T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:111- Finding
Caller identity verification is optional for private note operations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent cloud note-taking skill, but it needs review because it can access private notes, save shared content externally, and store long-lived credentials with weak default scoping.
Install only if you are comfortable giving the skill access to your Get笔记 account and sending saved links, images, and note contents to that service. Configure GETNOTE_OWNER_ID before using it in any shared chat or workspace, avoid broad auto-save behavior for sensitive links or images, and treat OAuth/API key output as secret material that should not appear in chat logs or command transcripts.
SKILL.md:111Caller identity verification is optional for private note operations
scripts/upload_image.py:84API-controlled image upload destination is used without validation
scripts/oauth_poll.py:61OAuth API key is emitted through captured process output
scripts/upload_image.py:23Runtime dependency installation is unpinned and not integrity-verified
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The manifest presents a normal note-management capability, but the document also directs the agent to obtain API credentials, poll for tokens, and write secrets into local configuration. That hidden operational behavior is materially different from the user-facing description, making consent and security review harder and increasing the risk of credential handling abuse.
Automatic activation on any URL or image is risky because many conversations naturally contain links or images that the user did not intend to upload to a third-party notes service. In this skill's context, such activation can directly expose private content to an external API and create persistent records without clear consent.
The trigger phrases are very broad, covering generic terms like '笔记', '保存', and '搜一下', which can cause the skill to activate during ordinary conversation. Because activation can lead to external data transmission or OAuth initiation, overly permissive triggering creates a real risk of unintended privacy-impacting actions.
The entire skill documentation and all example interactions are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. This can constitute a language/locale policy issue because the skill appears to assume one language by default without opt-in or justification.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/workspace/skills/getnote
cd ~/.openclaw/workspace/skills/getnote
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/SKILL.md -o SKILL.md
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/package.json -o package.json
The skill advertises very broad trigger phrases such as general note/save/search language and even automatic activation on any URL or image. In a chat environment, this can cause unintended invocation on unrelated user content, leading to accidental capture, storage, or retrieval of sensitive data without clear user confirmation.
The skill declares capabilities that require environment access, outbound network access, and shell/process execution, but it does not explicitly scope or constrain those tools. In practice this increases the blast radius of prompt-induced misuse, especially because the same document also instructs the agent to run local scripts and handle credentials/OAuth automatically.
The skill advertises saving links, images, audio, and text, but it does not prominently warn that this content will be sent to an external service for storage, OCR, transcription, summarization, and retrieval. For a personal notes tool handling potentially sensitive material, missing disclosure undermines informed consent and increases privacy risk.
The skill directs the agent to automatically initiate OAuth when credentials are absent and continue the user's original request after authorization. This can cause unexpected authentication flows and persistence of access without an adequately explicit consent checkpoint, which is risky for a privacy-sensitive notes service.
The skill instructs the agent to execute a local Python script and manage background polling sessions during OAuth. Introducing arbitrary local script execution for a note-taking integration is a dangerous expansion of privilege because it creates an execution path on the host that can be repurposed or abused beyond simple API access.
The documentation explicitly instructs writing obtained API credentials to ~/.openclaw/openclaw.json. Storing secrets via an agent-directed local file write is sensitive behavior that exceeds the visible note-management scope and can lead to credential exposure, persistence without oversight, or modification of unrelated local configuration.
The package description contains broad, natural-language trigger phrases like ‘存一下’ and ‘记到笔记’, and the broader skill metadata also indicates automatic activation on arbitrary URLs, images, and common words such as ‘保存’ or ‘收藏’. This can cause unintended invocation during ordinary conversation, resulting in accidental capture, storage, or transmission of user content to the notes service without sufficiently explicit user intent.
The natural-language description is entirely in Chinese and presents the interaction examples only in Chinese, which can imply a fixed language expectation. There is no indication that the skill supports user language choice or that the Chinese-only behavior is a documented, justified regional constraint.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. 获取上传凭证
curl 'https://openapi.biji.com/open/api/v1/resource/image/upload_token?mime_type=jpg&count=1' \
-H 'X-Client-ID: {client_id}' \
-H 'Authorization: {api_key}'
This code file contains natural-language documentation entirely in Chinese, and later emits Chinese-only user-facing status and error messages. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and there is no indication here that the locale restriction is optional or justified.
The script takes an arbitrary local image path and uploads the file contents to a remote service, but the interface and help text do not clearly warn the operator that local data will leave the machine and be stored/processed by third-party infrastructure. In a note-taking skill context, users may reasonably expect cloud sync, but local file upload still creates privacy and data handling risk if sensitive images are provided unintentionally.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
print(f"访问 URL: {image_url}")
print()
print("💡 创建图片笔记:")
print(f' curl -X POST "https://openapi.biji.com/open/api/v1/resource/note/save?task_id=..."')
print(f' -H "Authorization: $GETNOTE_API_KEY"')
print(f' -H "Content-Type: application/json"')
print(f' -d \'{{"type":"img_text","image_urls":["{image_url}"]}}\'')
The file presents all headings, field descriptions, and usage guidance in Chinese, which effectively enforces a single language for readers. Under the stated policy, natural-language materials should not force a specific language unless the locale constraint is explicitly documented or the user is given a choice.
This markdown file includes concrete curl examples that use Authorization: {api_key}, X-Client-ID, and OSS upload signing fields such as signature, policy, and OSSAccessKeyId. While the examples are legitimate API documentation, the description does not warn readers that these values are sensitive credentials/tokens that should not be exposed, logged, or shared.
The script's docstring, CLI descriptions, and runtime messages are presented only in Chinese, which imposes a language choice on users without opt-in. The file does not document that this skill is intentionally restricted to a Chinese-speaking or region-specific audience.
No suspicious patterns detected.