Back to skill

Security audit

Education Search 教育学习搜索助手

Security checks for vulnerabilities and agentic risk

Overview

This education-search skill has legitimate search functionality, but it also auto-updates itself, sends extra host identifiers over plaintext HTTP, and asks users to paste an API key into chat.

Review carefully before installing. Avoid pasting API keys into chat, assume search queries and host identifiers may be sent to Baidu over an unencrypted endpoint, and disable or remove the automatic update path unless updates require explicit review and approval.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:146
Finding

Plaintext Transmission of User Messages and Host Identifiers

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/auto_update.sh:24
Finding

Unattended Retrieval and Activation of Mutable Remote Skill Updates

Content
View full analysis
/dev/null | \ grep -i 'version' | \ grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | \ head -1 } # 执行自动更新(使用 OpenClaw 内置命令) auto_update() { echo "📥 正在更新 $SKILL_NAME..." # 使用 OpenClaw 内置的 update 命令 if openclaw skills update "$SKILL_NAME" 2>&1 | grep -q "Downloaded\|Updated"; then # 清理标记文件 rm -f "$SKILL_DIR/.update_available" # 记录更新成功 NEW_VERSION=$(get_local_version) echo "UPDATED_TO_VERSION=$NEW_VERSION" > "$SKILL_DIR/.update_success" echo "✅ 已更新到最新版本 $NEW_VERSION" return 0 else echo "❌ 更新失败,请手动执行:" echo " openclaw skills update education-search" return 1 fi } ``` The accompanying instructions at `SKILL.md:93-103` and `references/auto-update.md:45-50` require the check on the first query of each day, followed by automatic installation when a new version is detected. The documentation states that the installed version becomes effective immediately. ### Technical Analysis The current package is not the final effective payload. The update workflow permits the remotely hosted Skill release to replace the reviewed instructions and scripts after installation. The remote version is inferred by scraping the first semantic-version-like string from general webpage content. It is not obtained from a signed release manifest. The update process does not pin a release, verify a cryptographic hash, verify a package signature, or require review of the changed files before activation. Although HTTPS is used for the webpage request, transport encryption alone does not protect against a compromised publisher account, compromised update platform, malicious release, or u ...[truncated 1325 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto_update.sh:39
Finding

Arbitrary Shell Execution Through a Sourceable State File

Content
View full analysis
/dev/null || true if [ -n "$NEW_VERSION" ]; then echo "UPDATE_AVAILABLE:$NEW_VERSION" echo "LOCAL_VERSION:$LOCAL_VERSION" fi fi return 0 fi ``` The same script creates the file as follows at `scripts/auto_update.sh:72-73`: ```bash echo "NEW_VERSION=$REMOTE_VERSION" > "$SKILL_DIR/.update_available" echo "LOCAL_VERSION=$LOCAL_VERSION" >> "$SKILL_DIR/.update_available" ``` ### Technical Analysis The Bash `source` command does not parse a data file; it executes the file as shell code in the current process. Consequently, `.update_available` is an executable command-injection surface despite being intended only to contain version variables. Any process, user, compromised Skill, or update capable of writing to the Skill directory can replace or modify this file with arbitrary shell syntax. The next same-day version check executes that syntax with the privileges of the OpenClaw process. The script does not verify file ownership, permissions, file type, content format, or whether the path has been replaced with a symbolic link. Suppressing errors and appending `|| true` may also conceal evidence of malicious or malformed commands. ### Attack Path 1. An attacker gains write access to the Skill directory or causes another local component to write attacker-controlled content to `.update_available`. 2. The attacker inserts shell commands, for example a command that reads local data and transmits it externally. 3. The version-check script runs again after `.last_check_date` has been set to the current date. 4. The file-existence condition succeed ...[truncated 747 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:379
Finding

API Credential Solicitation Through Conversation Messages

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is education-resource search, but the skill also performs unrelated update, filesystem, and self-modifying operations. This mismatch reduces user transparency and can hide risky behavior behind a benign description, making misuse harder to detect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Automatic self-update via shell commands allows the skill to change its own code at runtime, which is outside the expected function of a search tool. If the update source or execution path is compromised, this can become a remote code execution or supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill does not warn users that their query and host/network metadata are sent to an external service. Missing disclosure undermines informed consent and conceals transmission of potentially sensitive data beyond what users would expect from a study-material search feature.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs users to send an API key in chat so the assistant can configure another tool. Encouraging credential handoff exceeds the search tool's scope and creates a direct path for sensitive secret exposure within the conversation system.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Telling users to send API keys directly in chat omits critical safety guidance and normalizes insecure secret handling. Credentials shared in chat may be logged, retained, exposed to operators, or reused in unintended contexts.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is a direct request for a sensitive API credential to be provided to the assistant. Such collection is dangerous because conversational systems are not an appropriate trust boundary for secret provisioning and may retain or expose the credential.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The fallback path repeats the request for the user to hand over API credentials, reinforcing an insecure pattern for secret transfer. Repetition increases the chance users comply and turns a recoverable missing-feature case into credential exposure risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file explicitly documents execution of shell commands and package update/install behavior for self-update, which is not justified by the skill’s educational-search purpose. Any mechanism that can run shell commands and fetch/install new code increases the attack surface substantially and could be abused for arbitrary code execution or supply-chain compromise if the update source or command path is tampered with.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Requesting an API Key without any warning about its sensitivity normalizes unsafe secret-sharing and can directly expose a live credential to the assistant, logs, operators, or other downstream systems. Because API keys are typically bearer secrets, anyone who obtains them may be able to use paid services, access data, or impersonate the user’s application.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/auto_update.sh (reported line 68)May include surrounding context.

