T09 · Insecure Skill Coding Practices
- Location
scripts/transcribe.js:103- Finding
Shell Command Injection Through Untrusted URLs and File Paths
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real Douyin/video transcription tool, but its command execution and API-key handling create material security risk.
Review before installing. Do not paste API keys into normal chat; configure secrets through a safer local or platform secret mechanism. Run only in a sandboxed environment, avoid sensitive videos or private account sessions, and patch the script to use `execFileSync`/argument arrays plus strict URL and file-path validation before processing untrusted links or files.
scripts/transcribe.js:103Shell Command Injection Through Untrusted URLs and File Paths
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cd ~/.openclaw/workspace/skills/douyin-transcribe
cp .env.example .env
编辑 .env,填入你的 Groq API Key:
The declared purpose says the skill transcribes Douyin links or video files, but the instructions also include credential handling, browser automation, media extraction, local file operations, external API calls, and shell execution. This description-behavior gap can mislead users and policy systems about the real trust boundary and data flows.
The skill instructs the agent to inspect the .env file in the skill directory, which is a credential-bearing file by design. Reading such a file gives the agent access to secrets and increases the chance of accidental disclosure through logs, outputs, or prompt leakage.
当用户第一次触发这个 Skill 时,你需要先检查环境是否就绪。 按以下顺序检查,缺什么就引导用户补什么:
检查 Skill 目录下是否有 .env 文件:
The explicit read operation against <skill目录>/.env is credential access, not just normal configuration handling. In a skill context, this is especially risky because LLM agents can inadvertently expose secret values when summarizing file contents or debugging setup failures.
检查 Skill 目录下是否有 .env 文件:
read: <skill目录>/.env
如果不存在,从 .env.example 复制一份:
Copying a template into a live .env file is not secret theft by itself, but in this skill it is part of a broader pattern of agent-managed credential storage and handling. Having the agent create and manage the secret-bearing file expands the trusted surface and encourages unsafe secret workflows.
如果不存在,从 .env.example 复制一份:
exec: cp <skill目录>/.env.example <skill目录>/.env
The instructions explicitly tell the user to send a secret API key in natural language and direct the agent to read and write that secret into a .env file. This is a strong sensitive-data handling flaw because it normalizes secret exfiltration into conversation and broadens exposure to logs, prompt history, and local file access.
Referenced artifact was not completely inspected
node scripts/transcribe.js "<用户的原始链接>"
Referenced artifact was not completely inspected
node scripts/transcribe.js "<用户的原始链接>"
Referenced artifact was not completely inspected
node scripts/transcribe.js "<用户的原始链接>"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const path = require('path');
const https = require('https');
// 加载 .env 文件
function loadEnvFile() {
const envPath = path.join(__dirname, '..', '.env');
if (fs.existsSync(envPath)) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const path = require('path');
const https = require('https');
// 加载 .env 文件
function loadEnvFile() {
const envPath = path.join(__dirname, '..', '.env');
if (fs.existsSync(envPath)) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const path = require('path');
const https = require('https');
// 加载 .env 文件
function loadEnvFile() {
const envPath = path.join(__dirname, '..', '.env');
if (fs.existsSync(envPath)) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const path = require('path');
const https = require('https');
// 加载 .env 文件
function loadEnvFile() {
const envPath = path.join(__dirname, '..', '.env');
if (fs.existsSync(envPath)) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
// 加载 .env 文件
function loadEnvFile() {
const envPath = path.join(__dirname, '..', '.env');
if (fs.existsSync(envPath)) {
const envContent = fs.readFileSync(envPath, 'utf-8');
envContent.split('\n').forEach(line => {
README 明确写明“支持中文”,整体示例和说明也默认仅面向中文输出,但没有说明这是可配置选项,也未提供用户选择语言/locale 的机制。根据规则,若技能强制特定语言而无用户 opt-in,可构成语言/locale 政策问题。
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux:
sudo apt install ffmpeg # Debian/Ubuntu
sudo yum install ffmpeg # CentOS/RHEL
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Linux:
sudo apt install ffmpeg # Debian/Ubuntu
sudo yum install ffmpeg # CentOS/RHEL
The README instructs users to send audio to Groq for transcription and post-processing but does not clearly disclose the privacy implications of transmitting potentially sensitive voice content and derived transcripts to a third-party API. This can lead users to expose personal, confidential, or regulated data without informed consent, especially since the skill is positioned as easy and free to use.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
1. 打开 [console.groq.com](https://console.groq.com)
2. 用 Google 或 GitHub 登录(不需要信用卡)
3. 点击 **API Keys** → **Create API Key**
4. 填个名字(如 `douyin`),点 Submit
5. 复制生成的 Key(以 `gsk_` 开头)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
1. 打开 [console.groq.com](https://console.groq.com)
2. 用 Google 或 GitHub 登录(不需要信用卡)
3. 点击 **API Keys** → **Create API Key**
4. 填个名字(如 `douyin`),点 Submit
5. 复制生成的 Key(以 `gsk_` 开头)
The skill clearly instructs the agent to read environment files, execute shell commands, launch a browser, and set environment variables, but it does not declare an explicit tool scope or allowed-tools policy. That mismatch increases the risk of overbroad execution and makes it harder for a host platform to sandbox the skill appropriately.
The description says the skill will automatically transcribe into Chinese text and the title/body repeatedly frame the output as Chinese by default, but there is no opt-in or language selection mechanism. This is a natural-language locale policy issue because the skill mandates a specific output language without giving the user a choice or clearly documenting a justified regional limitation.
The skill asks the user to send a Groq API key to the assistant and then stores it in a local .env file. This turns a transcription workflow into a credential collection and management workflow, exposing sensitive secrets to the model, logs, and any component with access to the working directory.
The skill instructs users to send their API key directly to the assistant without any warning about secret handling, storage, retention, or exposure. This is dangerous because chat transcripts and local files may be accessible to operators, logs, other tools, or future prompts.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
> 4. 把 `C:\ffmpeg\bin` 添加到系统环境变量 PATH
> 5. 重启终端,运行 `ffmpeg -version` 验证
>
> **Linux 用户:** 运行 `sudo apt install ffmpeg`
>
> 装好了告诉我!
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal