Back to skill

Security audit

客服回复助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent as a cloud customer-service reply assistant, but its runtime depends on an unreviewed Python client loaded through broad path manipulation while handling API keys and customer/order data.

Review before installing. The skill is clearly meant to call a Yufluent cloud service with customer-service content, so avoid sending unnecessary personal data, order identifiers, or tracking details. Install only from a source that includes or verifies the yufluent_api client, keep TOKENAPI_KEY out of commits and logs, and prefer pinned dependencies for reproducible installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/run.py:10
Finding

Unverified External Python Module Loaded Through Runtime Path Manipulation

Content
View full analysis
Path: """ 将 cloud 客户端目录加入 sys.path。 - ClawHub zip:scripts/ 内已有 yufluent_api.py(package-skill 注入) - Monorepo:回退 skills/_shared/ """ scripts_dir = Path(script_file).resolve().parent skills_shared = scripts_dir.parent.parent / "_shared" for candidate in (scripts_dir, skills_shared, _SHARED_DIR): if candidate.is_dir() and (candidate / "yufluent_api.py").is_file(): path = str(candidate) if path not in sys.path: sys.path.insert(0, path) return candidate raise ImportError( "cloud client not found: expected scripts/yufluent_api.py (ClawHub) " "or skills/_shared/yufluent_api.py (monorepo)" ) ``` ### Technical Analysis The project does not contain `yufluent_api.py`, even though `scripts/run.py` imports and executes its `run_skill` function. The loader searches the local `scripts` directory and an external sibling `_shared` directory, prepends a matching directory to `sys.path`, and then imports the module by its unqualified name. Consequently, the central network client is outside the reviewed artifact. Its endpoi ...[truncated 2031 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/cloud_cli.py:12
Finding

Unused Helpers Permit Unrestricted Local File Reading and Base64 Encoding

Content
View full analysis
str: """CLI 参数:若为现有文件路径则读文件,否则当作原文。""" raw = (value or "").strip() if not raw: return "" path = Path(raw) if path.is_file(): return path.read_text(encoding="utf-8") return raw def encode_image_source(source: str) -> str: """本地路径 → data URI;http(s)/data: 原样返回(OpenClaw 云端 run 前编码)。""" raw = (source or "").strip() if not raw: raise ValueError("source_image is empty") if raw.startswith(("http://", "https://", "data:")): return raw path = Path(raw) if not path.is_file(): raise ValueError(f"source_image file not found: {raw}") data = path.read_bytes() suffix = path.suffix.lower() if suffix == ".png": mime = "image/png" elif suffix == ".webp": mime = "image/webp" elif suffix in (".jpg", ".jpeg"): mime = "image/jpeg" else: mime = "image/jpeg" encoded = base64.b64encode(data).decode("ascii") return f"data:{mime};base64,{encoded}" ``` ### Technical Analysis Both helpers interpret caller-controlled strings as local filesystem paths. If a supplied path exists, `read_text_arg()` returns its text contents, while `encode_image_source()` reads all bytes and returns them in a Base64 data URI. The functions do not: - Restrict access to an approved directory. - Reject absolute paths or parent-directory traversal. - Reject symbolic links. - Verify file content against the claimed image type. - Enforce a maximum file size. - Require user confirmation before reading a local file. The image helper labels unknown file extensions as `image/jpeg` without validating the contents. As a result, arbitrary binary files can be encoded despite the function's image-oriented name. The ...[truncated 1852 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
## 快速开始(3 步,60 秒)

1. **注册获取 API 密钥** → https://claw.changzhiai.com/login (新用户即送体验积分,无需绑卡)
2. **设置环境变量**:export TOKENAPI_KEY=*** 或写入 .env 文件
3. **运行**:参照下方 Examples 示例执行 python scripts/run.py ...

> 还没注册?前往 https://claw.changzhiai.com/login 免费获取密钥。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The listed trigger phrases include broad expressions such as "客服怎么回", "写个英文回复", and "订单到哪了", which are common conversational requests and not narrowly scoped to this specific skill. Without stronger constraints or negative examples, these phrases could cause unintended invocation in ordinary chat contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language strings in the module and function docstrings are written only in Chinese, which imposes a language expectation without any visible opt-in or alternative locale handling. Under the policy rule, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code sends buyer messages and optional order/order-tracking context to a remote cloud API via run_skill() without any visible notice, consent flow, masking, or minimization in this file. Because buyer messages and order context can contain personal, transactional, or sensitive customer data, undisclosed transmission to a third party creates a real privacy and data-handling risk even if the functionality is expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README instructs users to place an API key in an environment variable but does not include any guidance on secure credential handling. While using environment variables is common practice, omission of warnings can still lead to accidental exposure through shell history, shared terminals, screenshots, or misuse in local scripts and CI logs.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification uses a lower-bound only constraint (requests>=2.31.0) rather than pinning to an exact version or a tightly controlled range. This makes builds non-reproducible and can allow different environments to install newer releases with unexpected behavior or newly introduced supply-chain risk.

Content

Scanner excerpt · requirements-dev.txt (reported line 3)May include surrounding context.

text
-e ../../packages/tokenapi-sdk
-e ../../packages/tokenapi-harness
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Because requests is not pinned, it is not possible to verify from this manifest whether the installed version is affected by any of the known advisories associated with the package. The danger here is uncertainty: downstream environments may resolve to a vulnerable release, especially in development setups that are rebuilt over time.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower-bound range (requests>=2.31.0) instead of an exact pinned version, which makes builds non-reproducible and can cause different environments to install different releases. This increases supply-chain risk and makes it harder to verify whether a deployed version includes known security fixes or introduces a vulnerable or incompatible release.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Because requests is not pinned, the manifest does not prove which version will actually be installed, and some requests releases have known security advisories. The danger here is not that requests is inherently unsafe, but that the project cannot reliably demonstrate that it avoids affected versions, leaving room for vulnerable installs in some environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code includes a natural-language locale selection string of "zh" as part of scene composition inputs, but there is no indication here that the user chose that language or that the locale is required for a region-specific workflow. Under the policy, forcing or assuming a language/locale without explicit opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.