Back to skill

Security audit

Travel In China

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Feishu travel-lead collector, but its instructions are internally inconsistent and it stores personal travel/contact data with incomplete user-facing safeguards.

Install only if you are comfortable giving the skill editable access to a specific Feishu Bitable and storing travelers' personal details there. Use a dedicated Feishu app/table with limited permissions, confirm users consent before submission, define retention/deletion procedures, and treat the itinerary CRUD text in SKILL.md as an ambiguity that should be fixed before broad use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:75
Finding

Installation from a Mutable, Unverified GitHub Repository

Content
View full analysis

Vulnerability Details

File Location: README.md:75-77
Vulnerability Type: Supply-chain exposure through a mutable installation source
Risk Level: Medium

Vulnerable Code:

bash
clawhub install https://github.com/lijingxu007/travel-Inbound-customizer.git

Technical Analysis

The documented installation command retrieves the Skill directly from a mutable GitHub repository without pinning an immutable commit hash, verifying an artifact checksum, or requiring a cryptographic signature. Consequently, the content installed by this command can differ from the version reviewed during this audit.

This is an insecure supply-chain practice rather than evidence that the repository currently contains malicious content. If the repository, maintainer account, or relevant branch is compromised, an attacker could modify files such as SKILL.md or tools.py. A later installation would then retrieve those unreviewed changes.

Attack Path

  1. An attacker compromises the GitHub repository, maintainer account, credentials, or default-branch update process.
  2. The attacker adds malicious instructions to SKILL.md or executable behavior to tools.py.
  3. A user follows the documented installation command.
  4. ClawHub retrieves the current mutable repository content rather than the audited revision.
  5. The modified instructions or Python code execute when the installed Skill is loaded or invoked.

Impact Assessment

The precise impact depends on the permissions granted to the Skill runtime and the content introduced by the attacker. Potential impact includes modification of Agent behavior, unauthorized network requests, access to environment variables available to the process, and disclosure or alteration of customer travel data and Feishu records.

The command does not itself establish elevated privileges, persistence, or current compromise. The exposure is limited by the permissions and credentials availab ...[truncated 26 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable repository URL with an installation reference pinned to a reviewed immutable commit or release artifact.
  • Publish signed releases and require signature verification before installation.
  • Provide a cryptographic checksum for the complete Skill artifact and verify it during installation.
  • Prefer a trusted package registry that supports immutable versions, provenance attestations, and integrity verification.
  • Protect the source repository with multi-factor authentication, branch protection, mandatory review, and restricted release permissions.
  • Document a controlled update process so new revisions receive security review before deployment.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded and Unhashed Python Dependency

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1
Vulnerability Type: Non-reproducible dependency resolution without integrity verification
Risk Level: Low

Vulnerable Code:

text
requests>=2.28.0

Technical Analysis

The dependency constraint specifies only a minimum version. It permits installation of any current or future requests release satisfying the constraint and does not provide an integrity hash. As a result, installations are not reproducible and may use a dependency version that was not included in this audit.

No evidence was found that the legitimate requests package is currently malicious. The risk arises if a future release, package-distribution account, package index, or dependency-resolution channel is compromised. Compatibility regressions in an unreviewed future release could also affect the handling of network requests containing authentication tokens and customer data.

Attack Path

  1. A malicious or compromised release satisfying requests>=2.28.0 becomes available through the configured package index, or an unreviewed future release introduces unsafe behavior.
  2. A new deployment resolves the dependency without an exact version or artifact hash.
  3. The unreviewed package is installed into the Skill environment.
  4. The package executes in the same Python process as tools.py.
  5. When the Skill authenticates or submits a lead, the affected networking component may access request headers, Feishu access tokens, endpoint details, and customer information handled by the process.

Impact Assessment

A compromised dependency would execute with the permissions of the Skill process. It could potentially read environment variables accessible to that process, including Feishu credentials, inspect customer lead data, alter API requests or responses, or make additional network connections.

