.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are extremely broad and mandate use of this skill for many generic analytics phrases, which can cause the agent to invoke external-network behavior when a narrower or safer response would suffice. Because the skill has network:outbound and env:read permissions, over-triggering increases the chance of unnecessary transmission of user query content and API-key-backed requests to the external Gateway.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description and operating instructions are written to interpret user requests specifically through Chinese semantic rules, including multiple sections about understanding '用户的中文' and fixed Chinese phrasing behavior. There is no opt-in choice for language or documented reason that the skill must operate only in Chinese, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to send user-derived keywords and queries to an external service using a configured API key, but it does not prominently warn the user about that data flow. This creates a privacy and transparency issue: users may disclose sensitive business terms, filters, or identifiers without understanding that the content will be transmitted off-platform.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill explicitly instructs outbound requests to gateway.can.aloudata.com and requires attaching X-API-Key from an environment variable, meaning user-supplied query terms and derived business context are transmitted to a third party. In this skill context, external transmission is expected functionality, but it is still security-relevant because it combines network egress with secret-backed authentication and can expose sensitive analytical intent or business metadata.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
**⚠️ 调用 Gateway 的两条铁律**:
1. **所有请求必须加 API Key 认证头 `-H "X-API-Key: $CAN_API_KEY"`**,`$CAN_API_KEY` 从环境变量读取(用户需在 `~/.openclaw/.env` 中配置 `CAN_API_KEY=cgk-xxxxxxxx`),未携带或无效 Key 将返回 401
2. **URL 中文参数必须 URL 编码**,使用 `--data-urlencode` + `-G` 让 curl 自动编码,禁止中文直接拼入 URL

> 示例:
> ```bash

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This instruction operationalizes external transmission by extracting keywords from the user's request and sending them to the Gateway API. Even though the domain is whitelisted and the behavior is part of the skill's purpose, it still creates a data-exposure surface for potentially confidential metric names, dimensions, and business questions, especially because the skill mandates this lookup before building queries.

Content

Scanner excerpt · SKILL.md (reported line 702)May include surrounding context.

从用户问题中提取核心业务关键词,调用 Gateway API 搜索指标:

bash
curl -H "X-API-Key: $CAN_API_KEY" "https://gateway.can.aloudata.com/api/metrics/search?pageSize=10" --data-urlencode "keyword={关键词}" -G

从返回结果中取 metricName 放入 metrics 数组。校验: status 须为 ONLINE。

Static analysis

No suspicious patterns detected.