Back to skill

Security audit

ClawHub Automation

Security checks for vulnerabilities and agentic risk

Overview

This automation skill is not overtly malicious, but it needs Review because it advertises sensitive cross-platform data movement while its authorization, approval, and export controls are under-scoped.

Install only if you are comfortable reviewing and hardening it first. Treat it as a prototype: do not connect real accounts or sensitive files until OAuth, least-privilege scopes, workflow approvals, confirmation prompts, safe export directories, and dependency pinning are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/connector_manager.py:233
Finding

OAuth Authorization Can Be Forged Without Validating the Authorization Code

Content
View full analysis
PlatformAuth: """ Complete platform authorization. Args: platform: Platform identifier auth_code: Authorization code Returns: PlatformAuth: Authorization information """ # Simulated authorization flow auth = PlatformAuth( platform=platform, status=AuthStatus.AUTHORIZED, access_token=f"token_{platform}_{int(time.time())}", refresh_token=f"refresh_{platform}_{int(time.time())}", expires_at=time.time() + 7200, scope=['read', 'write'] ) self.auths[platform] = auth return auth ``` ### Technical Analysis The `authorize()` method ignores the supplied `auth_code` and unconditionally creates an authorization record with `AUTHORIZED` status. It also does not verify that the requested platform is registered. No authorization-code exchange is performed with the relevant OAuth provider, and there is no validation of OAuth state, redirect URI, code expiration, client identity, PKCE verifier, or provider response. Consequently, an empty, expired, fabricated, or previously used authorization code produces an apparently valid local session with read and write scopes. Although connector operations are currently simulated, applications that treat `PlatformAuth.status` or `execute_action()` results as authoritative would accept a forged authentication state. ### Attack Path 1. Obtain access to a component exposing `ConnectorManager.authorize()`. 2. Call `authorize()` with an arbitrary platform and an empty or fabricated authorization code. 3. The method creates access and refresh token strings without contacting an OAuth provider. 4. `get_auth_status()` subsequently returns `AUTHORIZED`. 5. For a registered connector, c ...[truncated 555 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/permission_manager.py:164
Finding

Unrestricted Role Assignment Enables Administrative Privilege Escalation

Content
View full analysis
bool: """ Assign a role. Args: user_id: User ID role: New role Returns: bool: Whether the operation succeeded """ user = self.get_user(user_id) if not user: return False old_role = user.role user.role = role user.permissions = self.role_permissions.get(role, []) # Record audit log self._log_audit( user_id=user_id, action='user:assign_role', resource_type='user', resource_id=user_id, details={'old_role': old_role.value, 'new_role': role.value} ) return True ``` ### Technical Analysis `assign_role()` identifies only the account being modified. It does not accept or authenticate an acting administrator, check `team:manage`, enforce tenant boundaries, or require additional authorization for elevation to `UserRole.ADMIN`. Any caller able to invoke this method can assign the administrator role to an arbitrary existing user. The resulting user receives every permission because the administrator role maps to all permission identifiers. The audit record is also misleading: it records the target user as the actor, preventing reliable attribution of the privilege change. The same manager also permits callers to create users with a caller-selected role, including `UserRole.ADMIN`, without an authenticated administrative actor. ### Attack Path 1. Identify or create an existing user account. 2. Invoke `assign_role(target_user_id, UserRole.ADMIN)`. 3. The method replaces the target's role and permissions without checking the caller. 4. Use the promoted account to pass checks for workflow deletion, workflow approval, team management, and audit-log viewing. 5. The audit log attr ...[truncated 462 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/workflow_engine.py:209
Finding

Workflow Execution Bypasses Permission and Approval Controls

Content
View full analysis
ExecutionResult: """ Execute a workflow. Args: workflow_id: Workflow ID context: Execution context Returns: ExecutionResult: Execution result """ if workflow_id not in self.workflows: raise ValueError(f"Workflow {workflow_id} does not exist") workflow = self.workflows[workflow_id] execution_id = str(uuid.uuid4())[:8] start_time = time.time() ``` ### Technical Analysis The workflow engine validates only whether the requested workflow identifier exists. It does not identify the requesting user, call `PermissionManager.check_permission()`, verify workflow ownership or team membership, or check that a corresponding approval is in the `APPROVED` state. The permission and approval subsystem is therefore disconnected from the sensitive operation it is intended to protect. Workflow status is also not used to block draft, paused, or error-state workflows. A caller with access to the engine and knowledge of a workflow ID can execute it directly. Current default handlers simulate platform actions, which limits immediate external effects. Nevertheless, this is a security-boundary failure and would become directly exploitable if real connectors were attached to workflow handlers. ### Attack Path 1. Obtain or guess a workflow identifier present in `WorkflowEngine.workflows`. 2. Call `run(workflow_id)` directly without a user identity or approval token. 3. The engine checks only that the workflow exists. 4. Nodes execute regardless of workflow ownership, user role, approval state, or workflow status. 5. Execution results and logs record the run as ordinary workflow activity. ### Impact Assessment Any caller with engine access ...[truncated 324 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/execution_monitor.py:352
Finding

