Back to skill

Security audit

Z视介 Publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its stated Z视介 publishing purpose, but it handles reusable login sessions and live publishing through under-protected HTTP, temp-file credential storage, and unrestricted host overrides.

Install only if you are comfortable giving the skill authority to log in to Z视介 and publish or edit live content. Avoid using the default plaintext publishing host on untrusted networks, do not use arbitrary `--base-url` or custom contracts with a saved session, and store the session file in a private location with restrictive permissions; delete it after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/zshijie-api.json:2
Finding

Authentication session and publishing data are transmitted over plaintext HTTP

Content
View full analysis
dict[str, Any]: req = request.Request(url=url, method=method.upper(), headers=headers, data=body) try: with request.urlopen(req, timeout=timeout_seconds) as response: raw_body = response.read() ``` ```python base_url = args.base_url or str(contract.get("base_url", ...[truncated 2314 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/publisher_cli.py:19
Finding

Reusable session and excessive login data are stored in an unsafe predictable temporary file

Content
View full analysis
None: path.parent.mkdir(parents=True, exist_ok=True) path.write_text(json.dumps(payload, indent=2, ensure_ascii=False) + "\n", encoding="utf-8") ``` ```python if session_id: captured["sessionId"] = session_id captured["sessionCookie"] = f"sessionId={session_id}" if isinstance(body, (dict, list)): for output_key, candidates in USER_KEY_GROUPS.items(): found = find_first_by_keys(body, candidates) if found is not None: captured[output_key] = found ``` ```python session_output = { "captured_at": datetime.now(timezone.utc).isoformat(), "captured": captured, "login_response": poll_response["body"], "login_mode": "qr_code", "qr_login": { "login_page": str(qr_config.get("login_page", "https://mp.cztv.com/#/login")), "html_output": str(html_output), "png_output": str(png_output), }, } write_json(session_path, session_output) ``` ### Technical Analysis The default session filename is static and located in the system temporary directory. `Path.write_text` does not explicitly create the file with owner-only permissions, so its effective permissions depend on the process umask and preexisting filesystem state. The predictable path also creates avoidable exposure to local race and symbolic-link risks on shared systems. The file contains more than the minimum credential required for later operations: - The reusa ...[truncated 1568 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/publisher_cli.py:155
Finding

Unrestricted contract and base URL overrides can redirect authentication credentials to arbitrary hosts

Content
View full analysis
str: if ABSOLUTE_URL_RE.match(path_value): resolved = path_value else: if not base_url: raise SystemExit("[ERROR] base_url is empty and operation path is not absolute.") base = base_url.rstrip("/") + "/" resolved = parse.urljoin(base, path_value.lstrip("/")) filtered = {} for key, value in query.items(): if value in (None, ""): continue filtered[key] = value if not filtered: return resolved return f"{resolved}?{parse.urlencode(filtered, doseq=True)}" ``` ```python def render_request_definition( *, definition: dict[str, Any], base_url: str, base_headers: dict[str, Any], context: dict[str, Any], ) -> dict[str, Any]: method = str(definition.get("method", "GET")).upper() path_value = render_template(str(definition.get("path", "")), context) headers = normalize_headers( merge_dicts( base_headers if isinstance(base_headers, dict) else {}, render_template(definition.get("headers", {}), context), ) ) query = render_template(definition.get("query", {}), context) if query and not isinstance(query, dict): raise SystemExit("[ERROR] Operation query must render to an object.") body_template = definition.get("body") body_value = render_template(body_template, context) if body_template is not None else None content_type = str(definition.get("content_type", "none")) body = encode_body(content_type, body_value, headers) url = build_url(base_url, str(path_value), query or {}) return { "method": method, "url": url, " ...[truncated 2788 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description says this skill operates the Z视介 publishing API and supports QR-code login plus publish/edit workflows for 图文 and 短视频 content. However, the actual code is solely a bundled QR code generator library (qrcode.min.js). It contains logic for QR encoding, error correction, mask patterns, and rendering to SVG/canvas/HTML, which is only a supporting UI utility at best. There is no evidence of network access, API endpoints, authentication/session handling, JSON payload processing for publishing, or any Z视介-specific behavior. Because the provided code chunk’s actual purpose is materially different from the declared skill purpose, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description centers on operating the Z视介 publishing API for user login and content publication/editing. The actual code does none of that. It only checks for the presence of SKILL.md and agents/openai.yaml, validates frontmatter fields like name and description, constructs clawhub publish <skill_dir>, and optionally runs that command. While the description briefly mentions packaging for ClawHub, this code still does not implement the primary advertised Z视介 functionality and instead serves as a release helper for publishing the skill package itself. That is a material description/behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes operations that require shell execution, local file access, and network communication, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, missing scope declarations can cause the skill to run with broader-than-necessary capabilities, increasing the chance of unintended command execution, file modification, or outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger conditions are broad enough that an agent could invoke this skill in situations that only loosely relate to publishing, uploaded HTML, or packaging. Overbroad activation increases the risk of unnecessary access to shell, network, and local files, especially because the workflow includes login orchestration and publishing actions that can have external side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction Do not report "Session 文件结构不对" embeds a required user-facing phrase in Chinese, which implies a fixed language choice rather than offering the user's preferred language. This is a natural-language policy concern because the file does not indicate that Chinese output is optional or user-selected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The display name, description, and default prompt are written to require interaction with the service using Chinese-language terms and content types, with no indication that users may choose another language or locale. This is a natural-language locale constraint that appears mandatory rather than optional or region-justified within the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file gives direct commands for publishing and editing articles and videos, which are user-data-affecting remote operations. The surrounding documentation explains mechanics like session handling and payload format, but does not include an explicit user warning that these commands will create or alter live content on the target platform.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/usage.md (reported line 60)May include surrounding context.

md
## Session Behavior

- `login` fetches a fresh QR code from the Z视介创作者平台, writes a local HTML file, waits for the user to scan it, then stores the extracted `sessionId` in the session file.
- Publish and edit commands automatically send the `sessionId` request header, and also include `Cookie: sessionId=...` for compatibility.
- The CLI redacts request cookies and login cookies in console output.
- QR login uses the fixed creator-platform page `https://mp.cztv.com/#/login` and the bundled QR polling config from `references/zshijie-api.json`.
- The generated QR HTML defaults to `/tmp/openclaw-zshijie-login.html`; override it with `--html-output` if needed.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration hard-codes a signing secret used in the QR login flow, which exposes a credential-like value directly in the skill artifact. Anyone with access to the file can reuse the secret to generate valid signatures for the associated endpoint, undermining the integrity of the login workflow and making unauthorized automation or abuse easier. In this context, the skill explicitly performs login-related actions, so embedding the secret is more dangerous than a generic placeholder because it is directly tied to an authentication mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly instructs the runtime to persist a successful login sessionId locally and reuse it for authenticated requests, but it provides no warning about credential sensitivity, storage protections, or lifecycle management. A persisted session token can be stolen from disk or logs and reused to publish or edit content as the user, so this is a real security weakness even though it appears to be operational guidance rather than overtly malicious behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The publish and edit sections describe authenticated API calls that create or modify remote articles and videos on the user's behalf, but they do not clearly warn that these are state-changing actions against a live platform. In an agent skill context, missing disclosure increases the risk of unintended or socially engineered posting/editing, because the capability is not framed with appropriate user confirmation and safety expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The request builder accepts absolute URLs and the CLI also allows a user-supplied --base-url, so a skill advertised as operating on the Z视介 API can be redirected to arbitrary hosts. In an agent setting, that makes the tool usable as a generic HTTP client that can exfiltrate session-linked data, contact unintended internal services, or bypass expected domain scoping.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a Z视介 publishing workflow with QR-code login and HTTP-based publish/edit operations. This file additionally depends on and executes a local Node.js interpreter via subprocess to run dynamically constructed JavaScript, which is not an obvious or necessary capability for a publishing API client and expands execution surface beyond the stated purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publisher_cli.py (reported line 706)May include surrounding context.

python
}}
process.stdout.write(JSON.stringify(matrix));
"""
    completed = subprocess.run(
        [node_path, "-e", script],
        check=False,
        capture_output=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The login flow persists captured session data, including sessionId and related identifiers, to a predictable temp-directory JSON file without protective controls or a strong warning. On multi-user or shared environments, another local process or user may recover the token and hijack the authenticated publishing session.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/release_to_clawhub.py (reported line 83)May include surrounding context.

python
if shutil.which("clawhub") is None:
        raise SystemExit("[ERROR] 'clawhub' is not installed or not on PATH.")

    completed = subprocess.run(command, check=False)
    return completed.returncode

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON manifest lists generic actions such as "publish_article", "edit_article", "publish_video", and "edit_video" but provides no contextual constraints, trigger scope, or negative examples indicating when these actions should or should not be invoked. In a manifest file, the lack of invocation specificity can make activation behavior ambiguous and increase the chance of unintended use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The generated HTML sets lang="zh-CN" and all user-facing text is fixed in Chinese, with no option to select another language or locale. This is a natural-language locale constraint embedded in the skill behavior rather than a documented opt-in choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.