Back to skill

Security audit

Opencli Content Hunter

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible content-collection tool, but it asks users to install unverified persistent components that reuse Chrome logins and can make platform requests beyond a narrow confirmed scope.

Review before installing. Use a separate Chrome profile or low-risk accounts, avoid loading the extension into a browser profile with sensitive sessions, prefer pinned and verified dependency versions, do not run the helper script unless Bilibili and Xiaohongshu test requests are acceptable, and avoid group-chat use unless everyone should see setup and platform-selection details.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:132
Finding

Unpinned Third-Party CLI and Unverified Browser Extension

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 132-143
Vulnerability Type: Unverified and mutable third-party dependencies
Risk Level: High

Vulnerable Code

bash
npm install -g @jackwener/opencli
text
https://github.com/jackwener/opencli/releases
opencli-extension.zip

The same installation guidance is repeated at lines 167-174 and 191-198. Line 512 also recommends installing the mutable latest release:

bash
npm install -g @jackwener/opencli@latest

Technical Analysis

The Skill requires a globally installed npm package without pinning an exact version. It also directs users to select an unversioned ZIP archive from a personal GitHub release page and manually load the extracted content as an unpacked Chrome extension. No cryptographic checksum, signature, immutable release URL, or reviewed extension manifest is supplied.

Because both installation sources are mutable, the code ultimately executed can change after the Skill itself has been audited. A global npm installation can execute package lifecycle scripts with the installing user's privileges and place executable files in a globally accessible command path. The manually loaded extension is especially sensitive because the documented functionality relies on reusing authenticated Chrome sessions across numerous websites.

Installing the CLI and extension is relevant to the declared content-fetching functionality, but the unpinned and unverified installation model grants substantially more trust than necessary. The recommendation to install @latest further prevents users from reproducing an audited configuration.

Attack Path

  1. An attacker compromises the npm publisher account, GitHub account, repository, release workflow, or downloadable release artifact.
  2. The attacker publishes a malicious package version or replaces the extension ZIP available from the generic releases page.
  3. A user follows the S ...[truncated 1218 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm dependency to a specific reviewed version instead of using an unqualified package name or @latest.
  2. Record and verify the npm package integrity hash before installation.
  3. Replace the generic GitHub releases link with an immutable, version-specific artifact URL.
  4. Publish a SHA-256 digest and, preferably, a verifiable digital signature for the extension archive.
  5. Include the reviewed extension source and manifest in the audit scope, or distribute it through a verified browser-extension marketplace.
  6. Document every requested extension permission and remove permissions not strictly required for selected platforms.
  7. Restrict extension access to explicitly selected domains rather than granting broad access to every supported platform.
  8. Avoid global installation where possible. Use a pinned project-local dependency, isolated runtime, or restricted container.
  9. Disable or review npm lifecycle scripts during installation and verify the package provenance before execution.
  10. Provide a controlled update process that requires review and integrity verification before users move to a newer release.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
check.sh:51
Finding

Prerequisite Check Performs Unrequested Platform Access Through Browser Sessions

Content
View full analysis

Vulnerability Details

File Location: check.sh, lines 51-67
Vulnerability Type: Platform requests outside the minimum diagnostic scope
Risk Level: Medium

Vulnerable Code

bash
opencli bilibili hot --limit 1 -f table > /dev/null 2>&1
bash
XHS_OUTPUT=$(opencli xiaohongshu feed --limit 1 2>&1 || true)

Technical Analysis

The prerequisite script is described as checking installation, extension connectivity, and login state. After running opencli doctor, it nevertheless invokes live content-fetching commands against Bilibili and Xiaohongshu.

These requests occur whenever the script reaches the platform-test section, regardless of whether the user selected either platform. According to the Skill documentation, opencli relies on a Chrome extension and can reuse the user's authenticated browser state. Consequently, these diagnostic commands may generate authenticated platform requests and associated telemetry without platform-specific consent.

The live requests are not necessary to establish whether the CLI is installed or whether the extension is connected. Those conditions are already checked using opencli --version and opencli doctor. This behavior therefore exceeds the least-privilege and minimum-network-access requirements of a prerequisite check.

No evidence shows that check.sh steals credentials or transmits data to an attacker-controlled destination. The issue is the unnecessary use of existing browser authentication and unsolicited access to fixed third-party platforms.

Attack Path

  1. A user installs the CLI and connects the Chrome extension while logged into one or more supported websites.
  2. The user runs check.sh only to verify the local prerequisite state.
  3. The script invokes Bilibili and Xiaohongshu content commands without asking whether those platforms should be tested.
  4. opencli communicates through its browser integration and may use the user's ex ...[truncated 834 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all platform-specific requests from the default prerequisite check.
  2. Restrict the default checks to local version discovery and opencli doctor.
  3. Ask for explicit user consent before testing any platform connection.
  4. Test only platforms the user has specifically selected.
  5. Clearly state whether a test may use an authenticated Chrome session and generate account-side activity.
  6. Add a non-network or public unauthenticated diagnostic mode if the CLI supports one.
  7. Provide command-line flags such as --platform bilibili and --platform xiaohongshu so platform probes are opt-in.
  8. Display the exact command and destination before performing an authenticated connectivity test.
  9. Ensure failed diagnostics do not automatically broaden testing to other platforms.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个面向终端用户的多平台内容抓取技能,核心能力应是跨平台抓取内容、热点和搜索结果,并包含执行前的平台范围/登录确认流程。但提供的代码只是一个 check.sh 前置检查脚本,主要验证 opencli、Chrome 扩展和部分平台登录状态。虽然这些检查可视为抓取功能的辅助准备步骤,但当前代码块本身没有执行所宣称的主要能力,因此代码实际行为与声明的主要目的存在明显不一致。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are overly broad and mandate invocation for generic phrases like multi-platform search or whole-network hot topics. In an agent environment, this can cause unintended tool activation, leading to unnecessary scraping, external requests, or use of browser-linked session state without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises large-scale collection across 65+ platforms and explicitly reuses Chrome login state, but it does not present a clear, prominent privacy warning about authenticated-session access and the implications for account-linked data. In this context, that is dangerous because the skill may access personalized or restricted content under the user's active browser session, and users may not understand the scope of data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Ambiguous shorthand examples such as generic requests to 'grab hot topics' or 'search AI' can match ordinary conversation and trigger collection behavior unintentionally. Because the skill is designed to operate across many platforms and may reuse Chrome login state, accidental activation materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to send initialization and status messages to a group, even though the skill's purpose is content collection rather than group broadcasting. This can expose operational details, user intent, selected platforms, or login/setup state to unintended recipients in a shared channel, creating a privacy leak and increasing the blast radius of misuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest says the skill 'must trigger' whenever users mention broad phrases like '搜全网' or '多平台抓取', while also stating that every execution should proactively ask the user to confirm platform scope and login willingness. This creates an intent-level inconsistency in the documented behavior: automatic triggering is presented as mandatory, but the later execution model requires a confirmation step before meaningful action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The activation and operational instructions are presented entirely in Chinese and prescribe exact user-facing messages in Chinese, but the skill does not indicate that language selection is optional or region-specific. This can amount to a language-policy issue when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and all user-facing messages are in Chinese, including installation and login instructions, with no indication that the skill is intended only for Chinese-speaking users or that another language is available. This can violate language/locale policy when users are not given an opt-in or choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.