Back to skill

Security audit

Deepsop Kuaishou 工作台

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Kuaishou uploader, but it automatically fetches and runs mutable third-party code and mirror-sourced executables before posting user media.

Review before installing. Only use this if you are comfortable letting the agent download and run the social-auto-upload project, install browser automation dependencies, store local Kuaishou session files, and publish selected media to Kuaishou. Prefer a pinned reviewed commit, no unofficial mirrors, explicit confirmation before uploads, and an isolated account/media directory.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/runtime-requirements.md:34
Finding

Automatic Retrieval and Execution of Mutable Third-Party Code

Content
View full analysis

Vulnerability Details

File Location: references/runtime-requirements.md:34-82
Additional Location: SKILL.md:34-39
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Technical Analysis

The skill instructs the agent to clone the social-auto-upload repository automatically and, if the canonical GitHub source is unavailable, retry through an unofficial Gitee fork and multiple proxy services. The retrieved repository is not pinned to a reviewed commit, tag, or cryptographic digest.

Relevant instructions include:

bash
git clone https://github.com/dreammis/social-auto-upload.git "$HOME/.openclaw/social-auto-upload"

# Attempt 1: Gitee mirror
git clone https://gitee.com/lonycn/social-auto-upload.git <SAU_HOME>

# Attempt 2: gh-proxy.org
git clone https://gh-proxy.org/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>

# Attempt 3: gh-proxy.com
git clone https://gh-proxy.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>

# Attempt 4: gitmirror
git clone https://hub.gitmirror.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>

The downloaded project is subsequently used as the execution environment:

bash
uv sync --python 3.12
uv run --project <SAU_HOME> python sau_cli.py --help

Because no commit identity, signed tag, or content hash is validated, the effective code executed by the skill can change after the skill package itself has been reviewed. The Gitee URL also refers to a separately controlled repository rather than a cryptographically authenticated representation of the canonical repository.

Attack Path

  1. An attacker compromises one of the configured repositories or proxy delivery paths, or controls the unofficial mirror.
  2. The canonical GitHub clone fails or times out.
  3. Following the skill instructions, the agent automatically retries the configured mirro ...[truncated 1078 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the upstream project to a specifically reviewed commit hash rather than cloning the mutable default branch.
  2. Verify the checked-out commit before running dependency installation or any Python entry point.
  3. Use only the canonical repository unless each mirror is authenticated and proven to provide byte-for-byte identical Git objects.
  4. Remove the unofficial Gitee fork from automatic fallback handling.
  5. Where possible, distribute a reviewed, immutable source archive with a published SHA-256 digest or vendor the necessary code into the skill package.
  6. Require explicit user confirmation before first-time retrieval and execution of external code.
  7. Run the external uploader in a sandbox with access limited to the selected media files and a dedicated credential directory.
  8. Treat an existing checkout as untrusted until its remote URL and current commit have both been validated.

T08 · Insecure Dependencies

Error
Location
references/runtime-requirements.md:86
Finding

Unverified Dependency and Browser Binary Installation

Content
View full analysis

Vulnerability Details

File Location: references/runtime-requirements.md:86-119
Vulnerability Type: Insecure third-party dependency and executable installation
Risk Level: High

Technical Analysis

The setup procedure installs Python dependencies from metadata contained in the externally cloned project and downloads a Chromium executable through an alternate mirror:

bash
cd <SAU_HOME>

# Windows
copy conf.example.py conf.py

# macOS / Linux
cp conf.example.py conf.py

uv sync --python 3.12
powershell
$env:PLAYWRIGHT_DOWNLOAD_HOST="https://npmmirror.com/mirrors/playwright"
uv run --project "$env:USERPROFILE\.openclaw\social-auto-upload" patchright install chromium
bash
PLAYWRIGHT_DOWNLOAD_HOST="https://npmmirror.com/mirrors/playwright" \
  uv run --project "$HOME/.openclaw/social-auto-upload" patchright install chromium

Although the documentation states that the upstream uv.lock pins dependency versions, the lockfile itself is obtained from a mutable remote repository. The skill does not independently validate the lockfile, enforce known package hashes, verify signatures, or validate the downloaded browser executable against a trusted digest.

A lockfile controlled by the same untrusted source as the executable project does not establish an independent trust boundary. Package build hooks, installed command entry points, or a substituted browser artifact may execute code in the user's context.

Attack Path

  1. An attacker modifies the remotely retrieved repository, its dependency metadata, or a configured artifact source.
  2. The modified project references a malicious package, build backend, dependency source, or browser artifact.
  3. The agent executes uv sync --python 3.12.
  4. Dependency resolution, package installation, or package build logic introduces attacker-controlled code.
  5. The agent runs patchright install chromium using the configured ...[truncated 816 chars]
Remediation
View remediation

Remediation Suggestions

  1. Maintain a reviewed dependency lockfile within an immutable, trusted release of the skill.
  2. Enforce package hashes and reject artifacts whose digests do not match approved values.
  3. Pin the external SAU repository to a reviewed commit before trusting its pyproject.toml or uv.lock.
  4. Verify browser downloads using publisher-provided signatures or known SHA-256 hashes.
  5. Prefer the verified official browser artifact source; do not silently redirect executable downloads to an alternate mirror.
  6. Record and validate the expected Patchright and Chromium versions.
  7. Disable unnecessary package build isolation exceptions and avoid dependencies that execute uncontrolled installation hooks.
  8. Perform installation and browser execution in a restricted sandbox or container with narrowly scoped filesystem access.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/examples/kuaishou_cli_template.py:1
Finding

Python Example Contains Corrupted Non-Python Source Text

Content
View full analysis

Vulnerability Details

File Location: scripts/examples/kuaishou_cli_template.py:1
Vulnerability Type: Invalid and apparently corrupted executable template
Risk Level: Low

Technical Analysis

The Python example begins with PowerShell-like interpolation text rather than a valid Python module docstring:

python
 '"""' + $args[0].Groups[1].Value.ToUpper() uaishou CLI invocation template.

