Back to skill

Security audit

野龙虾

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Alibaba OSS uploader, but it needs review because it can send local files to cloud storage using user credentials without clear confirmation or safety scoping.

Install only if you intentionally want an agent to upload explicitly named local files to your Alibaba OSS bucket. Use a RAM access key limited to the target bucket, avoid uploading secrets or regulated data, verify bucket ACL and URL exposure, and pin the installer and oss2 dependency where possible. Be aware that running aliossupload.py directly with configured credentials can create and upload a test file/object.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded Python Dependency Version Permits Unreviewed Upstream Code

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1 and clawhub.yaml:27
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable code:

requirements.txt:1

text
oss2>=2.18.0

clawhub.yaml:27

yaml
requirements:
  - oss2>=2.18.0

Technical Analysis

The project accepts any oss2 version equal to or newer than 2.18.0. This open-ended constraint does not ensure that installations use the same dependency version that was reviewed and tested. A future release can therefore become part of the Skill without a corresponding source review.

The dependency is imported and used directly by aliossupload.py. It executes in the same Python process as the Skill and consequently inherits the process's operating-system privileges, environment variables, and network access. In normal use, those environment variables include the Aliyun OSS access-key ID and secret.

Exploitation requires compromise of the legitimate upstream package, its publisher account, or the package distribution channel. There is no evidence in the reviewed project that the current oss2 package is malicious.

Attack Path

  1. An attacker compromises the upstream oss2 distribution process or publisher account.
  2. The attacker publishes a malicious release with a version greater than 2.18.0.
  3. A user installs or updates the Skill in a clean or refreshed environment.
  4. The package resolver selects the malicious version because it satisfies oss2>=2.18.0.
  5. aliossupload.py imports oss2, causing attacker-controlled Python code to execute.
  6. The malicious dependency can read OSS credentials from the environment, access files available to the Skill process, and communicate over the network.

Impact Assessment

Successful exploitation would provide code execution with the privileges of the user or service running the Skill. The compromised dependency could access the ...[truncated 474 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin oss2 to a specifically reviewed version, for example oss2==2.18.x, using the exact version approved by the maintainer.
  • Generate a reproducible lock file that also pins all transitive dependencies.
  • Require package hashes during installation, such as through a hash-locked requirements file and pip install --require-hashes.
  • Perform dependency updates through an explicit review process rather than allowing automatic adoption of future releases.
  • Run dependency vulnerability and provenance checks in CI.
  • Continue using narrowly scoped RAM credentials and avoid exposing unrelated secrets to the Skill process.

T08 · Insecure Dependencies

Warning
Location
README.md:62
Finding

Documentation Invokes an Unversioned npx Installer

Content
View full analysis

Vulnerability Details

File Location: README.md:62
Vulnerability Type: Unpinned executable installation dependency
Risk Level: Medium

Vulnerable code:

bash
# Install using clawhub
npx clawhub install aliossupload

Technical Analysis

The documented installation command invokes the clawhub npm package through npx without specifying a version. If the package is not already available locally, npx may retrieve a mutable release from the configured npm registry and execute it immediately.

This prevents users from reliably reproducing a reviewed installation path. A future malicious or compromised release of the installer could execute arbitrary code before or while installing the Skill. Exploitation depends on compromise of the legitimate package, publisher account, registry, or the user's registry configuration; the reviewed files do not demonstrate that the current package is malicious.

Attack Path

  1. An attacker compromises the clawhub npm package, its publisher account, the package registry, or a registry configured by the victim.
  2. The attacker publishes or serves a malicious package version.
  3. A user follows the README and runs npx clawhub install aliossupload.
  4. npx resolves the unversioned package to the attacker-controlled release.
  5. The downloaded package executes with the invoking user's privileges.
  6. The malicious installer can access user-readable files, environment variables, and writable Skill or agent directories.

Impact Assessment

Successful exploitation could result in arbitrary code execution under the account performing the installation. The attacker could read user-accessible data and credentials, alter the installed Skill, insert persistent malicious instructions or code into writable agent directories, or make unauthorized network requests. The exact scope is limited by the invoking account's operating-system privileges and sandboxing.

