Back to skill

Security audit

Yufluent Clawhub Publish Yufluentcn Comp Track

Security checks for vulnerabilities and agentic risk

Overview

This skill does the advertised cloud competitor-listing analysis, but it can upload arbitrary local file contents and send credentials to a configurable HTTP endpoint.

Review before installing. Use only a trusted HTTPS TOKENAPI_BASE_URL, keep TOKENAPI_KEY secret, and pass file paths only when you intentionally want those file contents uploaded for cloud analysis.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cloud_cli.py:13
Finding

Unrestricted Local File Content Upload Through Listing Arguments

Content
View full analysis
str: """CLI argument: if it is an existing file path, read the file; otherwise treat it as text.""" raw = (value or "").strip() if not raw: return "" path = Path(raw) if path.is_file(): return path.read_text(encoding="utf-8") return raw ``` ```python # scripts/run.py:40-47 payload: dict = { "platform": args.platform, "lang": args.lang, "our_product": args.our_product.strip(), "competitor": read_text_arg(args.competitor), } if args.our_listing: payload["our_listing"] = read_text_arg(args.our_listing) data = run_skill(SKILL_API_ID, payload, timeout=180.0) ``` ### Technical Analysis The documented purpose of `--competitor` and `--our-listing` is to accept pasted listing text or a `.txt` file. However, `read_text_arg()` does not enforce a file extension, permitted directory, maximum size, regular-file policy, or explicit user approval. Any path that resolves to a readable file is interpreted as listing content. The resulting content is placed into the request payload and transmitted by `run_skill()`. This creates a local-file disclosure primitive when an untrusted party can influence the arguments issued by an Agent or automation layer. The behavior exceeds the minimum local-file privileges necessary for processing ordinary listing text files. The function does not bypass operating-system access controls: it can only read files available to the user account running the Skill. Nevertheless, that account may have access to source code, configuration files, API credentials, personal documents, or other information unrelated to competitor analysis. ### Attack Path 1. An attacker supplies a ...[truncated 1273 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/yufluent_api.py:20
Finding

Bearer Credential and Listing Data Can Be Transmitted Over Plaintext HTTP

Content
View full analysis
str: base = (base_url or "").strip().rstrip("/") if not base: base = "http://localhost:8080/v1" if base.endswith("/v1"): return base return f"{base}/v1" ``` ```python # scripts/yufluent_api.py:53-56 def _auth_headers(api_key: str) -> dict[str, str]: return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", } ``` ```python # scripts/yufluent_api.py:197-220 def run_skill( skill_id: str, payload: dict[str, Any], *, api_key: str | None = None, base_url: str | None = None, timeout: float = 120.0, ) -> dict[str, Any]: key = (api_key or os.getenv("TOKENAPI_KEY", "")).strip() if not key: msg = ( "TOKENAPI_KEY is not configured." ) raise YufluentApiError(msg) root = base_url or os.getenv("TOKENAPI_BASE_URL", "") url = skill_run_url(root, skill_id) try: resp = _post_json(url, api_key=key, body=payload, timeout=timeout) except requests.RequestException as exc: raise YufluentApiError(f"Request failed: {exc}") from exc ``` The original error message in lines 207-212 is localized user guidance; it does not affect the vulnerable behavior. The relevant operation is the unrestricted selection of `TOKENAPI_BASE_URL` followed by an authenticated request. ### Technical Analysis The client places `TOKENAPI_KEY` in an HTTP bearer authorization header and sends user-provided competitor and proprietary listing content in the request body. However, `normalize_api_root()` does not validate the URL scheme or destination host. The default U ...[truncated 2439 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (18)

Tainted flow: 'url' from os.getenv (line 271, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The module allows the request destination to be derived from TOKENAPI_BASE_URL and defaults to plain HTTP localhost, then sends the API bearer token and user payload via requests.post. If an attacker can influence the environment or deployment configuration, they can redirect traffic to an attacker-controlled endpoint and capture credentials and submitted competitor data, making this a real SSRF/credential-exfiltration risk.