Execution Log Export Allows Arbitrary File Overwrite

Content
View full analysis
str: logs = self.get_execution_logs(execution_id=execution_id) if not filepath: timestamp = datetime.now().strftime('%Y%m%d_%H%M%S') filepath = f"execution_logs_{timestamp}.{format}" if format == 'json': data = [ { 'log_id': log.log_id, 'execution_id': log.execution_id, 'workflow_name': log.workflow_name, 'node_name': log.node_name, 'platform': log.platform, 'action': log.action, 'status': log.status.value, 'duration': log.duration, 'error': log.error, 'timestamp': datetime.fromtimestamp(log.start_time).isoformat() } for log in logs ] with open(filepath, 'w', encoding='utf-8') as f: json.dump(data, f, ensure_ascii=False, indent=2) elif format == 'csv': import csv with open(filepath, 'w', newline='', encoding='utf-8') as f: writer = csv.writer(f) ``` ### Technical Analysis The export method accepts a caller-controlled `filepath` and opens it in truncating write mode. It does not restrict output to an export directory, reject absolute paths or traversal components, canonicalize the destination, prevent symlink following, or use exclusive file creation. An attacker who can influence `filepath` can overwrite any file writable by the process. Symbolic links can also redirect an apparently safe path to another writable target. ### Attack Path 1. Invoke `export_logs()` with an absolute path, traversal path, or path to a malicious symbolic link. 2. Select either the JS ...[truncated 621 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/permission_manager.py:373
Finding

