Back to skill

Security audit

Huo15 Knowledge Base Enterprise

Security checks for vulnerabilities and agentic risk

Overview

This skill is an enterprise knowledge-base/Odoo sync tool, but it ships risky default Odoo credentials and can expose or overwrite sensitive knowledge-base content without enough safeguards.

Review this skill before installing or running it. Replace and rotate the bundled Odoo credential, do not store passwords or API tokens in ordinary knowledge-base articles, run Odoo export only with a known target and dry-run first, and avoid bulk activation across all agents unless that is explicitly intended. Treat LLM-generated wiki output as untrusted until filenames, paths, and article content are reviewed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kb-llm.py:137
Finding

LLM-Controlled Path Traversal Enables Arbitrary Markdown File Writes

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/kb-odoo-export.py:151
Finding

Department-Restricted Articles Are Exported as Workspace-Visible

Content
View full analysis
{html_body}', 'category': vis_settings.get('category', 'workspace'), } if existing: models.execute_kw( db, uid, password, 'knowledge.article', 'write', [existing, article_vals] ) article_id = existing[0] else: article_id = models.execute_kw( db, uid, password, 'knowledge.article', 'create', [article_vals] ) ``` The selected department users are subsequently added as writable members: ```python if matched_user_ids: partner_ids = user_ids_to_partner_ids( models, db, uid, password, matched_user_ids ) if partner_ids: added = add_article_members( models, db, uid, password, article_id, partner_ids ) ``` ### Technical Analysis The documentation claims that `department:` restricts an article to members of a selected department. The implementation instead sets the Odoo Knowledge article category to `workspace`. Adding selected partners as members with `write` permission does not remove workspace visibility from the article. Consequently, the member list grants additional write access but does not implement the promised read restriction. This is a fail-open authorization design: the exporter publ ...[truncated 1505 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
config.enterprise.json:2
Finding

Plaintext Odoo Credential Is Shipped in Runtime Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/kb-odoo-export.py:54
Finding

Unsanitized Markdown Content Is Written into Odoo HTML Articles

Content
View full analysis
\1', markdown_text, flags=re.MULTILINE ) markdown_text = re.sub( r'^## (.+)$', r'

\1

', markdown_text, flags=re.MULTILINE ) markdown_text = re.sub( r'^# (.+)$', r'

\1

', markdown_text, flags=re.MULTILINE ) markdown_text = re.sub(r'\*\*(.+?)\*\*', r'\1', markdown_text) markdown_text = re.sub(r'\*(.+?)\*', r'\1', markdown_text) markdown_text = re.sub( r'\[([^\]]+)\]\(([^)]+)\)', r'\1', markdown_text ) lines = markdown_text.split('\n') in_list = False result = [] for line in lines: if re.match(r'^[\-\*] (.+)', line): if not in_list: result.append('
    ') in_list = True item = re.sub(r'^[\-\*] (.+)', r'
  • \1
  • ', line) result.append(item) else: if in_list: result.append('
') in_list = False result.append(line) if in_list: result.append('') markdown_text = '\n'.join(result) paragraphs = re.split(r'\n\n+', markdown_text) paragraphs = [ f"

