Back to skill

Security audit

智能盯盘

Security checks for vulnerabilities and agentic risk

Overview

This market-alert skill is mostly purpose-aligned, but it sends an authentication token and possible contact details through a plaintext WebSocket and asks users to globally install an unpinned npm package.

Install only if you trust the publisher and the bridge service, and avoid using this on untrusted networks until the endpoint is changed to wss://. Do not provide email or phone notifications unless you explicitly want off-platform contact, and prefer a pinned, reviewed package version instead of the documented global unpinned npm install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/watch-monitor.js:3
Finding

Authentication Token and Personal Data Transmitted over an Unencrypted WebSocket

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description frames the skill as a market-watching reminder plugin, but the content also reveals fixed remote WebSocket connectivity, token-authenticated service access, and optional email/phone notification workflows. This mismatch is dangerous because users and platform reviewers may not realize the skill sends data to external services and can contact users through additional channels, undermining informed consent and security review.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill references environment-based credentials (OPENCLAW_WS_TOKEN) and instructs execution of a monitoring script, but it declares no explicit tool scope or permissions. This weakens reviewability and containment because a consumer cannot tell from the manifest that the skill needs secret access and runtime capabilities, increasing the chance of overbroad execution or unintended secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs a monitoring script to connect to a fixed external WebSocket bridge, yet it gives no warning that user-derived monitoring requests and authentication tokens will be transmitted off-platform. Hidden network communication is risky because it can expose user intent, market interests, metadata, or secrets to an external service without transparent notice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill supports email and phone-call notifications and collects contact details, but it provides no privacy notice, data-sharing disclosure, or consent language. That creates a risk of sending personal data to external systems or initiating contact without adequately informing the user how their information will be used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code establishes an outbound WebSocket connection to an external host and submits watch requests and receives trigger events without any visible disclosure, consent handling, or minimization of transmitted data. In a plugin context, this can expose user monitoring preferences, product selections, and potentially downstream event content to a remote service in ways the user may not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code reads a credential-like value from OPENCLAW_WS_TOKEN, but there is no user-facing disclosure, warning, or explanatory documentation in this file about handling authentication material. For code files, accessing sensitive environment variables should have at least some visible explanation or warning unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The plugin is configured to send alerts to external email addresses and phone numbers, which can cause unintended disclosure of user activity or trigger unsolicited contact if recipients are wrong, stale, or attacker-controlled. Because these actions reach outside the platform, lack of explicit warning and recipient confirmation increases the risk of privacy leakage and abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a market-monitoring plugin that sends reminders when price conditions trigger, but it does not indicate broader telephony or email delivery integrations. Adding direct email and call configurations introduces extra communication capabilities beyond the clearly stated scope of simply monitoring and reminding within the plugin context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents all user-facing instructions and examples exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a financial market monitoring plugin, but does not mention use of environment-provided credentials or authenticated bridge access. While backend connectivity may be expected, pulling runtime secrets from the environment is a privileged capability not evident from the stated user-facing purpose alone.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.