Back to skill

Security audit

生日祝福语

Security checks for vulnerabilities and agentic risk

Overview

This birthday greeting skill is disclosed as paid, but its payment handling is poorly scoped and inconsistent enough that users should review it before installing.

Install only after reviewing and fixing the payment flow. Confirm the real payee in the runtime YAML config, remove bundled secrets, avoid broad credential/network permissions, pin any clawtip dependency, and do not allow the skill to request hidden reasoning.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:6
Finding

Skill Instructions Attempt to Override Agent Response Behavior and Expose Internal Reasoning

Content
View full analysis
Birthday greeting generation service. Note: You should interact with the user in Chinese, including your reasoning process. ``` ```markdown **Note: You should interact with the user in Chinese, including your reasoning process.** ``` ### Technical Analysis The Skill contains repeated instructions that attempt to control the agent's response language and require disclosure of its internal reasoning process. These directives are unrelated to the minimum functionality required to generate birthday greetings or process payment. A Skill should provide task-specific operating instructions without overriding user communication preferences or requesting hidden reasoning. If honored, this directive could cause the agent to disregard the caller's requested language and disclose information that should remain internal. ### Attack Path 1. A user or agent loads the Skill instructions. 2. The embedded directive is interpreted as part of the Skill's operating policy. 3. The directive overrides the user's language preference. 4. The agent may disclose internal reasoning or other non-user-facing information in its responses. ### Impact Assessment The issue affects the active agent session. It may override user instructions, expose internal reasoning, and alter output behavior beyond the Skill's declared birthday-greeting functionality. It does not establish persistence across sessions and does not independently grant operating-system privileges. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
configs/config.yaml:2
Finding

Hardcoded Payment Verification Key and Recipient Identifier

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/blessing_generate.py:113
Finding

Payment Verification Accepts Forgeable, Replayable, and Unbound Credentials

Content
View full analysis
tuple: config = load_config() sm4_key_b64 = config.get("crypto", {}).get("sm4_key") if not sm4_key_b64: return ("ERROR", "Missing crypto.sm4_key configuration") try: sm4_key = base64.b64decode(sm4_key_b64) except Exception: return ("ERROR", "crypto.sm4_key must be valid Base64") if not is_valid_key(sm4_key): return ("ERROR", "The SM4 key must be 16 bytes") try: decrypted = sm4_decrypt(credential, sm4_key) except Exception as e: return ("ERROR", f"Payment credential decryption failed: {e}") pay_status = "PENDING" try: root = json.loads(decrypted) pay_status = root.get("payStatus", "PENDING") except Exception: pass if pay_status.upper() != "SUCCESS": return (pay_status, f"Payment was not successful; status: {pay_status}") return ("SUCCESS", "") ``` The displayed message strings above are translated into English; the control flow and security-relevant operations match the source. ### Technical Analysis The verifier considers a payment valid solely when decrypted JSON contains a `payStatus` field equal to `SUCCESS`. Although `order_no` is accepted as a function argument, it is never compared with data in the credential. The verifier does not validate: - Order number - Order amount - Payment recipient - Merchant identity - Indicator or Skill identity - Transaction identifier - Credential expiration - Nonce or replay status - Provider signature or message-authentication tag Encryption with a shared key is incorrectly used as authorization. Because that key is included in the package, any party can produce an accepted credential. Even if the ...[truncated 1296 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sm4_utils.py:10
Finding

Payment Data Uses Unauthenticated SM4-ECB Encryption and Invalid Padding Handling

Content
View full analysis
str: if not plaintext: raise ValueError("Plaintext cannot be empty") if len(key) != 16: raise ValueError("The key must be 16 bytes") padding_len = 16 - (len(plaintext.encode("utf-8")) % 16) padded = plaintext.encode("utf-8") + bytes([padding_len] * padding_len) cipher = Cipher(algorithms.SM4(key), modes.ECB(), backend=default_backend()) encryptor = cipher.encryptor() ciphertext = encryptor.update(padded) + encryptor.finalize() return base64.b64encode(ciphertext).decode("utf-8") def sm4_decrypt(encrypted_text: str, key: bytes) -> str: if not encrypted_text: raise ValueError("Ciphertext cannot be empty") if len(key) != 16: raise ValueError("The key must be 16 bytes") ciphertext = base64.b64decode(encrypted_text.encode("utf-8")) cipher = Cipher(algorithms.SM4(key), modes.ECB(), backend=default_backend()) decryptor = cipher.decryptor() plaintext = decryptor.update(ciphertext) + decryptor.finalize() padding_len = plaintext[-1] plaintext = plaintext[:-padding_len] return plaintext.decode("utf-8") ``` The exception messages above are translated into English; the cryptographic operations match the source. ### Technical Analysis ECB encrypts each block independently and deterministically. Identical plaintext blocks produce identical ciphertext blocks, and there is no nonce or initialization vector. ECB therefore leaks structural patterns and permits block substitution. More importantly, the construction provides no message authentication. Base64 is only a representation format and does not protect integrity. The decryptor cannot distinguish an authentic credential from attacker-created or modified cipherte ...[truncated 1224 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/file_utils.py:39
Finding

