T09 · Insecure Skill Coding Practices
- Location
sp501lw_mqtt.py:197- Finding
MQTT Credentials and Device-Control Traffic Transmitted Without TLS
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent MQTT gateway management skill, but it needs review because it controls hardware while handling MQTT credentials and traffic insecurely.
Review before installing on real hardware. Use only test or authorized gateways, avoid the default public broker credentials, assume devices.json and command output may expose passwords, and avoid untrusted networks because TLS is not implemented. Pin dependencies and confirm device IDs, topics, and rebooting configuration changes before use.
sp501lw_mqtt.py:197MQTT Credentials and Device-Control Traffic Transmitted Without TLS
sp501lw_mqtt.py:320Broker Passwords Are Persisted and Returned in Plaintext
requirements.txt:1Open-Ended Dependency Version Allows Unreviewed Future Releases
This markdown file describes actions that can change device working mode, send serial commands, and modify MQTT/serial/network/OTA settings, all of which can affect connected hardware or system availability. The README provides usage examples but does not include any caution, confirmation note, or warning about validating commands before applying them to real devices.
The skill metadata does not declare any tool scope or allowed-tools restrictions even though the documentation clearly indicates local file read/write behavior via devices.json and JSON import/export flows. In an agent environment, missing explicit capability scoping can lead to broader-than-expected filesystem access and makes it harder to enforce least privilege.
The documentation includes plaintext broker credentials in a device record example without any warning that they are sensitive or should be rotated. Publishing reusable-looking usernames and passwords normalizes unsafe secret handling and may expose real infrastructure if the sample values are valid or copied into production.
The command examples pass passwords directly on the command line, which can expose secrets through shell history, process listings, logs, and terminal transcripts. This is especially risky on shared systems and agent platforms where command invocations may be captured automatically.
The documentation exposes a destructive reset capability with only minimal inline caution and no strong safeguards such as explicit confirmation workflow, recovery guidance, or access restrictions. In an agent-controlled device-management context, destructive commands can cause service disruption, configuration loss, and operational outages if invoked mistakenly or by prompt manipulation.
The installation instructions use npx clawhub@latest, which is effectively an unpinned remote package execution pattern. If the upstream package is compromised or changes unexpectedly, users may execute malicious code during installation.
The example script embeds MQTT broker credentials directly on the command line, exposing secrets in plaintext within the file and potentially in shell history, process listings, logs, or screenshots. In an MQTT management skill that configures real devices and brokers, this can lead to unauthorized broker access, device impersonation, or interception of operational telemetry and commands if copied into production use.
The top-level docstring states that the tool supports two modes only: mqtt_tcp and modbus_rtu. Elsewhere, the implementation and CLI advertise modbus_tcp as a valid mode, so the documented intent does not match the actual behavior.
The module docstring actively enumerates supported modes and omits modbus_tcp, creating a direct contradiction with the executable logic that permits modbus_tcp configuration. This is stronger than mere incompleteness because the documentation explicitly constrains supported behavior to two modes.
The code defines default MQTT broker credentials and later stores per-device broker usernames and passwords in plaintext within devices.json. Anyone with local file access can recover credentials and potentially connect to brokers, read device traffic, or send unauthorized control/configuration messages to managed gateways.
The manifest description limits the skill to '串口透传' and 'Modbus RTU 数据采集' via MQTT, which aligns with mqtt_tcp and modbus_rtu. However, the code explicitly accepts and configures a third work mode, modbus_tcp, extending the operational scope beyond what the manifest says.
SKILL.md 在 L163-L399 的命令参考中混合列出了已实现与规划中的命令,虽然有提醒,但同一文档仍详细描述了大量当前脚本未实现的能力,如设备端 MQTT/网络配置、OTA、重启、恢复出厂和信息查询。这会造成技能声明能力范围与实际可执行行为之间的偏差,属于描述与实际行为不完全一致。
The script's human-facing comments and echo messages are written entirely in Chinese, which imposes a specific language on users without any opt-in or explanation. Under the policy, locale or language constraints should either be optional for users or clearly documented as necessary for a region-specific use case.
All user-facing comments and echo output in the script are written in Chinese, and the file provides no option or note allowing another language. This is a natural-language policy concern because the skill implicitly enforces a specific locale without user opt-in or a documented region-specific requirement.
The script's comments and all user-visible output strings are written in Chinese, with no option to select another language or indication that the skill is intentionally region-specific. This can violate language/locale policy when a skill imposes a specific language without user opt-in or documented justification.
This shell script executes commands that register a device and switch its operating mode, which changes remote device configuration and transmits data over network topics. Although it prints step labels, it does not provide any explicit warning, confirmation, or cautionary note about modifying device state or interacting with remote MQTT topics.
The dependency is specified with only a lower bound, so future installs may resolve to newer unreviewed versions of paho-mqtt. This creates supply-chain and reliability risk because a breaking or compromised upstream release could be pulled into deployments without validation.
paho-mqtt>=2.0.0
The listen command connects to MQTT, subscribes to the device data topic, and prints received payloads directly to stdout. While the command purpose implies listening, the code does not explicitly warn users that potentially sensitive device or system data received over the network will be displayed verbatim.
No suspicious patterns detected.