Back to skill

Security audit

DeepSop工作台

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its DeepSOP sales-assistant purpose, but it handles sensitive customer and communication data with under-scoped automatic reporting and unsafe shell-oriented instructions.

Review before installing in any workspace with real customer data. Only use it where DeepSOP API access and report delivery destinations are tightly controlled, and require fixes for authenticated cron callbacks, fixed/authorized message targets, safe non-shell argument handling, stdin/file-based JSON transfer, and PII minimization or masking in chat and exported reports.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:117
Finding

Unauthenticated Auto-Query Trigger Allows Instruction Hijacking and Unauthorized Report Forwarding

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:1823
Finding

Shell Command Injection Through Interpolated Callback Fields and API Response JSON

Content
View full analysis
' '/tmp/aiwa_{aiwaDagTaskId前8位}.xlsx' cp /tmp/aiwa_{aiwaDagTaskId前8位}.xlsx ~/.openclaw/workspace/aiwa_{aiwaDagTaskId前8位}.xlsx openclaw message send --channel feishu --target {feishuChatId} --media ~/.openclaw/workspace/aiwa_{aiwaDagTaskId前8位}.xlsx --message 'AiWa 客户挖掘完成,共找到客户数据,详见附件' ``` A corresponding email-report command is also prescribed: ```sh python3 ~/.openclaw/workspace/skills/deepsop-humabot/scripts/format_emails.py '' '/tmp/frank_{frankDagTaskId前8位}.xlsx' cp /tmp/frank_{frankDagTaskId前8位}.xlsx ~/.openclaw/workspace/frank_{frankDagTaskId前8位}.xlsx openclaw message send --channel feishu --target {feishuChatId} --media ~/.openclaw/workspace/frank_{frankDagTaskId前8位}.xlsx --message 'Frank 邮件发送完成,详见附件' ``` ### Technical Analysis The Skill instructs the Agent to interpolate untrusted data into shell command strings. Relevant sources include: - `feishuChatId` parsed from callback text; - Task IDs parsed from callback text; - Complete DeepSOP JSON responses; - Customer, email, call, and SMS fields contained in those responses. Wrapping `` in single quotes does not make the operation safe. Any apostrophe in the JSON data terminates the shell-quoted argument. Shell metacharacters following that apostrophe can then be parsed as commands. Likewise, callback-controlled identifiers used in command arguments or paths can alter argument boundaries if they are not strictly validated. This is especially dangerous because the Skill explicitly directs the Agent to use an execution tool for these commands. The vulnerability ther ...[truncated 2022 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/format_customers.py:94
Finding

Spreadsheet Formula Injection in Generated Customer and Communication Reports

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向销售任务与外呼场景管理的自动化技能,核心能力应包括:解析用户意图、构造任务参数、通过指定脚本向 deepsop 提交任务、查询任务结果并推送。实际代码却只是一个离线格式化脚本:从命令行接收 JSON 和输出路径,解析 describeJobJson 中的通话详情,并使用 openpyxl 生成带样式的 xlsx 报表。代码中没有网络请求、没有 deepsop 接口、没有提交/审核逻辑、没有 cron 回调处理,也没有调用声明中要求的 submit_task.py 或 submit_script_review.py。其主要用途与声明的主要用途明显不同,因此属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向销售任务/场景审核的编排型技能,核心能力应是解析指令、调用 deepsop API、提交任务、轮询查询与推送结果,并且依赖特定提交脚本。实际代码仅是一个数据格式化工具,输入 JSON、输出 xlsx,不涉及任何 API 调用、任务提交、审核、定时触发或用户指令处理。该代码的主要用途与声明的主要用途明显不同,且实现了声明中未提及的导出 Excel 功能,因此属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码的实际功能与声明的核心目的明显不一致。声明描述的是一个面向销售任务和外呼场景的自动化技能,重点在调用 DeepSOP 接口提交任务、审核场景并查询结果;而给出的代码块只是一个数据导出工具,读取命令行参数中的 JSON,生成邮件数据报表并写入 xlsx 文件。它既没有使用 DEEPSOP_API_KEY,也没有任何 HTTP/API 调用、任务编排、cron 回调处理、submit_task.py 或 submit_script_review.py 相关行为。因此这是明显的 description-behavior mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是:根据用户销售/客户挖掘/外呼场景指令,调用 DeepSOP 平台接口提交任务、审核场景、等待查询并推送结果,还要求走特定 submit 脚本。实际代码完全没有这些行为。它只接收命令行参数中的 JSON 字符串和输出路径,解析短信结果列表,并使用 openpyxl 生成 Excel 文件。代码涉及的数据域是“Lisa 短信任务 getSmsResultList 返回的 JSON”,而不是客户挖掘、销售任务、电话场景或 DeepSOP。其资源访问模式也不同:仅本地文件写入,无网络请求、无 API key 使用、无定时触发逻辑、无提交/查询工作流。因此该代码块与声明用途存在明显且实质性的描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是 DeepSOP 销售任务/外呼场景的提交、审核、查询与推送,且依赖特定脚本与平台接口。提供的代码块却是完全不同领域的短信模板变量校验工具,关注时间、姓名、单位名、地址、验证码、邮箱等字段格式限制。该代码没有任何 DeepSOP API 调用、任务提交、轮询查询、cron 处理、自然语言解析或场景创建/审核逻辑。因此这不是对声明功能的支持性细节,而是一个与声明主用途明显不同的独立能力,构成实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The cron payload embeds task identifiers, customer-pool references, employee participation, chat destination IDs, and detailed instructions to transmit generated reports and summaries into external messaging channels. Storing and replaying this much operational and customer-linked context in plain text increases the blast radius of misdelivery, log leakage, job inspection, or unauthorized access to scheduled payloads.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The AiWa result preview explicitly instructs the agent to reveal personal and contact information in chat, including names, positions, company names, email addresses, phone numbers, and social handles. That is unnecessary broad disclosure of customer PII and business contact data, especially in chat contexts where access control, retention, and audience scope may be unclear.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The phone-call workflow directs disclosure of detailed call records, phone numbers, contact identities, and conversation content summaries. Call transcripts and interaction metadata are highly sensitive and may contain personal data, commercial information, or regulated communications that should not be broadly echoed into chat or pushed automatically.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The email and SMS result steps require exposing recipient email addresses, phone numbers, message subjects/content, delivery status, and timestamps in chat and exported files. This is a direct risk of leaking personal data, campaign content, and communication metadata to unintended viewers or systems, especially when combined with automatic push behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document first mandates script-only submission to preserve UTF-8 safety and validation, but later tells implementers to use curl for HTTP requests. Contradictory security guidance causes operators or agents to bypass the validated wrappers, which can disable input validation and increase the chance of malformed or unsafe direct requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage instructions tell users to 'directly speak your needs' and provide only Chinese example utterances, while the document as a whole is written primarily in Chinese. This creates a natural-language expectation that the skill operates in Chinese only, but the README does not offer users a language/locale choice or justify a locale restriction.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes capabilities that access environment secrets, read/write files, perform network requests, and execute shell commands, but it declares no explicit tool scope or permission boundaries. That increases the risk of overbroad execution and makes accidental or unauthorized use of sensitive capabilities harder to constrain or audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase 'instructions related to customer mining and sales tasks' lacks clear boundaries, making invocation ambiguous. In a skill that can process customer data and trigger external submissions, overbroad matching can lead to accidental task creation or disclosure from casual user prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The phrase 'instructions related to customer mining and sales tasks' lacks clear boundaries, making invocation ambiguous. In a skill that can process customer data and trigger external submissions, overbroad matching can lead to accidental task creation or disclosure from casual user prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is designed to handle API keys, user profile data, customer records, contact details, and outbound messaging, but it does not present clear upfront notice about collection, use, external transmission, or retention of that data. This weakens user consent and increases privacy/compliance risk, especially because data may be pushed to external channels and files may be generated on disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L0166 规定只要提及国家或地区且与中国无关联就返回“英文”,否则返回“中文”,这是基于地域的强制语言策略,而不是让用户选择语言。该规则会在未获用户明确偏好时替用户决定语言/locale,符合语言与区域策略方面的自然语言政策风险。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The main flow explicitly allows Frank/Fran/Lisa to run without AiWa by entering Step 1.6, where the user supplies customer sources via xlsx upload or company search. The error-handling bullet instead says such tasks should be terminated and the user told to add customer mining requirements, which is the opposite of the intended behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

