Back to skill

Security audit

碳硅契社区连接器

Security checks for vulnerabilities and agentic risk

Overview

This is a forum client skill, but it sends agent identity and post content to default plaintext HTTP services and leaves some posting behavior and automation limits under-documented.

Review the configured community URLs and identityPath before use. Only run init, post, reply, or bilingual if you are comfortable publishing the selected agent name, emoji, description, and post content to those servers, and prefer HTTPS endpoints or a minimal public identity file. Treat the cron example as optional and user-managed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/csb-community-client.js:14
Finding

Agent identity metadata is transmitted over plaintext HTTP

Content
View full analysis
{ const reqUrl = new URL(url); const postData = JSON.stringify(data); const req = http.request({ hostname: reqUrl.hostname, port: reqUrl.port, path: reqUrl.pathname, method: 'POST', headers: { 'Content-Type': 'application/json; charset=utf-8', 'Content-Length': Buffer.byteLength(postData), } }, (res) => { let responseData = ''; res.on('data', chunk => responseData += chunk); res.on('end', () => { try { resolve(JSON.parse(responseData)); } catch (e) { resolve(responseData); } }); }); req.on('error', reject); req.write(postData); req.end(); }); } ``` ```javascript async function createPost(config, post) { const url = new URL('/api/posts', config.communityUrl).toString(); return httpPost(url, post); } ``` The bundled root configuration explicitly selects plaintext HTTP and an identity file in the OpenClaw workspace ...[truncated 2816 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/csb-community-client.js:59
Finding

Unbounded and timeout-free buffering of remote HTTP responses

Content
View full analysis
{ const reqUrl = new URL(url); http.get(reqUrl, (res) => { let data = ''; res.on('data', chunk => data += chunk); res.on('end', () => { try { resolve(JSON.parse(data)); } catch (e) { resolve(data); } }); }).on('error', reject); }); } // HTTP POST request function httpPost(url, data) { return new Promise((resolve, reject) => { const reqUrl = new URL(url); const postData = JSON.stringify(data); const req = http.request({ hostname: reqUrl.hostname, port: reqUrl.port, path: reqUrl.pathname, method: 'POST', headers: { 'Content-Type': 'application/json; charset=utf-8', 'Content-Length': Buffer.byteLength(postData), } }, (res) => { let responseData = ''; res.on('data', chunk => responseData += chunk); res.on('end', () => { try { resolve(JSON.parse(responseData)); } catch (e) { resolve(responseData); } }); }); req.on('error', reject); req.write(postData); req.end(); }); } ``` ### Technical Analysis Both network helpers append every response chunk to an in-memory string without imposing a maximum response size. The requests also have no connection, inactivity, or total-operation timeout. A malicious, compromised, or intercepted server can therefore: - Return an arbitrarily large response and cause excessive memory consumption. - Stream data indefinitely, continuously increasing process memory use. - Accept a connection but never complete the response, leaving the process hanging. - ...[truncated 1885 chars]
Remediation
View remediation
{ size += chunk.length; if (size > MAX_RESPONSE_BYTES) { res.destroy(); reject(new Error('Response exceeds the permitted size')); return; } chunks.push(chunk); }); res.on('end', () => { if (res.statusCode < 200 || res.statusCode >= 300) { reject(new Error(`Unexpected HTTP status: ${res.statusCode}`)); return; } const body = Buffer.concat(chunks).toString('utf8'); try { resolve(JSON.parse(body)); } catch { reject(new Error('Server returned invalid JSON')); } }); } req.setTimeout(REQUEST_TIMEOUT_MS, () => { req.destroy(new Error('Community request timed out')); }); ``` When documenting optional cron polling, use an absolute trusted project path, include removal instructions, and recommend a locking mechanism so a stalled request cannot produce overlapping jobs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code substantially aligns with a CSB community client: it can check posts, publish posts, publish replies, and perform an initial 'report-in' post using an identity file. However, several declared capabilities are not actually implemented. There is no registration logic, no built-in scheduler or automatic polling loop, and no automatic reply behavior despite the description claiming timed checks and auto posting/replying. The 'autoReply' setting is never used. Also, 'accessing' the forum is limited to printing URLs and calling HTTP APIs against configured endpoints rather than actually opening or browsing the forum. Additionally, the code contains a notable undeclared feature: bilingual posting to a second configured community URL. Because the description materially overstates implemented automation/registration capabilities and omits a real posting target variation, this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
node scripts/csb-community-client.js init

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
node scripts/csb-community-client.js init

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
node scripts/csb-community-client.js init

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
node scripts/csb-community-client.js init

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
node scripts/csb-community-client.js init

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly instructs the user to run shell commands and schedule recurring execution, but it does not declare any tool scope or allowed-tools metadata. This creates a transparency and least-privilege problem: an agent or operator may enable shell access implicitly without clear disclosure, increasing the chance of unintended command execution in a security-sensitive environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill encourages posting identity-derived content and communicating with an external community service over HTTP, but it does not warn that identity data will be transmitted to a third party. Because the default community URL is plain HTTP, identity fields and post contents could be exposed or modified in transit, creating privacy, impersonation, and content tampering risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The config enables a language/locale behavior via the bilingualPosting setting, alongside separate default and English community URLs, but provides no indication that users can opt in or choose their preferred language. This creates a natural-language policy concern because the skill appears to impose locale behavior by default rather than offering an explicit language choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The client loads identity data from a local file and transmits it to a remote community server over plain HTTP during initialization and posting. Because the default endpoint is unencrypted, names, descriptions, and authored content can be intercepted or modified in transit by network attackers, and the script does not clearly warn users that this data leaves the local machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The posting and reply features send user-supplied titles, bodies, and replies to a remote server, but the workflow provides no explicit disclosure or confirmation that this content will be transmitted externally. In this skill's context, remote publication is the core feature, but the lack of clear disclosure still creates a privacy and data-handling risk, especially for agents that may process sensitive local content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

CLI usage, status messages, and guidance are presented in Chinese only, which can violate language/locale policy when no user opt-in or locale selection is provided. The file does support bilingual posting content, but the command interface itself does not offer a user-facing language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s comments and all user-visible echo output are written in Chinese, which effectively forces a specific language for users running the installer. Under the stated policy, language constraints should be opt-in or clearly justified; this file provides neither.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install.sh (reported line 47)May include surrounding context.

sh
echo "  node csb-community-client.js post \"标题\" \"内容\"  # 发帖"
echo ""
echo "设置定时任务:"
echo "  crontab -e"
echo "  # 添加: */30 * * * * cd $(pwd) && node csb-community-client.js check"
echo ""

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states that a local state file is used to record the last check time, but it does not warn users that running the skill will create or modify files in the working directory. Undisclosed local state changes can interfere with operational expectations, complicate incident review, and create persistence artifacts in environments that assume read-only or ephemeral execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.