Audit Log Export Allows Arbitrary File Overwrite

Content
View full analysis
str: """ Export audit logs. Args: filepath: Export path Returns: str: Export file path """ if not filepath: from datetime import datetime timestamp = datetime.now().strftime('%Y%m%d_%H%M%S') filepath = f"audit_logs_{timestamp}.json" data = [ { 'id': log.id, 'user_id': log.user_id, 'action': log.action, 'resource_type': log.resource_type, 'resource_id': log.resource_id, 'details': log.details, 'timestamp': log.timestamp } for log in self.audit_logs ] with open(filepath, 'w', encoding='utf-8') as f: json.dump(data, f, ensure_ascii=False, indent=2) return filepath ``` ### Technical Analysis `export_audit_logs()` writes to an unrestricted caller-provided path using truncating mode. No path containment, permission check, symlink defense, or safe file-creation mechanism is applied. The method is also not internally protected by the declared `audit:view` permission. Thus, callers able to reach the manager may both retrieve sensitive audit information and choose an arbitrary writable destination. ### Attack Path 1. Call `export_audit_logs()` with a path to a writable configuration, data, or application file. 2. Alternatively, provide a path that resolves through a symbolic link to the intended target. 3. The method opens the destination in write mode and truncates it. 4. Serialized audit-log data replaces the existing file. 5. The overwrite can cause application failure or alter files consumed by later processing. ### Impact Assessment The attacker can overwrite files within the process's filesystem privileges and expo ...[truncated 282 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose focuses on cross-platform integrations, but the described/projected behavior includes access control, approvals, audit logging/export, and sensitive-action checks without clearly disclosing these capabilities. This mismatch is dangerous because reviewers and users may trust the skill as simple automation while it potentially handles governance, user management, and data export functions with materially different security and privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes workflows that automatically back up files and chat records across multiple external platforms without any visible warning about privacy, consent, retention, or access-control risks. In this context, users may enable automation involving personal messages, attachments, or business documents and unintentionally exfiltrate sensitive data to third-party services, especially because the skill targets low-code users and emphasizes fast setup.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill advertises executable workflow/code behavior but does not declare any explicit tool scope or permissions boundaries. For an automation skill that can write files and orchestrate actions, missing scope declarations increases the chance of overbroad execution, unclear operator expectations, and misuse in environments that rely on metadata for policy enforcement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The visible instructional content and examples are presented in Chinese, and the sample natural-language prompt is also Chinese, without indicating that other languages are supported or that the user may choose their preferred language. This can violate a language/locale policy when no opt-in or choice is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill promotes moving data between multiple external ecosystems but provides no warning about data transfer, account permissions, retention, or the possibility of propagating sensitive files across services. In cross-platform automation, omitted safety guidance can lead users to unintentionally expose confidential business or personal data through automated sync and export flows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description scopes the skill to cross-platform automation for ClawHub with WeChat, DingTalk, Feishu, and WPS integration. This configuration expands the actual supported ecosystem to include Tencent Docs and Aliyun Drive, which are additional platforms not reflected in the stated description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Aliyun Drive adds broad file upload, download, listing, folder creation, and sharing capabilities that exceed the narrowly stated messaging/document-automation description. In an automation skill, undisclosed storage and sharing connectors can expand the data-exfiltration and oversharing surface if workflows later gain access to user files or documents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module title and subsequent user-facing strings are written in Chinese, and the file provides no option for users to select another language or opt in to this locale. This can violate language/locale policy when a skill implicitly forces a specific language for interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example walks users through authorization and then prints part of an access token, while providing no warning that the flow is credential- and network-sensitive. Even partial token disclosure in example output can normalize unsafe handling, leak secrets into logs/screenshots, and encourage developers to replicate insecure practices in production integrations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language description explicitly advertises '中文语义理解' and all instructional text is framed around Chinese-language handling, which implies a language-specific constraint. There is no indication that users can choose another language or that the Chinese-only scope is an explicit opt-in or justified regional limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generator automatically creates high-impact actions such as sync_file, upload_file, and backup based only on keyword matching, and marks some as critical without any confirmation, preview, destination validation, or policy checks. In an automation skill that bridges multiple enterprise platforms, ambiguous or maliciously crafted natural-language instructions could cause unintended data movement, disclosure, or destructive propagation across connected services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The module title and descriptive text are written only in Chinese, with no indication that users can choose another language or that the locale restriction is intentional. Under the stated policy, a skill that effectively requires a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code exports execution logs to a file via open(...) and serializes workflow identifiers, names, actions, statuses, and errors. Although the function has a docstring describing parameters, there is no explicit user-facing warning, confirmation, or disclosure that potentially sensitive execution metadata will be written to local storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The export_audit_logs method serializes audit records containing user IDs, actions, resource identifiers, and details, then writes them to a JSON file. Although the function has a docstring, there is no explicit warning, confirmation, or user-facing disclosure that potentially sensitive audit data will be persisted to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language content, including module description, class/method docstrings, and all template names/descriptions, is entirely in Chinese with no indication that language is configurable or intentionally limited to a China-specific deployment. Under the stated policy, forcing a specific language without user opt-in is a locale-policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This method turns template definitions into executable workflows, including actions such as uploading WeChat files to cloud storage, organizing chat records, exporting approvals, and sending notices. Although these are safety-relevant data movement and write operations, the file provides no confirmation prompt, user-facing disclosure, or warning comment/docstring indicating that creating a workflow may cause external data transfer or document creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module-level docstring presents the skill description entirely in Chinese, including the title and feature description, without indicating that language selection is optional. This can violate language/locale policy when a skill imposes a specific language on users without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file uses Chinese-language connector names and comments throughout, and the configured services are exclusively China-specific platforms such as 微信, 钉钉, 飞书, 腾讯文档, and 阿里云盘. Under the policy, a locale/language constraint should be documented as intentional or offer user choice; this file contains no such justification or opt-in language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes a no-code cross-platform automation skill focused on integrations like WeChat, DingTalk, Feishu, and WPS. This example file also demonstrates creating users, assigning roles, checking permissions, processing approvals, and viewing audit logs, which are governance/identity-management capabilities rather than obvious automation connectors or workflow execution features.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower bound only (requests>=2.31.0), which allows future unresolved versions to be installed and makes builds non-reproducible. In an automation skill that likely performs network requests across external platforms, this increases supply-chain and patch-management risk because a vulnerable or behavior-changing release could be pulled without review.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
pyyaml>=6.0
python-dateutil>=2.8.0
schedule>=1.2.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
96% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin an exact version, it is impossible to verify from this file whether deployments will use an affected release. Given this skill's cross-platform automation purpose, requests is likely security-relevant because it may handle outbound HTTP calls, credentials, redirects, and remote content.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

pyyaml>=6.0 is unpinned, so the installed version may vary between environments and could include vulnerable or incompatible releases. This is more concerning in an automation skill because YAML libraries are often used to parse configuration or workflow data, and PyYAML has a history of deserialization-related issues when used unsafely.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
pyyaml>=6.0
python-dateutil>=2.8.0
schedule>=1.2.0

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
98% confidence
Finding

PyYAML has a history of serious advisories, and without an exact pinned version the manifest does not allow verification that a safe release will be installed. In a no-code automation skill, YAML may plausibly be used for user-editable configuration or workflow definitions, making version ambiguity more dangerous because parsing mistakes can expose deserialization or input-validation weaknesses.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

python-dateutil>=2.8.0 is not version-pinned, so dependency resolution can drift over time and produce non-reproducible installs. While this package is not inherently high risk from the manifest alone, unpinned versions still weaken supply-chain control and make it harder to guarantee that only reviewed releases are deployed.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.31.0
pyyaml>=6.0
python-dateutil>=2.8.0
schedule>=1.2.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

schedule>=1.2.0 is also unpinned, allowing uncontrolled future versions to be installed. In an automation-oriented skill, scheduler behavior changes could affect task execution reliability or introduce vulnerable transitive dependency states, even if the direct security impact from this manifest entry alone is limited.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
requests>=2.31.0
pyyaml>=6.0
python-dateutil>=2.8.0
schedule>=1.2.0

Static analysis

No suspicious patterns detected.