Remediation
View remediation

Remediation Suggestions

  • Document an exact reviewed installer version, such as npx clawhub@<approved-version> install aliossupload.
  • Prefer installation from a lock-file-controlled toolchain and verify package integrity and provenance.
  • Document the expected trusted registry and advise users to verify their npm registry configuration before installation.
  • Review installer updates before changing the documented version.
  • Where supported, use signed releases, package provenance attestations, and integrity checks.
  • Recommend installation under a minimally privileged account or isolated environment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes upload behavior but does not explicitly warn users that file contents, filenames/paths, and related metadata will be transmitted to Alibaba Cloud OSS, a third-party cloud service. This omission can lead to users unintentionally sending sensitive or regulated data off-host without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language examples are broad ('upload this file to Alibaba Cloud', 'upload the image to OSS and give me the link') and do not state confirmation requirements, file-scope constraints, or exclusions for sensitive data. In an agent setting, vague triggers can cause unintended uploads of local files or user-provided content to external cloud storage, increasing data exfiltration risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares required environment variables and performs file upload behavior, but it does not define any explicit tool scope such as permissions or allowed-tools. That makes the skill's ability to access local files and transmit data externally insufficiently constrained, increasing the risk of unintended file access or data exfiltration when invoked by an agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes file upload and URL return behavior but does not prominently warn users that local files will be sent to a remote cloud bucket and made reachable via an access URL. This omission can cause users or downstream agents to expose sensitive local data without fully understanding the external transmission and sharing implications.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

from aliossupload import AliOSSUploader

uploader = AliOSSUploader() result = uploader.upload_file("/path/to/file.mp4", "videos/file.mp4") print(result['url'])

text

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

from aliossupload import AliOSSUploader

uploader = AliOSSUploader() result = uploader.upload_file("/path/to/file.mp4", "videos/file.mp4") print(result['url'])

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's main block automatically creates a local file if it does not exist and then uploads it to the configured OSS bucket without any interactive confirmation or explicit dry-run mode. In an agent or automation context, invoking the script can therefore cause unintended data transfer to cloud storage, which is a real security/privacy risk even if the uploaded content is only a generated test file in this exact branch.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This code performs an actual upload to Alibaba Cloud OSS in the main execution path, which is a cloud exfiltration sink. Although the shown code uploads a generated test file rather than harvesting sensitive files, in an agent skill context any automatic network transfer to externally configured cloud storage is more dangerous because it can move local data outside the host boundary without strong operator awareness.

Content

Scanner excerpt · aliossupload.py (reported line 147)May include surrounding context.

python
with open(test_file, 'w') as f:
            f.write(f"Test file created at {time.time()}")
    
    result = uploader.upload_file(test_file, f"test/{os.path.basename(test_file)}")
    print(json.dumps(result, indent=2, ensure_ascii=False))

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says it uploads files to Alibaba Cloud OSS but does not clearly warn users that local file contents will be transferred off-device to a cloud provider and may become accessible via a generated link. For a storage/upload skill, missing disclosure about data egress materially increases the risk of users exposing sensitive files without fully informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example trigger phrase "上传这个视频到云存储" is broad, conversational, and overlaps with normal user language, which increases the chance the skill is invoked unintentionally. In the context of a file-upload capability, accidental activation can lead to unintended transmission of local files to a third-party cloud service, making the trigger quality a real security concern rather than a purely usability issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language instructions and all example invocations are presented exclusively in Chinese, with no indication that other languages are supported or that Chinese is a deliberate region-specific constraint. This can constitute a language/locale policy issue when the skill appears to require a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description and headings are presented in Chinese, and the file does not indicate that this locale is optional, user-selected, or required for a region-specific compliance reason. Under the stated policy, forcing a specific language without opt-in can be a documentation-level language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstrings and user-facing error/output messages are presented in Chinese only, with no option to select another language. This can violate a language/locale policy when a skill is expected to be language-neutral or offer user opt-in for locale-specific behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file begins with a Chinese-only comment ("阿里云 OSS 配置"), which indicates a language-specific presentation without any visible opt-in or explanation. Under the language/locale policy rule, natural-language content that enforces a specific language without user choice can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The package description is entirely in Chinese and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, a skill should not implicitly force a specific language without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is specified with a lower bound only (oss2>=2.18.0), which allows future unreviewed versions to be installed. This creates supply-chain risk because a breaking, vulnerable, or malicious upstream release could be pulled into the environment without explicit approval or testing.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
oss2>=2.18.0

Static analysis

No suspicious patterns detected.