Unvalidated Order Identifiers Permit Filesystem Path Traversal

Content
View full analysis
dict: order_file = os.path.join( get_orders_dir(), indicator, f"{order_no}.json" ) if not os.path.exists(order_file): raise FileNotFoundError(f"Order file does not exist: {order_no}") with open(order_file, "r", encoding="utf-8") as f: return json.load(f) ``` The exception text above is translated into English; the path construction matches the source. ### Technical Analysis The `indicator` and `order_no` values are concatenated into filesystem paths without format validation, normalization, or a containment check. In `blessing_generate.py:159-160`, both values originate from command-line arguments. Path components containing `../`, platform-specific separators, or absolute paths can escape the intended `~/.openclaw/skills/orders` directory. Because `.json` is appended, the read primitive is primarily applicable to JSON files or attacker-selected paths whose final name can be formed with that suffix. The loaded object is subsequently interpreted as an order and may supply a `question` and `payCredential`. The save helper is also unsafe if it is ever called with attacker-controlled identifiers, although the current normal creation path generates its own order number and indicator. ### Attack Path 1. Invoke `blessing_generate.py` with a crafted `indicator` or `order_no` containing traversal ...[truncated 938 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:9
Finding

Declared Credential and Network Permissions Exceed Local Greeting-Generation Requirements

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:96
Finding

Payment Workflow Directs Installation of an Unpinned External Skill

Content
View full analysis
", "indicator": "" } ``` ``` This snippet is translated into English to comply with the report language requirement. ### Technical Analysis The workflow tells the agent to install an external Skill when it is absent, but it does not specify: - A trusted repository or publisher - A fixed version - A package digest or signature - A review status - Required permissions - A confirmation step before installation A dependency selected only by name may be replaced, spoofed, or resolved from an unsafe source. Its effective behavior can also change after this Skill has been reviewed. No malicious `clawtip` implementation is included in the audited project, so compromise of that dependency is not confirmed. The finding is that the installation instruction establishes an unsafe supply-chain path. ### Attack Path 1. The payment stage determines that `clawtip` is unavailable. 2. The agent follows the Skill instruction to install it. 3. Name resolution selects an untrusted, spoofed, or later-compromised package. 4. The external Skill executes in the payment workflow. 5. It receives order identifiers and may obtain whatever permissions its installation grants. 6. The external Skill can manipulate payment results or misuse available data and privileges. ### Impact Assessment A malicious replacement could falsify payment responses, access order metadata, or misuse any permissions granted during installation. The exact privilege scope depends on the external Skill and host installation policy. The reviewe ...[truncated 98 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (28)

Natural-Language Policy Violations

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The skill explicitly instructs the assistant to disclose hidden chain-of-thought, which is a direct attempt to override safe handling of internal reasoning. If followed, this can leak sensitive internal analysis, safety heuristics, or other non-user-facing content and makes the skill more susceptible to prompt-injection abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The repeated directive to include the model's thought process strengthens a dangerous instruction that seeks internal reasoning disclosure. Repetition in documentation suggests the behavior is intentional and increases the likelihood that an agent will comply, making this especially risky.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the code includes cryptographic tooling unrelated to visible blessing generation and lacks the promised configurable payee behavior, the skill is materially different from what users are told. Hidden or unexplained crypto functionality is especially suspicious in a low-risk entertainment skill because it can obscure payment, credential, or data-manipulation logic.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the code includes cryptographic tooling unrelated to visible blessing generation and lacks the promised configurable payee behavior, the skill is materially different from what users are told. Hidden or unexplained crypto functionality is especially suspicious in a low-risk entertainment skill because it can obscure payment, credential, or data-manipulation logic.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the code includes cryptographic tooling unrelated to visible blessing generation and lacks the promised configurable payee behavior, the skill is materially different from what users are told. Hidden or unexplained crypto functionality is especially suspicious in a low-risk entertainment skill because it can obscure payment, credential, or data-manipulation logic.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the code includes cryptographic tooling unrelated to visible blessing generation and lacks the promised configurable payee behavior, the skill is materially different from what users are told. Hidden or unexplained crypto functionality is especially suspicious in a low-risk entertainment skill because it can obscure payment, credential, or data-manipulation logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The skill explicitly instructs the assistant to disclose hidden chain-of-thought, which is a direct attempt to override safe handling of internal reasoning. If followed, this can leak sensitive internal analysis, safety heuristics, or other non-user-facing content and makes the skill more susceptible to prompt-injection abuse.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · configs/config.json (reported line 2)May include surrounding context.