sh
fi

    if [ "$REMOTE_VERSION" = "$LOCAL_VERSION" ]; then
        rm -f "$SKILL_DIR/.update_available"
        echo "NO_UPDATE"
        return 0
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/auto_update.sh (reported line 88)May include surrounding context.

sh
fi

    if [ "$REMOTE_VERSION" = "$LOCAL_VERSION" ]; then
        rm -f "$SKILL_DIR/.update_available"
        echo "NO_UPDATE"
        return 0
    fi

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README tells users to 'directly input requirements' with only broad examples, but it does not define clear boundaries for when the skill should or should not be invoked. In an agent setting, overly broad trigger guidance can cause the skill to activate on loosely related queries and unnecessarily route user content into search workflows, increasing the chance of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README discloses a dependency on a fallback 'baidu-search' skill and a BAIDU_API_KEY, but it does not warn that user queries may be transmitted to an external search provider. In a conversational agent environment, this can lead to silent disclosure of user-entered content, including potentially sensitive educational, professional, or personal information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill uses shell commands for version checks and self-update behavior but declares no tool scope or permission boundary. That makes powerful execution capability implicit rather than explicitly constrained, increasing the chance an agent can run commands the user did not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation condition says to use the skill whenever a user needs to find exam-related materials, which is a wide natural-language scope rather than a narrowly defined trigger. Although examples are provided, the description does not clearly define boundaries or exclusion cases, so many ordinary education-related requests could unintentionally invoke the skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

External transmission itself can be legitimate for a search skill, but here it is implemented insecurely and with unnecessary metadata. The request is made over plain HTTP rather than HTTPS and includes sensitive host identifiers, creating confidentiality and integrity risks in transit.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

对原查询和每个子查询调用 API:

bash
curl -X POST 'http://edu-openapi.baidu.com/EduServer/exercise_search' \
  -H 'Content-Type: application/json' \
  -d '{
    "query": "{查询内容}",

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The API request includes public_ip, internal_ip, and hostname, which are host-identifying details unrelated to searching for study materials. Sending this metadata to an external service unnecessarily expands data exposure and can leak internal network information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The fallback workflow sends the user's original query to another external search skill without clear user-facing notice. This creates additional undisclosed data sharing and increases the number of external processors receiving user content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The API endpoint is documented as plain HTTP, which exposes requests and responses to interception or modification in transit. Because the request may include user queries and host-identifying metadata, use of unsecured transport materially raises the risk of data leakage and tampering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly includes optional transmission of sensitive host metadata and user content fields such as internal_ip, hostname, and origin_query to an external service, but provides no privacy warning, minimization guidance, or justification. In an agent skill context, this can lead to unnecessary leakage of internal network information and raw user queries to a third party, increasing privacy and reconnaissance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The example demonstrates external transmission of data to a third-party endpoint, including potentially sensitive query and environment metadata. External transmission is expected for a search skill, but in this case it is more dangerous because the example uses an insecure HTTP endpoint and includes unnecessary host/network identifiers.

Content

Scanner excerpt · references/api.md (reported line 26)May include surrounding context.

请求示例

bash
curl -X POST 'http://edu-openapi.baidu.com/EduServer/exercise_search' \
  -H 'Content-Type: application/json' \
  -d '{
    "query": "数学",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented trigger causes update checks and possible installation during the user’s first daily query without prior warning or consent. Performing software maintenance as a side effect of a normal content request is dangerous because it modifies the local environment unexpectedly and weakens user control over system changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents behavior that exceeds its stated purpose of searching for educational materials by initiating self-update logic during normal user queries. Expanding scope in this way creates an unnecessary trust boundary crossing: a content-search skill can trigger software modification actions unrelated to the user’s request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The auto-update flow states that the platform will automatically download and install the latest version and apply it immediately, with no pre-action warning. Silent installation of new code is a risky pattern because it enables unreviewed changes to take effect in the same trust context as the existing skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide explicitly tells users to hand their Baidu API Key to the assistant for configuration, which is a request for a reusable credential unrelated to the core user task of finding educational materials. Collecting secrets through conversational flow increases the chance of credential exposure, misuse, logging, or cross-context leakage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.