Back to skill

Security audit

企微瓣 CLI (qwb-cli)

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent with Qiweiban CLI use, but it needs Review because it combines a global unpinned CLI install with authenticated, potentially billable media and account actions that are not tightly scoped or gated.

Review before installing. Verify the `qwb-cli` npm package publisher and version, prefer a pinned or isolated install, keep authentication interactive where possible, and require explicit user confirmation before sending passwords or codes, changing the API URL, uploading private media, deleting resources, updating profile details, or starting any operation that may consume Qiweiban credits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:15
Finding

Unpinned Global Installation of an Unaudited Third-Party CLI Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Supply-chain exposure through an unpinned globally installed dependency
Risk Level: High

Vulnerable Code Snippet:

bash
npm install -g qwb-cli

Technical Analysis

The Skill instructs users or agents to install qwb-cli globally from the npm registry without specifying an exact version, integrity hash, verified publisher identity, trusted source repository, or lockfile. Consequently, the code installed at execution time can differ from the code that existed when the Skill was reviewed.

The -g option installs the package into the user's global npm environment. Package installation can also execute npm lifecycle scripts where permitted. Any malicious code introduced through package compromise, ownership transfer, dependency confusion, or a compromised transitive dependency would run with the privileges of the user performing the installation.

This risk is particularly significant because the installed CLI is subsequently trusted to authenticate users, process passwords and verification codes, store a token in ~/.qwb/credentials.json, upload private audio and video, and communicate with remote services. The repository contains no CLI source, package manifest, lockfile, checksums, or signature information with which these behaviors can be independently verified.

Attack Path

  1. An attacker compromises the qwb-cli npm package, its publisher account, or one of its transitive dependencies.
  2. The attacker publishes a malicious release under the same package name or causes a malicious dependency version to be resolved.
  3. A user or agent follows the Skill instruction and runs npm install -g qwb-cli.
  4. npm retrieves the mutable package version available at installation time and may execute its lifecycle scripts.
  5. Malicious code executes with the installing user's privileges.
  6. The compromise ...[truncated 1116 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed exact version, for example:

    bash
    npm install -g qwb-cli@<reviewed-exact-version>
    
  2. Publish and verify the expected package integrity hash or signed release provenance before installation.

  3. Document the official npm scope, publisher identity, and source repository so users can detect package substitution or ownership changes.

  4. Include the CLI source or a reproducible build reference in the audited project.

  5. Provide and audit a lockfile for all transitive dependencies.

  6. Prefer a project-local or isolated installation over global installation, such as a dedicated container or restricted execution environment.

  7. Disable npm lifecycle scripts during installation unless they are explicitly required and separately audited.

  8. Run the CLI with only user-level permissions and restrict filesystem and network access to the minimum required destinations.

  9. Protect ~/.qwb/credentials.json with owner-only permissions, avoid exposing its contents in logs, and shorten or make configurable the documented 30-day token lifetime.

  10. Restrict API endpoint configuration to trusted HTTPS origins or clearly warn users before credentials are sent to a changed endpoint.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

qwb auth logout

text

Token 存储在 `~/.qwb/credentials.json`,默认有效期 30 天。

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to activate this skill for generic requests such as AI chat or image generation, even when the user did not explicitly intend to use Qiweiban. Because this skill can perform authenticated and billable actions, unintended invocation could lead to privacy issues, accidental account use, or unwanted charges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents login flows, token persistence, and multiple paid operations, but does not instruct the agent to warn users before collecting credentials or initiating charge-incurring actions. In an agent context, this increases the risk of users exposing sensitive secrets and of the agent spending account balance without clear consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.