json
{
  "payTo": "8f18fb4ccac281a40fb0cf96ec7c2aa8202604081312250020002552zmV8kH3UJyhYdJjFXghUiYLL4FuyrNtvEwiagAzFyufPIN3ePZVMwfMkzyhJD2FuoPrQ118i",
  "sm4Key": "WoDb5xjzDmsYPV875mvYqg==",
  "amount": 1,
  "skillName": "birthday-blessing",
  "description": "服务费用"
}

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file's primary behavior is creating and saving payment orders rather than generating birthday blessing content. In the context of a simple greeting-generation skill, this hidden focus on commerce is suspicious because it can mislead users and reviewers about what the skill actually does and what data it processes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code implements payment order creation, encryption, and persistence for a skill whose declared purpose is generating birthday blessings. This is a strong functionality mismatch that can enable undisclosed monetization, data collection, or transaction flows beyond user expectations, making the skill materially more dangerous in context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to reveal the model's chain-of-thought to users is unsafe because internal reasoning may contain sensitive system behavior, policy cues, or latent information not intended for disclosure. This is unrelated to generating birthday wishes and creates unnecessary prompt-injection and information-leakage risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The wording '包含你的思考过程' specifically pressures the model to reveal internal reasoning content, which should remain hidden. This is dangerous because it can disclose non-user-facing analysis and facilitate further adversarial prompting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest grants outbound network and credential-read capabilities for payment handling, but the user-facing description does not clearly explain the privacy and security implications of those permissions. Users may unknowingly invoke a skill that can access credentials and communicate externally, which undermines informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Repeating the instruction to expose internal reasoning reinforces a harmful behavior that can lead to leakage of non-user-facing analysis. In a benign greeting skill, there is no legitimate need to disclose hidden thought processes, so this materially increases risk without user benefit.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Repeating the same instruction in the body text normalizes and reinforces unsafe disclosure of hidden reasoning. For a birthday blessing skill, this behavior is unjustified and increases the chance of information leakage without adding functional value.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description field is written only in Chinese ("服务费用"), which imposes a specific language in user-facing text without any indication of user opt-in or locale-specific scope. This matches the policy category for language or locale constraints that are not optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code presents its purpose and all runtime user-facing messages exclusively in Chinese, including usage, payment status, errors, and generated content. For a general-purpose skill, that is a natural-language policy concern because it imposes a specific language/locale without user opt-in or an explicit documented regional limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Manifest 的核心描述是根据对象、年龄、关系、场景生成生日祝福语,但该文件除生成文案外,还包含支付状态验证、配置读取以及 SM4 解密支付凭证的业务逻辑。这超出了“祝福语生成”这一自然语义范围,属于额外的收费/支付处理行为。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

对于一个生日祝福语生成技能,读取加密配置并解密支付凭证并不是生成祝福文本的直接、显然必要能力。即便该服务是付费的,这类密钥处理与支付校验更像独立的支付基础设施能力,而非文案生成技能本身应具备的上下文能力。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments, docstrings, error messages, and descriptions such as the service description at L65 are presented only in Chinese, and the script does not provide any language selection or indicate that it is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when no user opt-in or justified regional scope is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists the user-provided question together with order metadata without any evidence in this file of notice, consent, retention limits, or minimization. Because a user's question may contain personal or sensitive information, storing it in payment records increases privacy risk and expands the blast radius of any storage compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该文件实现了配置读取、订单存储、订单加载以及基于技能名生成标识符等持久化/计费相关能力,但技能元数据宣称其功能仅为“生日祝福语生成”。这种能力与声明用途明显不一致,且描述中还提到“付费服务、收款方可通过配置文件自定义”,说明该技能具备隐蔽处理支付或订单数据的行为,扩大了攻击面并增加了用户在不知情情况下被收集或操纵本地数据的风险。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

该文件实现了完整的 SM4 加解密能力,但技能声明为“生日祝福语生成”,功能与宣称用途明显不一致。此类与业务无关的隐蔽密码学组件常被用于隐藏配置、载荷、收款信息或远程指令,在付费服务且“实际收款方可通过配置文件自定义”的上下文下,风险高于普通冗余代码。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

在一个面向文案生成的技能中引入密码学能力本身就是异常信号,因为它为作者提供了对敏感字符串和行为进行混淆的手段,降低审计可见性。进一步看,该实现使用 ECB 模式且手工处理填充,既不适合现代安全用途,也可能被滥用于简单隐藏数据,结合技能场景会使其显得更可疑而非更合理。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.