Back to skill

Security audit

Zhihu

Security checks for vulnerabilities and agentic risk

Overview

This skill automates live Zhihu actions, but its code and documentation are aligned with that purpose and do not show hidden or unrelated behavior.

Install only if you intend to let the agent act on a real Zhihu integration. Treat the Zhihu app key and secret as sensitive credentials, prefer a restricted account or least-privilege token if available, and manually confirm publish, like, comment, and delete actions before running them because they can affect public account state.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:27
Finding

Unpinned Third-Party Installation Commands Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 27-32
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: Medium

bash
3. `requests` library: `pip install requests`

### Install the Skill

```bash
npx clawhub install zhihu
text

### Technical Analysis

The installation instructions resolve third-party packages without specifying reviewed versions, lockfiles, package hashes, or integrity metadata. As a result, the installed code can change independently of the audited Skill.

`pip install requests` selects the version currently resolved by the configured Python package index. The `npx clawhub install zhihu` command may download and execute the currently resolved `clawhub` package. In particular, `npx` can execute remotely retrieved package code, including package lifecycle behavior, without the project pinning the package to an audited release.

This is a supply-chain weakness rather than evidence that either dependency is currently malicious. Exploitation would require compromise or substitution of a package, registry, release, dependency, or package-resolution source.

### Attack Path

1. An attacker compromises a relevant package or release, publishes a malicious version under a package name that the commands resolve, or influences the user's registry configuration.
2. A user follows the documented `pip install requests` or `npx clawhub install zhihu` instruction.
3. The package manager resolves the attacker-controlled or compromised version because no exact reviewed version or integrity hash is required.
4. Installation hooks, package execution through `npx`, or subsequently imported dependency code runs in the user's environment.
5. Malicious code can act with the permissions of the user running the installation or Skill.

### Impact Assessment

Successful exploitation could allow arbitrary code execution with the installing user's privileges. Depending on t
...[truncated 528 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin every dependency and installation tool to an exact, reviewed version.
  • Provide a dependency lockfile generated from reviewed artifacts.
  • Require cryptographic hashes for Python packages, such as through a hash-locked requirements file and pip install --require-hashes.
  • Replace implicit npx resolution with an explicitly pinned package version and use integrity verification where supported.
  • Document the expected package registries and recommend rejecting untrusted registry overrides.
  • Review package provenance, release signatures, transitive dependencies, and lifecycle scripts before updating pinned versions.
  • Run installation and the Skill as an unprivileged user in an isolated environment with access only to the required Zhihu credentials and network destination.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes account-affecting actions such as posting, liking, commenting, and deleting content, but does not warn users that these operations change live Zhihu account state. This is dangerous because users or downstream agents may treat the skill as informational and unintentionally perform irreversible or reputation-impacting actions against a real account. The context makes this more serious because the tool is explicitly designed for social-platform automation, where accidental actions can create spam, abuse, or unwanted public activity.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The README instructs users to run npx clawhub install zhihu without pinning a specific package version. This creates a supply-chain risk because users may install whatever version is current at execution time, including a compromised or malicious release if the upstream package or dependency chain is tampered with. The skill context increases risk because this installation path is the primary onboarding step and the package will likely run with the user's local environment and credentials available.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The credential setup section tells users to store ZHIHU_APP_KEY and ZHIHU_APP_SECRET in local configuration without warning that these are sensitive secrets. This can lead to accidental exposure through file sharing, backups, screenshots, or weak filesystem permissions, and leaked credentials could let an attacker act on the user's Zhihu integration. The skill context increases the danger because the credentials authorize account-affecting API operations such as posting and deleting content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents a destructive comment delete action with no warning, confirmation guidance, or note about irreversibility. In an agentic context, this increases the chance of accidental moderation actions or unintended deletion of user-generated content, especially if the command is invoked from ambiguous user requests or automation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/zhihu_bot.py (reported line 70)May include surrounding context.

python
if method == "GET":
                response = requests.get(url, headers=headers, params=params, timeout=30)
            elif method == "POST":
                response = requests.post(url, headers=headers, params=params, json=data, timeout=30)
            else:
                raise ValueError(f"不支持的 HTTP 方法: {method}")

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions and operational guidance are presented in Chinese, and the file does not indicate that the user can choose another language or that the locale restriction is intentional and justified. This can violate language/locale policy when a specific language is effectively forced without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring says the tool supports posting pins, liking, and commenting, which implies creation/interaction features. However, the code also implements comment deletion via the /openapi/comment/delete endpoint, a materially different destructive action not reflected in the top-level documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.