{p.strip()}

" if not p.strip().startswith('<') else p for p in paragraphs if p.strip() ] return '\n'.join(paragraphs) ``` The generated HTML is sent directly to Odoo: ```python with open(wiki_path, 'r', encoding='utf-8') as f: content = f.read() fm, body = extract_frontmatter(content) title = fm.get('title', os.path.basename(wiki ...[truncated 2056 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description promises an enterprise knowledge-base skill with Odoo Knowledge sync and access-control features. The supplied code chunk only performs local setup for an agent-specific knowledge-base workspace: it creates directories, writes a simple config file, creates an index markdown file, and prints instructions. There is no evidence of Odoo API interaction, synchronization logic, permission enforcement, visibility settings, or credential handling. While this could be a supporting activation script within a larger skill, based on the supplied code chunk alone the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述强调的是企业版知识库能力,尤其是 Odoo Knowledge 同步以及权限、凭证等企业特性。但提供的代码没有任何 Odoo 接口调用、认证处理、权限逻辑、可见性策略或企业配置管理。相反,它只是一个用于将 raw/ 文档整理为 LLM 编译任务的脚本,负责收集文档、拼接 prompt、初始化 wiki 索引文件,并提示使用 OpenClaw 执行后续编译。因此代码实际行为与声明的核心用途存在明显偏差,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes an enterprise knowledge base with Odoo Knowledge sync, visibility controls, departmental permissions, and credential management. The supplied code does none of these. It only reads markdown files from a local wiki directory, categorizes them by simple text matching (type: paper/article/note), and writes index markdown files. This is a materially different primary purpose and lacks the enterprise/Odoo-related capabilities claimed in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description emphasizes an enterprise edition knowledge-base system with Odoo Knowledge sync and administrative/security features. The actual code chunk is narrowly focused on ingesting content from a URL, local file, or text into dated files under a raw directory. It performs basic argument parsing, filename sanitization, file copying, and markdown stub generation. There is no code interacting with Odoo, no API calls, no synchronization logic, no permission or visibility enforcement, and no credential handling. This is a material description-behavior mismatch, not merely an implementation detail omission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims an enterprise edition with Odoo Knowledge sync and access-control/credential-management features. The supplied code chunk does not implement any of those capabilities. It only initializes folders and starter files for a local knowledge-base project. While initialization may be a supporting detail of a larger system, this chunk’s actual behavior is materially narrower than the declared purpose and does not evidence the described enterprise-specific functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes an enterprise edition with Odoo Knowledge sync and access-control/credential features. The supplied code only performs administrative local setup: it enumerates agent directories, creates per-agent kb subdirectories and seed files, and writes basic configuration. This is related to knowledge-base activation, but it does not implement the key enterprise capabilities claimed in the description. Additionally, the code has an undeclared bulk operation scope affecting all agents on disk. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description presents an enterprise knowledge base extension centered on Odoo Knowledge synchronization and enterprise access-control features. The supplied code chunk instead implements a knowledge-base compilation helper: it reads a prompt file, loads LLM provider configuration, makes outbound HTTP requests to an LLM service, parses structured model output, and writes compiled wiki Markdown files. While LLM-based knowledge compilation could be a supporting component of a knowledge-base product, the specific enterprise features emphasized in the description—Odoo Knowledge sync, visibility control, department-level permissions, and credential management—are not present in this code. Conversely, the code performs an undeclared networked LLM-calling capability using provider credentials from local config. Therefore this chunk does not accurately match the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents an enterprise knowledge-base product with Odoo Knowledge sync and access-management features. The supplied code chunk is only a local lint/health-check utility for wiki content: it enumerates markdown files, creates a prompt describing consistency/link/content checks, and suggests invoking OpenClaw manually. This is a materially different purpose and lacks the headline enterprise/Odoo capabilities described. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description emphasizes an enterprise edition knowledge-base system with Odoo Knowledge sync, access-control features, and credential management. The supplied code chunk only performs a local text search over Markdown files in a wiki/ directory and formats results. It does not interact with Odoo, external services, credentials, permission systems, or visibility controls. While search could be a supporting KB feature, this specific code chunk does not substantiate the core declared enterprise/Odoo capabilities, so the description does not accurately represent the behavior shown.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to store all account passwords and API tokens in a shared Odoo knowledge base is a serious secret-management anti-pattern. Natural-language knowledge repositories are broadly readable, searchable, syncable, and often included in exports, backups, or LLM context, making credential theft, lateral movement, and accidental disclosure far more likely in an enterprise setting.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents exporting articles to Odoo and handling credentials but does not provide an explicit warning that content will be transmitted to an external service and may create or modify records remotely. In a knowledge-base context, this increases the chance of accidental data exfiltration, unintended publication, or unauthorized modification of enterprise content because users may trigger sync/export without understanding the consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger list includes generic phrases such as "编译知识库" and "体检知识库", which could overlap with ordinary requests about knowledge-base maintenance rather than this specific enterprise skill. The file also does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation presents kb-odoo-export as a normal workflow step and notes that preview mode requires --dry-run, but it does not clearly warn that the default behavior will create or update records in a remote Odoo Knowledge instance. In an enterprise knowledge-base context, this can lead to unintended publication or synchronization of internal content to an external system, especially when visibility settings or target environment are misconfigured.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language instruction explicitly requires summaries and body text to be written in Chinese. This is a language policy constraint applied unconditionally, and the file does not provide user opt-in, alternative locale selection, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script concatenates the full contents of every file under raw/ into a single prompt file intended for LLM processing, but it does not warn the operator that potentially sensitive enterprise documents will be aggregated and exposed to an external model workflow. In an enterprise knowledge-base skill that explicitly supports Odoo Knowledge sync and enterprise credential handling, this increases the likelihood of confidential business data, internal procedures, or regulated content being unintentionally disclosed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script's natural-language comments, usage text, and echo output are written in Chinese, which imposes a specific language/locale on users without offering a choice or documenting that the skill is intended only for a Chinese-speaking context. The policy explicitly calls for flagging language or locale constraints when they are forced without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script presents its description, usage examples, and later user-facing output entirely in Chinese, with no option to choose another language or locale. That is a natural-language policy concern under the language/locale rule because the skill imposes a specific language by default rather than offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script performs bulk installation against every local OpenClaw agent under ~/.openclaw/agents, which is broader than the enterprise skill’s stated purpose and can modify agents that did not explicitly opt in. In a multi-agent or shared workstation environment, this increases the blast radius of mistakes, causes unintended configuration changes, and may overwrite trust boundaries by enabling a knowledge-base component everywhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes LLM-generated content directly to disk as markdown files without validation, confirmation, or clear user warning. Because the response can contain attacker-influenced text, filenames, frontmatter, and markdown content, this creates a trust-boundary violation that can persist untrusted output into the knowledge base and potentially enable content poisoning or unsafe file writes in downstream workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the full prompt file contents to an external LLM provider over the network without an explicit disclosure or consent step at the point of transfer. In an enterprise knowledge-base skill, prompts may embed internal documents, credentials, URLs, or proprietary material, so silent transmission increases the risk of unintended data exposure to third-party services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Natural-language strings in the docstring, CLI help, and runtime messages are all presented only in Chinese. Because there is no opt-in, locale selection, or documented region-specific justification, this constitutes a language/locale policy violation under the stated rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code loads and uses the Odoo password from configuration to establish XML-RPC access, then later uses that connection to send knowledge-base content to a remote service. While the module docstring says it syncs to Odoo, there is no explicit warning at the connection point or before transmission about credential use or remote data export, which fits the missing user disclosure criteria for code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script generates a prompt that explicitly instructs an LLM to directly modify wiki files and create a health report, but it does not require user confirmation, dry-run behavior, scoped edit constraints, or review-before-write safeguards. In an enterprise knowledge-base skill, this is risky because the wiki content itself is adversarial input to the downstream model, so prompt injection inside entries could steer the LLM into making unintended or destructive edits across the repository.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's description, usage text, and runtime messages are written only in Chinese, which imposes a specific language on users. Under the policy, locale or language constraints should either be optional for the user or clearly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.