Back to skill

Security audit

Quark Lazy Cli

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for maintaining QAS cloud-drive subscriptions, but it handles powerful credentials and includes unsafe transport/script patterns plus an unrelated Claude permission file.

Review before installing. Use only a trusted local or HTTPS QAS endpoint, rotate and limit QAS/LLM tokens, avoid using the sample run_lazy_update script without removing shell sourcing of .env, and remove the bundled .claude/settings.local.json unless you specifically want that Claude permission.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/quark_lazy_cli/api.py:86
Finding

QAS Authentication Token Exposed Through URL Query Parameters and Plaintext HTTP

Content
View full analysis
dict: """GET request with token""" self._ensure_token() url = f"{self.host}{path}" merged = dict(params or {}) merged["token"] = self.api_token resp = self._session.get(url, params=merged, timeout=self.TIMEOUT, **kwargs) if not resp.ok: raise QasApiError(f"Request failed: {resp.status_code} {resp.text}") return resp.json() def _post(self, path: str, *, params: Optional[dict] = None, **kwargs) -> dict: """POST request""" self._ensure_token() url = f"{self.host}{path}" merged = dict(params or {}) merged["token"] = self.api_token resp = self._session.post(url, params=merged, timeout=self.TIMEOUT, **kwargs) if not resp.ok: raise QasApiError(f"Request failed: {resp.status_code} {resp.text}") return resp.json() ``` The same query-parameter authentication pattern is used by share-link validation and the streaming update endpoint: ```python resp = self._session.post( f"{self.host}/get_share_detail", params={"token": self.api_token}, json={"shareurl": shareurl}, timeout=timeout, ) ``` ```python resp = self._session.post( f"{self.host}/run_script_now", params={"token": self.api_token}, json=payload, stream=True, timeout=self.TIMEOUT, ) ``` ### Technical Analysis The QAS API token is added to the query string of every authenticated request. URL query strings are commonly recorded by web-server access logs, reverse proxies, monitoring systems, browser or HTTP debugging tools, and network appliances. This gives the credential a substantia ...[truncated 1698 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/quark_lazy_cli/advisor.py:558
Finding

LLM API Credential and Subscription Metadata Can Be Sent to an Unencrypted Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_lazy_update.sample.sh:19
Finding

Sample Update Script Executes the Credential File as Arbitrary Shell Code

Content
View full analysis
> "$CRON_LOG" fi ``` ### Technical Analysis The shell `source` built-in executes the target file in the current shell process. It does not restrict the file to passive `KEY=VALUE` declarations. Command substitutions, function definitions, redirections, shell commands, and other executable syntax in `.env` will run with the privileges of the user executing the update script. The script also embeds a developer-specific absolute path. When copied as a template, this may cause it to load a credential file from an unintended installation or account instead of the user's selected Skill directory. The CLI already supports loading `.env` through `python-dotenv` using `--env`. Consequently, shell execution of the `.env` file is not required for the declared update behavior and violates least-execution principles. ### Attack Path 1. The sample is copied into an active local script and scheduled or run manually. 2. An attacker, compromised process, or less-trusted local account gains write access to the hard-coded `.env` file or replaces a path component. 3. The attacker adds shell syntax such as command substitution or an executable command to the file. 4. The update script checks only that the path exists and then invokes `source "$ENV_F ...[truncated 890 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:33
Finding

Installation Instructions Resolve Mutable and Unpinned Remote Code

Content
View full analysis
Remediation
View remediation
" ``` 2. Publish versioned packages through a trusted registry and document the exact reviewed version. 3. Provide SHA-256 hashes or signed release artifacts and instructions for verifying them before installation. 4. Sign release tags and publish provenance or software-bill-of-materials information. 5. Use a dependency lock file containing exact tested versions and integrity hashes where the packaging workflow permits it. 6. Configure automated dependency scanning and controlled update review. 7. Avoid recommending mutable branch-based installation for production or scheduled environments. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (72)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/OpenClaw定时任务.md (reported line 27)May include surrounding context.

--channel feishu
--account bot-AgentName
--to "USER_OPEN_ID"
--message "bash -c 'LAZY_CLI_ADVISOR=code qslazy update all 凡人修仙传 --env /quark-lazy-cli/.env'\n\n仅根据 stdout 汇报结果,除非排错,不要读取 log 或报告文件。"

text

替换项:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/每日汇报.md (reported line 96)May include surrounding context.

--channel feishu
--account bot-AgentName
--to "USER_OPEN_ID"
--message "bash -c 'LAZY_CLI_ADVISOR=code qslazy update all 凡人修仙传 --env /quark-lazy-cli/.env'\n\n仅根据 stdout 汇报结果,除非排错,不要读取 log 或报告文件。"

text

替换项:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 125)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/每日汇报.md (reported line 40)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/每日汇报.md (reported line 153)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/每日汇报.md (reported line 160)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/环境变量.md (reported line 6)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/环境变量.md (reported line 18)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/环境变量.md (reported line 66)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/订阅时间估算.md (reported line 171)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/顾问模式.md (reported line 30)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/顾问模式.md (reported line 51)May include surrounding context.

如果安装后的 Skill 目录没有 .env.local.example,Agent 应根据本文件创建:

text
<skills-dir>/quark-lazy-cli/.env

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/run_lazy_update.sample.sh (reported line 25)May include surrounding context.

sh
如果安装后的 Skill 目录没有 `.env.local.example`,Agent 应根据本文件创建:

```text
<skills-dir>/quark-lazy-cli/.env
```

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/run_lazy_update.sample.sh (reported line 36)May include surrounding context.

sh
如果安装后的 Skill 目录没有 `.env.local.example`,Agent 应根据本文件创建:

```text
<skills-dir>/quark-lazy-cli/.env
```

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/run_lazy_update.sample.sh (reported line 40)May include surrounding context.

sh
如果安装后的 Skill 目录没有 `.env.local.example`,Agent 应根据本文件创建:

```text
<skills-dir>/quark-lazy-cli/.env
```

创建后必须替换:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/run_lazy_update.sample.sh (reported line 47)May include surrounding context.

sh
如果安装后的 Skill 目录没有 `.env.local.example`,Agent 应根据本文件创建:

```text
<skills-dir>/quark-lazy-cli/.env
```

创建后必须替换:

Static analysis

No suspicious patterns detected.