In Step 3, when no PUBLISHED Fran scene exists, the documented behavior is to offer the user an immediate creation path via Step 1.7 or let them cancel. The error-handling section instead instructs outright termination and sending the user to the website, contradicting the interactive fallback flow defined earlier.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes this skill as analyzing sales instructions, submitting DeepSOP tasks, querying results, and creating/reviewing outbound-call scenarios. This file instead converts call-result JSON into an XLSX spreadsheet, which is a materially different user-visible behavior not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script writes sensitive call records to an Excel file, including contact names, phone numbers, company names, timestamps, and conversation summaries, without any built-in minimization, masking, consent prompt, or retention control. In this skill context, the data is sales/call-center information and may contain personal data and conversation content, so exporting it to a local file increases the risk of privacy leakage, secondary sharing, and non-compliant storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language docstring presents the script description, usage, and output entirely in Chinese, with no indication that other languages are supported or that Chinese is a required locale for a region-specific tool. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code file saves processed email task data, including recipient addresses, phone numbers, and LinkedIn details, to disk via wb.save(output_path). While the module docstring states that it outputs an xlsx file, there is no runtime confirmation or explicit user-facing warning that potentially sensitive contact data will be written to the specified path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language documentation and runtime messages exclusively in Chinese, including usage instructions and status summaries. That creates a locale policy issue if the skill is used in broader contexts, because it imposes a specific language without offering the user a choice or documenting that the skill is region/language-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 997)May include surrounding context.

md
DeepSOP agentSubmitTask 一站式提交脚本:UTF-8 安全 + 双重 pre-flight 校验 + HTTP 提交。

为什么需要这个脚本(替代 LLM 直接写 curl):
  - LLM 在 Windows bash 里写 `curl -d '{中文 JSON}'` 会触发 ANSI 代码页(cp936)
    与 UTF-8 之间的转码歧义,导致 taskName/taskDescription 提交后变成乱码。
  - 用本脚本后,body 通过 **stdin 字节流**进入 Python,统一按 UTF-8 解码;
    HTTP 请求体使用 `Content-Type: application/json; charset=utf-8` 显式声明编码,

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/submit_task.py (reported line 7)May include surrounding context.

python
DeepSOP agentSubmitTask 一站式提交脚本:UTF-8 安全 + 双重 pre-flight 校验 + HTTP 提交。

为什么需要这个脚本(替代 LLM 直接写 curl):
  - LLM 在 Windows bash 里写 `curl -d '{中文 JSON}'` 会触发 ANSI 代码页(cp936)
    与 UTF-8 之间的转码歧义,导致 taskName/taskDescription 提交后变成乱码。
  - 用本脚本后,body 通过 **stdin 字节流**进入 Python,统一按 UTF-8 解码;
    HTTP 请求体使用 `Content-Type: application/json; charset=utf-8` 显式声明编码,

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:41