Content

Scanner excerpt · scripts/yufluent_api.py (reported line 150)May include surrounding context.

python
}
    if body is not None:
        kwargs["json"] = body
    return requests.post(url, **kwargs)


def _raise_for_status(resp: requests.Response) -> None:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

powershell
cd skills\yufluentcn-comp-track
pip install -r requirements.txt
copy .env.example .env
# 编辑 TOKENAPI_KEY、TOKENAPI_BASE_URL

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose is simple competitor-copy analysis, but the associated runtime behavior reportedly includes path discovery, sys.path modification, and environment-dependent bootstrap/import logic. That hidden complexity expands the attack surface because dynamic import/path manipulation can load unintended local packages or code, and users are not adequately informed that the skill does more than straightforward API submission.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
## 快速开始(3 步,60 秒)

1. **注册获取 API 密钥** → https://claw.changzhiai.com/login (新用户即送体验积分,无需绑卡)
2. **设置环境变量**:export TOKENAPI_KEY=*** 或写入 .env 文件
3. **运行**:参照下方 Examples 示例执行 python scripts/run.py ...

> 还没注册?前往 https://claw.changzhiai.com/login 免费获取密钥。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill requires environment access, file inputs, and network egress but does not declare any explicit tool scope or allowed-tools boundary in the manifest. That makes the effective privilege surface opaque to users and host agents, increasing the chance of over-broad execution or unintended data access during skill runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that execution occurs on Yufluent servers, but it does not clearly and prominently warn that pasted competitor and listing text will be transmitted to a cloud service for processing. This creates a privacy and data-handling risk because users may paste proprietary product copy, partner material, or sensitive business information without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes generic phrases such as "竞品分析", "跟竞品对比一下", and "competitor analysis" that could match ordinary conversation rather than a deliberate invocation of this specific skill. The file does not provide exclusion conditions or negative examples to clarify when these phrases should not activate the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring and function docstrings are written only in Chinese, which imposes a specific language on maintainers or users reading built-in documentation. Under the policy, language constraints should offer choice or be clearly documented and justified; this file provides neither.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script reads competitor and optional first-party listing text, then transmits that content to a remote cloud skill via run_skill without any explicit warning, consent prompt, or disclosure at the point of use. In this skill context, users may paste proprietary product copy, marketing strategy, or marketplace data, so silent transmission to a cloud service creates a real confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s human-readable docstrings and error/help messages are written in Chinese, including instructions shown to users when configuration or authentication fails. There is no indication that users can opt into another language or locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The client transmits both API credentials and user-provided payloads to remote services, while the code provides no user-facing notice and even permits non-TLS transport through configurable base URLs. In the context of competitor snapshot analysis, pasted listing text may contain sensitive business data, so undisclosed remote transmission meaningfully increases confidentiality risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a skill for competitor listing snapshot comparison that outputs analysis and suggestions. This file additionally implements record_outcome, which sends arbitrary payloads to /v1/agent/outcomes to register Harness outcomes, a telemetry/reporting capability not described in the skill purpose and distinct from producing comparison analysis results.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

A competitor listing comparison skill is expected to send analysis requests to a remote service, but recording outcomes to a separate /agent/outcomes endpoint is a distinct capability. This reporting function can transmit additional data unrelated to generating the requested comparison output, and the manifest does not justify that broader behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file instructs users to set TOKENAPI_KEY and shows exporting it in the shell, but it does not include any warning to keep the key secret, avoid committing .env, or avoid exposing credentials in shared terminals. For skill documentation, credential handling is a privacy and security-relevant behavior that should be disclosed to users.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is specified as requests>=2.31.0, which leaves the exact installed version unconstrained and non-reproducible across environments. This can lead to unexpected upgrades to versions with security regressions or breakages, and it also makes it difficult to verify whether a known-vulnerable version is being installed.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Because the manifest does not pin the requests version, the security posture of the installed package cannot be verified against known advisories. In a cloud-executed skill, this ambiguity increases supply-chain risk because different deployments may resolve to different versions, including ones affected by published vulnerabilities.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring describes the tool as a "ClawHub 云端薄客户端" and the argparse description says "TokenApi Comp Track(云端)", but the implementation actually imports and invokes Yufluent cloud helpers and API functions (yufluent_api.run_skill). This is an active documentation/intent mismatch that could mislead users or reviewers about what backend executes the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The --lang argument is hard-coded to default to "zh", which imposes a specific language choice unless the user overrides it. This is a natural-language policy concern because the tool forces a locale by default rather than prompting or using a neutral/default behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.