Back to skill

Security audit

Weibo Channel Config

Security checks for vulnerabilities and agentic risk

Overview

The skill does only configure Weibo credentials, but it handles an AppSecret through plain CLI commands and may expose or mishandle that secret.

Review before installing. Only use this in a trusted environment, avoid pasting the AppSecret into shared chats or terminals, verify without printing the full secret-bearing configuration, and rotate the Weibo AppSecret if it appears in logs, command history, transcripts, or tool output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:16
Finding

Shell Command Injection Through Unescaped Credential Interpolation

Content
View full analysis
' openclaw config set 'channels.weibo.appSecret' '' ``` The workflow subsequently instructs the agent to execute these commands with user-provided values: ```text 2. Run the two `openclaw config set` commands above with the provided values. ``` ### Technical Analysis The `AppId` and `AppSecret` values originate from the user and are intended to replace placeholders embedded inside single-quoted shell arguments. The skill does not require credential validation, shell-safe escaping, or execution through a structured argument-array API. If an agent constructs a command string by directly replacing the placeholders, a credential containing a single quote can terminate the quoted argument. The remaining content can then introduce shell operators and arbitrary commands. For example, a malicious value following this pattern could escape the intended argument: ```text ' ; attacker_command ; # ``` The vulnerability depends on the agent passing the interpolated command through a shell. It can be prevented by avoiding shell-string construction entirely. ### Attack Path 1. An attacker asks the agent to configure the Weibo channel. 2. The agent requests an AppId and AppSecret as directed by the workflow. 3. The attacker supplies a credential containing a closing single quote, shell separators, and an arbitrary command. 4. The agent substitutes that value into the documented command template. 5. The agent executes the resulting string through a shell. 6. The shell terminates the intended quoted argument and executes the injected command. 7. The attacker's command runs with the operating-system privileges and filesystem or network access available to the agent process. ### Impact Assessment Successful exploitation could permit a ...[truncated 458 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:21
Finding

AppSecret Exposure Through Chat, Command Arguments, and Configuration Verification

Content
View full analysis
' ``` ### Technical Analysis The workflow directs the agent to collect an AppSecret in ordinary conversation and pass it as a command-line argument. This creates several possible disclosure surfaces: - The secret can remain in conversation transcripts. - Tool invocation logs or shell auditing can record the complete command. - Command-line arguments may be visible to other processes or administrators through process-inspection facilities, depending on the operating system and execution environment. - Shell history may retain the credential if an interactive shell is involved. - Retrieving the entire `channels.weibo` configuration for verification may display the AppSecret if the CLI does not redact sensitive fields. The skill does not instruct the agent to use a protected secret-input channel, redact logs, suppress command echoing, or verify configuration without reading the secret back. ### Attack Path 1. A user provides a valid Weibo AppSecret in response to the skill's prompt. 2. The secret is stored in the conversation transcript or agent execution log. 3. The agent includes the secret in an `openclaw config set` command-line argument. 4. A local user, monitoring process, log collector, or administrator with access to process metadata or tool logs observes the argument. 5. During verification, the agent runs `openclaw config get 'channels.weibo'` ...[truncated 898 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs collecting an AppSecret and writing it into configuration without any warning about secure handling, masking, least-privilege storage, or confirmation of where the secret will persist. In a credential-configuration skill, this omission increases the risk of secrets being exposed in shell history, logs, screenshots, shared terminals, or insecure config stores.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.