Back to skill

Security audit

Yufluent Clawhub Publish Yufluentcn B2b Assist

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent cloud B2B quotation assistant, but it can send API tokens and sensitive quotation data to an unrestricted HTTP endpoint and has an import-path weakness that merits review before installation.

Review this before installing if you will process real customer inquiries or pricing. Use only a trusted HTTPS Yufluent endpoint, avoid setting TOKENAPI_BASE_URL to arbitrary hosts, keep TOKENAPI_KEY out of shared files and version control, and treat all inquiry, quote, MOQ, payment, lead-time, and company-profile inputs as data sent to the cloud service.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/yufluent_api.py:21
Finding

Bearer Credential and Sensitive Business Data Can Be Transmitted over Plaintext HTTP

Content
View full analysis
str: base = (base_url or "").strip().rstrip("/") if not base: base = "http://localhost:8080/v1" if base.endswith("/v1"): return base return f"{base}/v1" ``` ```python def _auth_headers(api_key: str) -> dict[str, str]: return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", } ``` ```python def _post_json( url: str, *, api_key: str, body: dict[str, Any] | None = None, timeout: float, ) -> requests.Response: kwargs: dict[str, Any] = { "headers": _json_headers(api_key) if body is not None else _auth_headers(api_key), "timeout": timeout, } if body is not None: kwargs["json"] = body return requests.post(url, **kwargs) ``` ```python root = base_url or os.getenv("TOKENAPI_BASE_URL", "") url = skill_run_url(root, skill_id) try: resp = _post_json(url, api_key=key, body=payload, timeout=timeout) except requests.RequestException as exc: raise YufluentApiError(f"Request failed: {exc}") from exc if _should_fallback_skill_run(resp.status_code): return _run_skill_via_agent_turn( skill_id, payload, api_key=key, base_url=root, timeout=timeout, ) ``` ### Technical Analysis The API root accepts an arbitrary URL supplied through an argument or the `TOKENAPI_BASE_URL` environment variable. No validation requires HTTPS for non-loopback destinations, restricts the destination to an approved Yufluent origin, or rejects embedded credentials and unsupported URL schemes. The client attaches `TOKENAPI_KEY` as an HTT ...[truncated 2128 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/run.py:9
Finding

External Sibling Directory Can Shadow and Execute a Trusted Bootstrap Module

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Tainted flow: 'url' from os.getenv (line 271, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/yufluent_api.py (reported line 150)May include surrounding context.

python
}
    if body is not None:
        kwargs["json"] = body
    return requests.post(url, **kwargs)


def _raise_for_status(resp: requests.Response) -> None:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

powershell
cd skills\yufluentcn-b2b-assist
pip install -r requirements.txt
copy .env.example .env
# 编辑 TOKENAPI_KEY = "tk-***"

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A B2B quotation skill that can read arbitrary local files, encode local images, or perform generic output formatting has capabilities unrelated to its declared purpose. That mismatch can be abused to exfiltrate sensitive local business documents or other data under the guise of processing an inquiry.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A B2B quotation skill that can read arbitrary local files, encode local images, or perform generic output formatting has capabilities unrelated to its declared purpose. That mismatch can be abused to exfiltrate sensitive local business documents or other data under the guise of processing an inquiry.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
## 快速开始(3 步,60 秒)

1. **注册获取 API 密钥** → https://claw.changzhiai.com/login (新用户即送体验积分,无需绑卡)
2. **设置环境变量**:export TOKENAPI_KEY=*** 或写入 .env 文件
3. **运行**:参照下方 Examples 示例执行 python scripts/run.py ...

> 还没注册?前往 https://claw.changzhiai.com/login 免费获取密钥。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares no explicit tool scope or permissions despite instructing use of environment variables, local files, and network access. This weakens least-privilege controls and makes it easier for the skill or associated implementation to access more local/system capabilities than users may expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to send inquiry content and pricing details to a cloud endpoint but does not present a clear privacy or data-transfer warning at the point of use. In a B2B context, inquiries, pricing, MOQ, lead times, and customer communications are often commercially sensitive, so silent transmission increases confidentiality risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes short, generic phrases such as "B2B 回复", "外贸报价", and "inquiry reply" that could naturally appear in ordinary conversation rather than uniquely signaling intentional skill use. The section provides examples but no exclusion conditions or context boundaries to clarify when these phrases should not activate the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s user-facing docstrings are written only in Chinese, including operational descriptions such as reading file arguments and image-source handling. This can constitute a language/locale policy violation when the skill implicitly enforces a single language without offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sets --lang to en by default, which forces a specific language if the user does not explicitly choose otherwise. This is a natural-language locale policy concern because the skill does not present the default as an opt-in choice or explain why English is mandatory.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The fallback converts structured skill execution into a broader agent/turn orchestration request with web_fast enabled and natural-language instructions. That widens the execution surface from a narrow API route to a more general agent pathway, increasing the chance of unintended tool use, web access, or prompt-influenced behavior if the upstream service interprets the request more broadly than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code posts skill payload content to remote endpoints via requests.post, including /agent/turn, where _build_agent_turn_body serializes user-provided fields into user_message and session data. Although the module has internal comments and docstrings for developers, there is no user-facing confirmation, print/log disclosure, or warning in this file that user or system data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a B2B foreign-trade assistant for generating inquiry replies, RFQ quotes, MOQ negotiation, delivery responses, and company introductions. This file also implements record_outcome, which posts data to /v1/agent/outcomes to register Harness effects/telemetry, a separate behavior not described as part of the user-facing assistant functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The record_outcome function submits arbitrary payload data to /v1/agent/outcomes over HTTP. This code lacks any user-visible notice, confirmation, or disclosure explaining that outcome data may be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README instructs users to copy a .env file and place a live API key in it, but provides no guidance on protecting that secret, excluding the file from version control, or avoiding accidental disclosure. This can lead to credential leakage through commits, screenshots, shared archives, or local environment mismanagement, especially because the skill is intended for local setup by end users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The workflow says to confirm language but simultaneously sets the default to en as the general language for foreign trade. That creates a built-in language preference unless the user actively changes it, rather than making language selection fully user-driven.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as requests>=2.31.0, which allows future unreviewed versions to be installed and prevents reproducible builds. In a cloud-executed B2B assistant, this creates supply-chain uncertainty and can unexpectedly introduce vulnerable or breaking releases during deployment.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Because requests is not pinned, it is impossible to verify whether the installed version includes known security fixes for published advisories. This is especially relevant for a cloud-hosted skill that may process business communications or credentials, where a vulnerable HTTP client could expose sensitive data or weaken transport security depending on runtime resolution.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/run.py (reported line 61)May include surrounding context.

python
"payment_terms",
        "company_profile",
    ):
        val = getattr(args, key)
        if val and str(val).strip():
            payload[key] = str(val).strip()

Static analysis

No suspicious patterns detected.