The $args[0].Groups[1].Value.ToUpper() expression is not valid Python syntax. As a result, the advertised template cannot be parsed or executed by Python. The line appears to be residue from an unsafe or defective text-generation or replacement operation.

No malicious payload is executable through this malformed line as written. Nevertheless, shipping corrupted executable source is an integrity and availability problem and indicates that generated artifacts were not syntax-validated before publication.

Attack Path

  1. A user copies or directly runs scripts/examples/kuaishou_cli_template.py.
  2. Python parses the first line.
  3. Parsing fails because the line contains invalid $args syntax and malformed text.
  4. None of the intended commands execute, preventing the documented workflow.

Impact Assessment

The direct impact is denial of the example script's intended functionality. It does not, based on the reviewed content, provide code execution, credential access, or privilege escalation. The broader concern is reduced confidence in the integrity of generated project files and the possibility that similar unvalidated transformations could produce more dangerous corruption elsewhere.

Remediation
View remediation

Remediation Suggestions

  1. Replace the first line with a valid static Python docstring, for example:
python
"""Kuaishou CLI invocation template.

Assumes social-auto-upload was cloned to SAU_HOME and dependencies are ready.
"""
  1. Run python -m py_compile scripts/examples/kuaishou_cli_template.py in continuous integration.
  2. Add linting and formatting checks for every distributed script.
  3. Review the process that produced the interpolation residue and remove unsafe cross-language replacement logic.
  4. Regenerate and manually inspect affected release artifacts before redistribution.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/cli-contract.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/runtime-requirements.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/examples/kuaishou_commands.ps1 (reported line 1)May include surrounding context.

text
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that first use will automatically clone an external repository and prepare dependencies, but it does not present this as a prominent user warning or explain the supply-chain and code-execution implications. Auto-fetching and preparing third-party code can introduce unreviewed code execution and network access on the user's machine without sufficiently informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage examples encourage natural-language invocation and automatic execution, but do not clearly warn that the selected images or videos will be uploaded to Kuaishou, an external service. This can lead to accidental disclosure of private media or unintended publication because the agent workflow obscures the boundary between local file selection and remote upload.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs shell-capable behavior such as cloning a repository, running dependency synchronization, and executing Python commands, yet it declares no explicit tool scope or permission boundaries. This weakens policy enforcement and increases the chance an agent may perform filesystem and network actions without transparent authorization or least-privilege constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs automatic cloning of an external repository and automatic dependency setup on first use, but does not require a clear user-facing warning that code will be fetched from the network and written to the local filesystem. This creates supply-chain and consent risks, especially because executing newly fetched code can change the host environment and expose the user to malicious upstream changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill mandates automatic retry through third-party GitHub mirror domains after clone failure, without warning the user that requests may be redirected to untrusted intermediaries. This materially increases supply-chain and privacy risk because code and metadata may come from alternate infrastructure outside the original source's trust boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and all operational instructions are written in Chinese, with no indication that users may choose another language or locale. Per the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to automatically clone and execute code from a third-party repository and, on failure, silently retry via multiple unofficial mirror/proxy sources without user confirmation. This creates a significant supply-chain risk because the mirrors may serve altered content, and the agent is directed to proceed automatically before any integrity verification or trust check.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes this as a Kuaishou upload/login/account-check skill, but the runtime documentation explicitly states the bundled CLI exposes four platform commands: douyin, kuaishou, xiaohongshu, and bilibili. This indicates the skill operational scope is broader than the user-facing description suggests, which is a semantic mismatch in declared purpose versus actual supported behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing operational instructions only in Chinese, which can amount to forcing a specific language without user opt-in. The stated policy requires flagging language or locale constraints unless the skill offers a choice or clearly documents a justified regional limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs login, account checking, and content uploads to Kuaishou automatically, including explicit upload-video and upload-note actions, without any user-facing confirmation, warning, or dry-run safeguard before posting to an external service. In the context of an agent skill that may be invoked on a user's behalf, this creates a real risk of unintended publication, account misuse, or accidental disclosure of media and metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script includes headless upload commands that can publish content without an interactive user review step or any explicit warning in the example itself. In the context of a social-media auto-upload skill, this increases the risk of unintended posting, misuse of the wrong account, or accidental publication of sensitive or non-compliant content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

全文以中文向 agent 下达强约束性操作说明,未见提供其他语言选项或声明该技能仅面向中文场景。按规则,若技能强制特定语言而无用户选择或明确合理的地域限定,可视为自然语言政策问题。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill as a Kuaishou-specific automation tool, but the runtime requirements direct the agent to clone and set up the entire upstream social-auto-upload project. Since that upstream project is a broader social-platform automation suite, the documented behavior exceeds the narrow scope claimed in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document directs copying configuration and synchronizing dependencies into a user-directory project path, which performs local filesystem writes and environment setup without an explicit warning or consent checkpoint. In the context of an agent skill, silent writes and dependency installation can surprise users and increase the risk of unwanted persistence or execution side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The file includes natural-language guidance in Chinese, which imposes a specific language on users without any opt-in or explanation that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.