This finding does not demonstrate an existing malicious dependency or auto ...[truncated 132 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin requests to an exact version that has been reviewed and tested.
  • Generate a lockfile covering direct and transitive dependencies.
  • Require cryptographic hashes for downloaded packages, such as through a hash-locked requirements file and pip --require-hashes.
  • Install packages only from a trusted, explicitly configured package index.
  • Use automated vulnerability monitoring, but review and test dependency updates before changing the pinned version.
  • Rebuild and redeploy from a controlled environment after dependency updates rather than resolving unrestricted versions at runtime.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (14)

Tainted flow: 'url' from os.getenv (line 134, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · tools.py (reported line 32)May include surrounding context.

python
try:
        # Timeout set to prevent hanging; strict HTTPS used by default
        resp = requests.post(url, json=payload, timeout=10)
        resp.raise_for_status()
        data = resp.json()

Tainted flow: 'url' from os.getenv (line 134, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · tools.py (reported line 141)May include surrounding context.

python
}
        payload = { "records": [{ "fields": fields }] }
        
        resp = requests.post(url, headers=headers, json=payload, timeout=10)
        resp.raise_for_status()
        result = resp.json()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that the skill automatically detects the user's language and continues the conversation in that language. This imposes a language/locale behavior without explicitly offering the user a choice or opt-in, which matches the policy's language/locale violation criterion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is presented as an inbound-travel lead collector, but the same document later expands scope into a general travel planner with database CRUD operations. This scope drift is security-relevant because users and reviewers may authorize the skill expecting passive data collection, while the agent is actually empowered to create, modify, search, and delete records.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented primary task says the assistant collects inbound-China travel requirements, but later instructions authorize broader itinerary management unrelated to that role. This contradiction can mislead users about what data will be stored and what backend actions may occur, increasing the chance of unauthorized or unexpected record operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly collects personal data such as full name, contact details, nationality, travel dates, budget, and special requirements, then stores it in Feishu Bitable, but provides no privacy notice, consent flow, retention policy, or handling limitations. This creates privacy and compliance risk because sensitive travel inquiry data may be gathered and persisted without users being informed how it will be used or protected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation advertises update/delete capabilities without safeguards or warnings about destructive actions. In an agent context, undocumented destructive behavior increases the chance of accidental data loss and weakens user ability to make informed decisions before the assistant mutates stored records.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Delete capability is not justified by the stated assistant role of collecting inbound travel requirements. Unnecessary destructive permissions materially raise risk because a prompt mistake, misuse, or malicious instruction could remove itinerary records from the Feishu table without a legitimate business need.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools.py (reported line 32)May include surrounding context.

python
try:
        # Timeout set to prevent hanging; strict HTTPS used by default
        resp = requests.post(url, json=payload, timeout=10)
        resp.raise_for_status()
        data = resp.json()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code defaults currency to CNY and language_pref to English, then maps output fields to Chinese labels such as 姓名 and 语言需求. This reflects a built-in language/locale assumption rather than offering an explicit user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This function transmits user-provided lead data, including contact details and potentially travel preferences, to an external third-party service. In this skill context, that is the intended business function, but it is still security-relevant because there is no consent check, data minimization control, or validation that the destination dataset is appropriate for the sensitivity of the data being sent.

Content

Scanner excerpt · tools.py (reported line 141)May include surrounding context.

python
}
        payload = { "records": [{ "fields": fields }] }
        
        resp = requests.post(url, headers=headers, json=payload, timeout=10)
        resp.raise_for_status()
        result = resp.json()

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified as requests>=2.28.0, which allows any newer version to be installed and makes builds non-reproducible. This can unexpectedly pull in vulnerable or breaking releases over time, and prevents reviewers from verifying exactly which version is in use.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Because requests is not pinned, it is impossible to determine from this manifest whether the installed version is one of the releases affected by known advisories. This uncertainty weakens supply-chain assurance and may allow a vulnerable version to be resolved at install time depending on environment and timing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The header comment says sensitive credentials are never exposed in error messages, but the function later returns a message listing missing configuration variable names including FEISHU_APP_SECRET. While this does not reveal the secret value itself, it contradicts the stated documentation about non-exposure in error output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.